„Passwort“ Folge 63: Ein Rotes Kreuz für den Cyberspace (2026-08-05 07:00 UTC)
Kurz: Mit einem Gast von der ETH Zürich geht es in dieser Podcastfolge um digitale Embleme. Die sollen, analog zum Roten Kreuz, im Cyberspace vor Angriffen schützen.
Check Point: Angreifer können Security-Management-Server übernehmen (2026-08-04 12:05 UTC)
Kurz: Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download.
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests (2026-08-04 23:39 UTC)
Kurz: OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people out…
Kurz: TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). […]
Phishing service spoofs RingCentral to steal Microsoft 365 accounts (2026-08-04 21:45 UTC)
Kurz: The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. […]
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer (2026-08-05 05:47 UTC)
Kurz: Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet …
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens (2026-08-04 17:27 UTC)
Kurz: The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorizati…
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks (2026-08-04 13:30 UTC)
Kurz: A credential-stealing npm worm that first appeared in keyv@6.0.0
spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 pac…
Kurz: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful expl…
Kurz: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful expl…