IT‑Sicherheits‑Digest (2026-07-28)

Aktuelle Security‑News

heise security

  • Neobank Revolut: Angeblich 75 Millionen Datensätze im Untergrund angeboten (2026-07-28 07:05 UTC)
    • Kurz: Ein Krimineller bietet im digitalen Untergrund eine Datenbank mit 75 Millionen Einträgen an, die von der Neobank Revolut stammen sollen.
    • Quelle: Link
  • Angriffe auf FortiOS und Arista VeloCloud beobachtet (2026-07-28 05:48 UTC)
    • Kurz: Die IT-Sicherheitsbehörde CISA meldet Angriffe auf Sicherheitslücken in Fortinet FortiOS sowie Arista VeloCloud.
    • Quelle: Link
  • Sicherheitsupdate: Dateitransferlösung MOVEit ist verwundbar (2026-07-27 13:40 UTC)
    • Kurz: Mehrere Sicherheitslücken gefährden MOVEit-Server. Es gibt unter anderem Sicherheitsprobleme bei der Authentifizierung.
    • Quelle: Link

BleepingComputer

  • Hackers target US firms in FastJson RCE zero-day attacks (2026-07-27 23:49 UTC)
    • Kurz: Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. […]
    • Quelle: Link
  • Arista patches VeloCloud Orchestrator zero-day exploited in attacks (2026-07-27 22:49 UTC)
    • Kurz: Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. […]
    • Quelle: Link
  • New Dysphoria DDoS botnet spreads to 200k devices worldwide (2026-07-27 21:08 UTC)
    • Kurz: A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. […]
    • Quelle: Link

The Hacker News

  • Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost (2026-07-28 06:07 UTC)
    • Kurz: Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It als…
    • Quelle: Link
  • Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw (2026-07-28 04:43 UTC)
    • Kurz: A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating s…
    • Quelle: Link
  • NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework (2026-07-27 18:10 UTC)
    • Kurz: NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.