IT‑Sicherheits‑Digest (2026-02-14)

Aktuelle Security‑News

heise security

  • Palantir will Gegendarstellung von Schweizer Magazin gerichtlich durchsetzen (2026-02-13 19:05 UTC)
    • Kurz: Der Datenanalyse-Anbieter Palantir will vor Gericht eine Gegendarstellung erwirken – und löst eine Welle der Solidarität für ein kleines Schweizer Magazin aus.
    • Quelle: Link
  • IPFire stellt freie Domain-Blockliste DBL vor (2026-02-13 12:46 UTC)
    • Kurz: Die IPFire-Entwickler haben mit DBL eine kategorisierte Domain-Blockliste veröffentlicht. Sie soll Malware, Phishing und Tracker blockieren.
    • Quelle: Link
  • Angreifer können auf Dateisystem von QNAP-NAS zugreifen (2026-02-13 10:46 UTC)
    • Kurz: Sicherheitspatches für die NAS-Betriebssysteme QTS und QuTS hero von Qnap schließen mehrere Lücken.
    • Quelle: Link

BleepingComputer

  • Fake job recruiters hide malware in developer coding challenges (2026-02-13 22:35 UTC)
    • Kurz: A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks. […]
    • Quelle: Link
  • Claude LLM artifacts abused to push Mac infostealers in ClickFix attack (2026-02-13 20:21 UTC)
    • Kurz: Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries. […]
    • Quelle: Link
  • Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches (2026-02-13 18:35 UTC)
    • Kurz: South Korea has fined luxury fashion brands Louis Vuitton, Christian Dior Couture, and Tiffany $25 million for failing to implement adequate security measures, which facilitated unauthorized access and the exposure of data belonging to more…
    • Quelle: Link

The Hacker News

  • Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs (2026-02-13 17:27 UTC)
    • Kurz: A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organizations with malware known as CANFAIL. Google Threat Intelligence Group (GTIG) described the hack group as possibly affiliated with Russian inte…
    • Quelle: Link
  • Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations (2026-02-13 16:23 UTC)
    • Kurz: Several state-sponsored actors, hacktivist entities, and criminal groups from China, Iran, North Korea, and Russia have trained their sights on the defense industrial base (DIB) sector, according to findings from Google Threat Intelligence …
    • Quelle: Link
  • UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors (2026-02-13 15:23 UTC)
    • Kurz: A previously unknown threat actor tracked as UAT-9921 has been observed leveraging a new modular framework called VoidLink in its campaigns targeting the technology and financial services sectors, according to findings from Cisco Talos. “Th…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den letzten 24h.

Atlassian (Jira/Confluence)

  • CVE-2026-22892 — CVSS 4.3 (MEDIUM)
    • Kurz: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira…
    • Quelle: Link

HPE/Aruba Switches

  • Keine neuen Treffer in den letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).