IT‑Sicherheits‑Digest (2026-07-31)

Aktuelle Security‑News

heise security

  • SolarWinds Web Help Desk: Update bessert umgehbare Authentifizierung aus (2026-07-31 07:11 UTC)
    • Kurz: SolarWinds schließt Sicherheitslücken in Web Help Desk. Eine gilt als kritisch und ermöglicht Angreifern, die Authentifizierung zu umgehen.
    • Quelle: Link
  • Russische Akteure greifen über Outlook-Web-Access-Lücke an (2026-07-31 06:24 UTC)
    • Kurz: Eine Sicherheitslücke in OWA ermöglicht durch Anzeigen von Mails das Ausführen von JavaScript-Code. Russische Akteure nutzen das aus.
    • Quelle: Link
  • KI-Attacke: Auch Anthropic-Modelle griffen echte Unternehmen an (2026-07-31 05:16 UTC)
    • Kurz: Nach einem Vorfall bei OpenAI räumt nun auch Anthropic ein, dass eigene KI-Modelle bei Sicherheitstests ungeplant echte Firmensysteme angegriffen haben.
    • Quelle: Link

BleepingComputer

  • Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests (2026-07-31 00:57 UTC)
    • Kurz: One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecti…
    • Quelle: Link
  • South Korea fines telco giant KT $39 million for customer data breach (2026-07-30 22:28 UTC)
    • Kurz: South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. […]
    • Quelle: Link
  • JetBrains warns of critical TeamCity remote code execution flaw (2026-07-30 22:01 UTC)
    • Kurz: JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. […]
    • Quelle: Link

The Hacker News

  • DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware (2026-07-30 18:18 UTC)
    • Kurz: Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of…
    • Quelle: Link
  • ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories (2026-07-30 15:25 UTC)
    • Kurz: A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems…
    • Quelle: Link
  • Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database (2026-07-30 13:34 UTC)
    • Kurz: A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chai…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • CVE-2026-59309 — CVSS 9.8 (CRITICAL)
    • Kurz: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized acces…
    • Quelle: Link
  • CVE-2026-59310 — CVSS 9.8 (CRITICAL)
    • Kurz: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
    • Quelle: Link
  • CVE-2026-47876 — CVSS 9.3 (CRITICAL)
    • Kurz: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploi…
    • Quelle: Link
  • CVE-2026-41703 — CVSS 7.6 (HIGH)
    • Kurz: VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more …
    • Quelle: Link
  • CVE-2026-41709 — CVSS 2.7 (LOW)
    • Kurz: VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
    • Quelle: Link

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.