IT‑Sicherheits‑Digest (2026-08-06)

Aktuelle Security‑News

heise security

  • Auch KI von Meta hackte sich in eine andere Firma (2026-08-06 05:04 UTC)
    • Kurz: Nach OpenAI und Anthropic räumt nun auch Meta ein, dass sich eigene KI-Software in fremde Systeme gehackt hat.
    • Quelle: Link
  • Weitere KI-Attacke: Modell schleust Schwachstelle ein und manipuliert Menschen (2026-08-05 10:03 UTC)
    • Kurz: Ein KI-Modell von Anthropic versuchte, eine Schwachstelle in Software einzuschleusen und manipulierte Menschen per E-Mail.
    • Quelle: Link
  • Sicherheitsupdates: TP-Links Netzwerk-Ökosystem Omada ist kompromittierbar (2026-08-05 09:32 UTC)
    • Kurz: Sicherheitsforscher entdecken unter anderem kritische Lücken in TP-Link Omada, die sich auf weitere Netzwerkkomponenten ausweiten.
    • Quelle: Link

BleepingComputer

  • Ransom Cartel ransomware creator sentenced to 16 years in prison (2026-08-05 23:00 UTC)
    • Kurz: Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. […]
    • Quelle: Link
  • Canadian pleads guilty to Snowflake cloud data-theft attacks (2026-08-05 21:53 UTC)
    • Kurz: A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. […]
    • Quelle: Link
  • Hackers run khunt post-exploitation toolkit from Oracle database (2026-08-05 19:55 UTC)
    • Kurz: Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. […]
    • Quelle: Link

The Hacker News

  • Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People (2026-08-06 06:04 UTC)
    • Kurz: Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at leas…
    • Quelle: Link
  • Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures (2026-08-05 18:44 UTC)
    • Kurz: A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for wee…
    • Quelle: Link
  • OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes (2026-08-05 18:33 UTC)
    • Kurz: OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that e…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • CVE-2026-63457 — CVSS 6.5 (MEDIUM)
    • Kurz: A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
    • Quelle: Link

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.