IT‑Sicherheits‑Digest (2026-02-04)

Aktuelle Security‑News

heise security

  • Messenger Signal: Nachrichten in Chats lassen sich festpinnen (2026-02-04 13:30 UTC)
    • Kurz: Der Messenger Signal hat eine neue Funktion erhalten. Nutzer und Nutzerinnen können nun Nachrichten in Chats festpinnen.
    • Quelle: Link
  • Phishing: Falsche Cloud-Speicher-Warnung nachverfolgt (2026-02-04 11:22 UTC)
    • Kurz: Phishing-Mails zielen nicht nur direkt auf Zugangsdaten ab, sondern bringen Opfer öfter zu Affiliate-Marketing-Seiten.
    • Quelle: Link
  • Schadcode-Lücken in IBM WebSphere Application Server Liberty und Netcool/OMNIbus (2026-02-04 10:25 UTC)
    • Kurz: Angreifer können IBMs Anwendungsserver WebSphere Application Server Liberty und die Netzwerkmonitoringlösung Tivoli Netcool/OMNIbus attackieren.
    • Quelle: Link

BleepingComputer

  • CISA: VMware ESXi flaw now exploited in ransomware attacks (2026-02-04 17:38 UTC)
    • Kurz: CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was previously used in zero-day attacks. […]
    • Quelle: Link
  • CISA warns of five-year-old GitLab flaw exploited in attacks (2026-02-04 15:42 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems against a five-year-old GitLab vulnerability that is actively being exploited in attacks. […]
    • Quelle: Link
  • The Double-Edged Sword of Non-Human Identities (2026-02-04 15:05 UTC)
    • Kurz: Leaked non-human identities like API keys and tokens are becoming a major breach driver in cloud environments. Flare shows how exposed machine credentials quietly grant attackers long-term access to enterprise systems. […]
    • Quelle: Link

The Hacker News

  • Microsoft Develops Scanner to Detect Backdoors in Open-Weight Large Language Models (2026-02-04 17:52 UTC)
    • Kurz: Microsoft on Wednesday said it built a lightweight scanner that it said can detect backdoors in open-weight large language models (LLMs) and improve the overall trust in artificial intelligence (AI) systems. The tech giant’s AI Security tea…
    • Quelle: Link
  • DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files (2026-02-04 17:24 UTC)
    • Kurz: Threat hunters have disclosed details of a new, stealthy malware campaign dubbed DEAD#VAX that employs a mix of “disciplined tradecraft and clever abuse of legitimate system features” to bypass traditional detection mechanisms and deploy a …
    • Quelle: Link
  • China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns (2026-02-04 14:09 UTC)
    • Kurz: Threat actors affiliated with China have been attributed to a fresh set of cyber espionage campaigns targeting government and law enforcement agencies across Southeast Asia throughout 2025. Check Point Research is tracking the previously un…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).