IT‑Sicherheits‑Digest (2026-08-07)

Aktuelle Security‑News

heise security

  • Auslegungssache 165: Europas Datenschutz in Bewegung (2026-08-07 04:10 UTC)
    • Kurz: Der c’t-Datenschutz-Podcast beleuchtet den Datentransfer in die USA, neue Entscheidungen des EuGH und die stockende Reform der EU-Digitalregeln.
    • Quelle: Link
  • Cyberkrimineller bekennt sich der Millionen-Erpressung von Cloud-Kunden schuldig (2026-08-07 03:03 UTC)
    • Kurz: Nach dem Datenklau beim US-Cloud-Anbieter Snowflake hat ein Kanadier Millionen von dessen Kunden erpresst. Nach Schuldbekenntnis drohen ihm 2 bis 30 Jahre Haft.
    • Quelle: Link
  • Fehlende Kontaktmöglichkeit: Deutschland verschläft Sicherheit per security.txt (2026-08-06 15:40 UTC)
    • Kurz: Nur 1,8 Prozent der deutschen Webseiten bieten eine standardisierte security.txt an. Das BSI warnt vor den Risiken und verweist auf kommende Meldepflichten.
    • Quelle: Link

BleepingComputer

  • OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it (2026-08-06 22:48 UTC)
    • Kurz: OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. […]
    • Quelle: Link
  • ClickFix attack pushes macOS infostealer for crypto theft attacks (2026-08-06 22:37 UTC)
    • Kurz: A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. […]
    • Quelle: Link
  • Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (2026-08-06 20:07 UTC)
    • Kurz: A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. […]
    • Quelle: Link

The Hacker News

  • TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign (2026-08-07 06:50 UTC)
    • Kurz: A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sig…
    • Quelle: Link
  • New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts (2026-08-06 17:58 UTC)
    • Kurz: Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed …
    • Quelle: Link
  • Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs (2026-08-06 17:13 UTC)
    • Kurz: Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software,…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • CVE-2026-67261 — CVSS 9.8 (CRITICAL)
    • Kurz: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit …
    • Quelle: Link
  • CVE-2026-54489 — CVSS 9.1 (CRITICAL)
    • Kurz: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulne…
    • Quelle: Link

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.