IT‑Sicherheits‑Digest (2026-07-14)

Aktuelle Security‑News

heise security

  • Telegram-Messenger: Kurzdomain t.me womöglich wegen US-Sanktionen gesperrt (2026-07-14 07:31 UTC)
    • Kurz: Die Domain wurde von der Vergabestelle des Landes Montenegro blockiert - womöglich stecken US-Sanktionen gegen einen VPN-Anbieter dahinter.
    • Quelle: Link
  • Betrügerischer Ransomware-Verhandler muss 70 Monate ins Gefängnis (2026-07-14 07:29 UTC)
    • Kurz: Das Urteil ist gefallen: Für 70 Monate wandert ein betrügerischer Ransomware-Verhandler aus Florida hinter Gitter.
    • Quelle: Link
  • Alte Cisco-Lücke attackiert: Leitfaden zum Schutz (2026-07-14 05:38 UTC)
    • Kurz: Die US-IT-Sicherheitsbehörde CISA warnt vor Angriffen auf eine 18 Jahre alte Cisco-Lücke. Ein Leitfaden soll helfen, Router abzusichern.
    • Quelle: Link

BleepingComputer

  • Japan’s largest taxi operator shuts systems after cyberattack (2026-07-13 20:18 UTC)
    • Kurz: Japan’s largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. […]
    • Quelle: Link
  • Hackers backdoor Jscrambler npm package with infostealer malware (2026-07-13 19:44 UTC)
    • Kurz: The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. […]
    • Quelle: Link
  • New CrashStealer malware poses as Apple crash reporting tool (2026-07-13 19:04 UTC)
    • Kurz: A new macOS information-stealing malware called CrashStealer pretends to be Apple’s crash-reporting tool to steal credentials, keychain data, and crypto wallets. […]
    • Quelle: Link

The Hacker News

  • Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths (2026-07-14 06:19 UTC)
    • Kurz: Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organizat…
    • Quelle: Link
  • CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks (2026-07-13 17:36 UTC)
    • Kurz: Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Obj…
    • Quelle: Link
  • Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found (2026-07-13 17:17 UTC)
    • Kurz: Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The …
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.