IT‑Sicherheits‑Digest (2026-07-23)

Aktuelle Security‑News

heise security

  • Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke (2026-07-23 07:13 UTC)
    • Kurz: Weitere Sicherheitslücken in SharePoint stehen unter Beschuss. Auch Check Point SmartConsole wird derzeit attackiert.
    • Quelle: Link
  • Cyberattacken auf Landesverwaltung nehmen weiter zu (2026-07-23 04:45 UTC)
    • Kurz: Cyberangriffe nehmen in Sachsen-Anhalt deutlich zu: Im ersten Halbjahr meldet die Landesverwaltung mehr als doppelt so viele Vorfälle wie zuvor.
    • Quelle: Link
  • Online-Trading-Betrug: Opfer investieren über eine Million (2026-07-23 04:19 UTC)
    • Kurz: 24 Menschen aus ganz Deutschland sollen Geld in vermeintliche Online-Trading-Plattformen investiert haben. Doch Gewinne wurden nie ausgezahlt.
    • Quelle: Link

BleepingComputer

  • Upbound says hack caused $13 million in fraudulent Acima leases (2026-07-22 21:43 UTC)
    • Kurz: The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. […]
    • Quelle: Link
  • South Korea discloses data breach impacting diplomats worldwide (2026-07-22 20:06 UTC)
    • Kurz: South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), includin…
    • Quelle: Link
  • Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack (2026-07-22 16:59 UTC)
    • Kurz: Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. […]
    • Quelle: Link

The Hacker News

  • GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier (2026-07-22 18:37 UTC)
    • Kurz: Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or …
    • Quelle: Link
  • Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs (2026-07-22 18:07 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high…
    • Quelle: Link
  • Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data (2026-07-22 15:01 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. Th…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.