IT‑Sicherheits‑Digest (2026-04-15)

Aktuelle Security‑News

heise security

  • SAP-Patchday: Eine kritische SQL-Injection-Lücke – und 18 weitere (2026-04-14 11:17 UTC)
    • Kurz: Am April-Patchday behandelt SAP Schwachstellen mit 19 Sicherheitsnotizen. Eine kritische erlaubt das Einschleusen von SQL-Befehlen.
    • Quelle: Link
  • Sicherheitslücke: wolfSSL-Bibliothek winkt manipulierte Zertifikate durch (2026-04-14 10:16 UTC)
    • Kurz: Ein Sicherheitsupdate schließt unter anderem eine kritische Lücke in wolfSSL.
    • Quelle: Link
  • CPUID: Angreifer haben über Webseite Malware-Installer verteilt (2026-04-14 09:58 UTC)
    • Kurz: Die Webseite CPUID der System-Analyse-Tools CPU-Z und HWMonitor wurde von Angreifern manipuliert. Sie verteilte Malware.
    • Quelle: Link

BleepingComputer

  • Microsoft adds Windows protections for malicious Remote Desktop files (2026-04-14 22:23 UTC)
    • Kurz: Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (.rdp) files, adding warnings and disabling risky shared resources by default. […]
    • Quelle: Link
  • Crypto-exchange Kraken extorted by hackers after insider breach (2026-04-14 21:58 UTC)
    • Kurz: The Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data. […]
    • Quelle: Link
  • Over 100 Chrome Web Store extensions steal user accounts, data (2026-04-14 20:33 UTC)
    • Kurz: More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud. […]
    • Quelle: Link

The Hacker News

  • New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released (2026-04-14 15:57 UTC)
    • Kurz: Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as command injectio…
    • Quelle: Link
  • Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security (2026-04-14 14:56 UTC)
    • Kurz: Google has announced the integration of a Rust-based Domain Name System (DNS) parser into the modem firmware as part of its ongoing efforts to beef up the security of Pixel devices and push memory-safe code at a more foundational level. “Th…
    • Quelle: Link
  • AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud (2026-04-14 14:30 UTC)
    • Kurz: Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google’s Discove…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • CVE-2025-61848 — CVSS 7.2 (HIGH)
    • Kurz: An improper neutralization of special elements used in an sql command (‘sql injection’) vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, Fort…
    • Quelle: Link
  • CVE-2025-53847 — CVSS 6.5 (MEDIUM)
    • Kurz: A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, For…
    • Quelle: Link
  • CVE-2025-61624 — CVSS 6.0 (MEDIUM)
    • Kurz: An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all ver…
    • Quelle: Link
  • CVE-2024-23104 — CVSS 5.4 (MEDIUM)
    • Kurz: An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, Forti…
    • Quelle: Link
  • CVE-2025-61886 — CVSS 5.4 (MEDIUM)
    • Kurz: An Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow a…
    • Quelle: Link
  • CVE-2025-59809 — CVSS 4.3 (MEDIUM)
    • Kurz: A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiS…
    • Quelle: Link

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).