IT‑Sicherheits‑Digest (2026-08-01)

Aktuelle Security‑News

heise security

  • IBM App Connect Enterprise: Angreifer können Daten manipulieren (2026-07-31 09:02 UTC)
    • Kurz: IBMs Middleware-Plattform App Connect Enterprise ist über mehrere Sicherheitslücken attackierbar. Updates sind verfügbar.
    • Quelle: Link
  • „CosmosEscape“ ermöglichte Übernahme aller Microsoft-Azure-Datenbanken (2026-07-31 09:02 UTC)
    • Kurz: Eine Verkettung von Sicherheitslücken ermöglichte vollen Zugang zu allen Azure-Cosmos-DB-Datenbanken.
    • Quelle: Link
  • Gefahren beim Online-Spiel – Wie sich Jugendliche schützen (2026-07-31 04:55 UTC)
    • Kurz: Cybergrooming zielt oft auf junge Menschen ab. Durch Bildung und Prävention können sich Jugendliche jedoch effektiv vor gefährlichen Kontakten schützen.
    • Quelle: Link

BleepingComputer

  • Amgen says cloud data breach exposed patient health, proprietary info (2026-07-31 22:16 UTC)
    • Kurz: Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. […]
    • Quelle: Link
  • Arch Linux disables AUR package adoption to stop malware flood (2026-07-31 21:38 UTC)
    • Kurz: The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. […]
    • Quelle: Link
  • Online ad firm Adform’s script compromised to steal cryptocurrency (2026-07-31 21:09 UTC)
    • Kurz: Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker. […
    • Quelle: Link

The Hacker News

  • Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction (2026-08-01 07:12 UTC)
    • Kurz: Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CV…
    • Quelle: Link
  • Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware (2026-08-01 06:29 UTC)
    • Kurz: A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track…
    • Quelle: Link
  • Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk (2026-07-31 18:52 UTC)
    • Kurz: A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.