IT‑Sicherheits‑Digest (2026-07-16)

Aktuelle Security‑News

heise security

  • Webkonferenztool Zoom: Kontoübernahme aus dem Netz möglich (2026-07-16 07:38 UTC)
    • Kurz: Zoom hat mehrere Sicherheitslücken in der Webkonferenzsoftware geschlossen. Sie ermöglichen etwa Kontoübernahme aus dem Netz.
    • Quelle: Link
  • Windows-Update: Wegen Problemen auf einigen Dell-Computern ausgesetzt (2026-07-16 05:46 UTC)
    • Kurz: Die Windows-Updates machen auf einigen Dell-Computern Probleme. Microsoft installiert sie daher nicht auf betroffene Systeme.
    • Quelle: Link
  • BSI seziert Windows Hello: Wo Microsofts Anmeldung an Grenzen stößt (2026-07-15 13:30 UTC)
    • Kurz: Das BSI hat Windows Hello for Business analysiert und Schwächen bei der biometrischen Anmeldung aufgedeckt – besonders ohne Enhanced Sign-in Security.
    • Quelle: Link

BleepingComputer

  • Dutch police bust investment fraud ring stealing over €100 million (2026-07-15 21:55 UTC)
    • Kurz: The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. […]
    • Quelle: Link
  • Zoom warns of critical account takeover vulnerability (2026-07-15 20:16 UTC)
    • Kurz: Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. […]
    • Quelle: Link
  • Google Gemini CLI abused as a hacking agent, malware botnet operator (2026-07-15 18:33 UTC)
    • Kurz: A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. […]
    • Quelle: Link

The Hacker News

  • TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development (2026-07-15 18:43 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit w…
    • Quelle: Link
  • OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps (2026-07-15 15:30 UTC)
    • Kurz: A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet…
    • Quelle: Link
  • Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws (2026-07-15 13:18 UTC)
    • Kurz: Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly compone…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • CVE-2026-59838 — CVSS 5.9 (MEDIUM)
    • Kurz: A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSI…
    • Quelle: Link

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.