„Passwort“ Folge 62: IETF-Grabenkämpfe, Umbrella-CVEs, Riksha-Hacking und mehr (2026-07-22 07:00 UTC)
Kurz: Eine Podcastfolge fast ohne PKI, aber mit gehörig Drama (bei der IETF), Kopfschütteln (über Cisco) und gefährlichen Sicherheitslücken (im In- und Ausland).
Chick-fil-A discloses data breach after credential stuffing attacks (2026-07-22 06:40 UTC)
Kurz: American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. […]
OpenAI says its AI models hacked Hugging Face during testing (2026-07-22 05:19 UTC)
Kurz: OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […]
Kurz: Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. […]
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA (2026-07-22 06:38 UTC)
Kurz: German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed…
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library (2026-07-22 06:00 UTC)
Kurz: Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, nam…
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents (2026-07-22 04:57 UTC)
Kurz: A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft’s of…
Kurz: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, al…
Kurz: This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerabilit…
Kurz: This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vuln…