IT‑Sicherheits‑Digest (2026-07-17)

Aktuelle Security‑News

heise security

  • Apple-Tool nachgemacht: So geht die neue macOS-Malware CrashStealer vor (2026-07-17 07:30 UTC)
    • Kurz: Momentan kursiert ein neuer Mac-Datenschädling, der Zugangsdaten und Kryptowährungen klauen kann. Er tarnt sich als Apple-Software.
    • Quelle: Link
  • Google Chrome: Außerplanmäßiges zweites Update in der Woche (2026-07-17 06:27 UTC)
    • Kurz: Google aktualisiert Chrome eigentlich jeden Mittwoch. Diese Woche folgt ein zweites Update, das mehrere kritische Lücken schließt.
    • Quelle: Link
  • 7-Zip: Update stopft Codeschmuggel-Lücke (2026-07-17 06:07 UTC)
    • Kurz: Das Packprogramm 7-Zip patzt bei der Verarbeitung präparierter xz-Daten. Das kann zum Ausführen eingeschmuggelten Codes führen.
    • Quelle: Link

BleepingComputer

  • CISA urges immediate action on actively exploited Fortinet flaws (2026-07-17 07:03 UTC)
    • Kurz: CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. […]
    • Quelle: Link
  • New ClickLock macOS malware traps users into revealing login password (2026-07-16 21:52 UTC)
    • Kurz: A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. […]
    • Quelle: Link
  • Coca-Cola says Fairlife ransomware attack halts US dairy production (2026-07-16 21:09 UTC)
    • Kurz: The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. […]
    • Quelle: Link

The Hacker News

  • CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV (2026-07-17 06:42 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executiv…
    • Quelle: Link
  • Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack (2026-07-16 17:09 UTC)
    • Kurz: Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27…
    • Quelle: Link
  • ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories (2026-07-16 15:41 UTC)
    • Kurz: A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than th…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.