IT‑Sicherheits‑Digest (2026-02-13)

Aktuelle Security‑News

heise security

  • Attacken auf Systeme mit FortiSandbox und FortiOS möglich (2026-02-12 11:29 UTC)
    • Kurz: Angreifer können unter anderem Firewalls von Fortinet attackieren. Sicherheitsupdates stehen zum Download bereit.
    • Quelle: Link
  • Dell schließt unzählige Sicherheitslücken in Avamar, iDRAC und NetWorker (2026-02-12 09:11 UTC)
    • Kurz: Die Backuplösungen Dell Avamar und NetWorker und die Server-Fernverwaltung iDRAC sind verwundbar.
    • Quelle: Link
  • Kommentar: Neue Windows-Regeln – fraglich für die Sicherheit, nervig für Nutzer (2026-02-11 15:07 UTC)
    • Kurz: Microsoft kündigt deutlich verschärfte Sicherheitsmaßnahmen für Windows an – die wenigstens zweifelhaft bis kontraproduktiv sind, analysiert Moritz Förster.
    • Quelle: Link

BleepingComputer

  • Russia tries to block WhatsApp, Telegram in communication blockade (2026-02-12 22:57 UTC)
    • Kurz: The Russian government is attempting to block WhatsApp in the country as its crackdown on communication platforms not under its control intensifies. […]
    • Quelle: Link
  • Bitwarden introduces ‘Cupid Vault’ for secure password sharing (2026-02-12 21:55 UTC)
    • Kurz: Bitwarden has launched a new system called ‘Cupid Vault’ that allows users to safely share passwords with trusted email addresses. […]
    • Quelle: Link
  • Critical BeyondTrust RCE flaw now exploited in attacks, patch now (2026-02-12 21:34 UTC)
    • Kurz: A critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access appliances is now being exploited in attacks after a PoC was published online. […]
    • Quelle: Link

The Hacker News

  • Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support (2026-02-12 17:57 UTC)
    • Kurz: Google on Thursday said it observed the North Korea-linked threat actor known as UNC2970 using its generative artificial intelligence (AI) model Gemini to conduct reconnaissance on its targets, as various hacking groups continue to weaponiz…
    • Quelle: Link
  • Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems (2026-02-12 16:55 UTC)
    • Kurz: Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign orchestrated by the North Korea-linked Lazarus Group. The coo…
    • Quelle: Link
  • ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories (2026-02-12 11:51 UTC)
    • Kurz: Threat activity this week shows one consistent signal — attackers are leaning harder on what already works. Instead of flashy new exploits, many operations are built around quiet misuse of trusted tools, familiar workflows, and overlooked e…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).