IT‑Sicherheits‑Digest (2026-02-24)

Aktuelle Security‑News

heise security

  • Mit ChatGPT erstellte Passwörter sind nicht sicher (2026-02-23 13:45 UTC)
    • Kurz: Wer KI-Chatbots auffordert, starke Passwörter zu erstellen, erhält zwar sicher erscheinende Ergebnisse, jedoch sind die Passwörter leicht zu knacken.
    • Quelle: Link
  • Sicherheitsupdate: Schadcode-Attacken auf GIMP möglich (2026-02-23 10:36 UTC)
    • Kurz: Angreifer können PCs, auf denen das Grafikprogramm GIMP installiert ist, attackieren. Dafür müssen Opfer aber mitspielen.
    • Quelle: Link
  • CarGurus: Have I Been Pwned integriert Daten von 12,5 Millionen Kunden (2026-02-23 09:53 UTC)
    • Kurz: Have I Been Pwned ist um 12,5 Millionen Einträge von CarGurus-Nutzern und -Nutzerinnen reicher. Die haben ShinyHunters geklaut.
    • Quelle: Link

BleepingComputer

  • Android mental health apps with 14.7M installs filled with security flaws (2026-02-23 22:59 UTC)
    • Kurz: Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users’ sensitive medical information. […]
    • Quelle: Link
  • Spain arrests suspected hacktivists for DDoSing govt sites (2026-02-23 21:59 UTC)
    • Kurz: Spanish authorities have arrested four alleged members of a hacktivist group believed to have carried out cyberattacks targeting government ministries, political parties, and various public institutions. […]
    • Quelle: Link
  • Microsoft says bug in classic Outlook hides the mouse pointer (2026-02-23 19:40 UTC)
    • Kurz: Microsoft is investigating a known issue that causes the mouse pointer to disappear in the classic Outlook desktop email client for some users. […]
    • Quelle: Link

The Hacker News

  • APT28 Targeted European Entities Using Webhook-Based Macro Malware (2026-02-23 19:41 UTC)
    • Kurz: The Russia-linked state-sponsored threat actor tracked as APT28 has been attributed to a new campaign targeting specific entities in Western and Central Europe. The activity, per S2 Grupo’s LAB52 threat intelligence team, was active between…
    • Quelle: Link
  • Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb (2026-02-23 17:59 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromised hosts. “Analysis of the recovered dropper, persistence trigg…
    • Quelle: Link
  • ⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More (2026-02-23 13:00 UTC)
    • Kurz: Security news rarely moves in a straight line. This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public view. The details are different, but the pressure points are famili…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den letzten 24h.

HPE/Aruba Switches

  • CVE-2026-23694 — CVSS n/a
    • Kurz: Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handlers for ahsc_reset_opt…
    • Quelle: Link

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).