IT‑Sicherheits‑Digest (2026-02-06)

Aktuelle Security‑News

heise security

  • Auslegungssache 152: Wirtschaftsvorteil Datenschutz? (2026-02-06 05:10 UTC)
    • Kurz: Im c’t-Datenschutzpodcast diskutieren die Hosts mit Frederik Richter darüber, ob Datenschutz Unternehmen ausbremst oder ihnen sogar Vorteile verschafft.
    • Quelle: Link
  • Sicherheitsupdate: Root-Sicherheitslücke bedroht Cisco Meeting Management (2026-02-05 13:18 UTC)
    • Kurz: Angreifer können verschiedene Produkte von Cisco wie Meeting Management und Prime Infrastructure attackieren.
    • Quelle: Link
  • Patchday Android: Treiberlücke gefährdet Pixel-Smartphones (2026-02-05 11:35 UTC)
    • Kurz: Diesen Monat hält sich Google mit Android-Sicherheitsupdates zurück, dafür verteilt Samsung mehrere Patches.
    • Quelle: Link

BleepingComputer

  • Spain’s Ministry of Science shuts down systems after breach claims (2026-02-05 21:23 UTC)
    • Kurz: Spain’s Ministry of Science (Ministerio de Ciencia) announced a partial shutdown of its IT systems, affecting several citizen- and company-facing services. […]
    • Quelle: Link
  • Ransomware gang uses ISPsystem VMs for stealthy payload delivery (2026-02-05 20:57 UTC)
    • Kurz: Ransomware operators are hosting and delivering malicious payloads at scale by abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider. […]
    • Quelle: Link
  • Microsoft to shut down Exchange Online EWS in April 2027 (2026-02-05 18:07 UTC)
    • Kurz: Microsoft announced today that the Exchange Web Services (EWS) API for Exchange Online will be shut down in April 2027, after nearly 20 years. […]
    • Quelle: Link

The Hacker News

  • Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries (2026-02-06 05:49 UTC)
    • Kurz: Artificial intelligence (AI) company Anthropic revealed that its latest large language model (LLM), Claude Opus 4.6, has found more than 500 previously unknown high-severity security flaws in open-source libraries, including Ghostscript, Op…
    • Quelle: Link
  • AISURU/Kimwolf Botnet Launches Record-Setting 31.4 Tbps DDoS Attack (2026-02-05 17:25 UTC)
    • Kurz: The distributed denial-of-service (DDoS) botnet known as AISURU/Kimwolf has been attributed to a record-setting attack that peaked at 31.4 Terabits per second (Tbps) and lasted only 35 seconds. Cloudflare, which automatically detected and m…
    • Quelle: Link
  • ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories (2026-02-05 12:57 UTC)
    • Kurz: This week didn’t produce one big headline. It produced many small signals — the kind that quietly shape what attacks will look like next. Researchers tracked intrusions that start in ordinary places: developer workflows, remote tools, cloud…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • CVE-2026-25815 — CVSS 3.2 (LOW)
    • Kurz: Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across a…
    • Quelle: Link

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).