IT‑Sicherheits‑Digest (2026-08-05)

Aktuelle Security‑News

heise security

  • „Passwort“ Folge 63: Ein Rotes Kreuz für den Cyberspace (2026-08-05 07:00 UTC)
    • Kurz: Mit einem Gast von der ETH Zürich geht es in dieser Podcastfolge um digitale Embleme. Die sollen, analog zum Roten Kreuz, im Cyberspace vor Angriffen schützen.
    • Quelle: Link
  • Check Point: Angreifer können Security-Management-Server übernehmen (2026-08-04 12:05 UTC)
    • Kurz: Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download.
    • Quelle: Link
  • Jetzt patchen! Angreifer attackieren N-able N-central (2026-08-04 09:04 UTC)
    • Kurz: N-ables Endpoint-Managementlösung N-central ist verwundbar und Angreifer attackieren bereits Instanzen. Admins sollten zügig handeln.
    • Quelle: Link

BleepingComputer

  • OpenAI, Anthropic AI agents targeted real people and systems in cyber tests (2026-08-04 23:39 UTC)
    • Kurz: OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people out…
    • Quelle: Link
  • TP-Link patches Omada ZTP flaws allowing hackers to breach networks (2026-08-04 22:18 UTC)
    • Kurz: TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). […]
    • Quelle: Link
  • Phishing service spoofs RingCentral to steal Microsoft 365 accounts (2026-08-04 21:45 UTC)
    • Kurz: The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. […]
    • Quelle: Link

The Hacker News

  • QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer (2026-08-05 05:47 UTC)
    • Kurz: Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet …
    • Quelle: Link
  • Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens (2026-08-04 17:27 UTC)
    • Kurz: The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorizati…
    • Quelle: Link
  • Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks (2026-08-04 13:30 UTC)
    • Kurz: A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 pac…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • CVE-2026-63455 — CVSS 9.8 (CRITICAL)
    • Kurz: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful expl…
    • Quelle: Link
  • CVE-2026-63456 — CVSS 9.8 (CRITICAL)
    • Kurz: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful expl…
    • Quelle: Link

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.