IT‑Sicherheits‑Digest (2026-08-11)

Aktuelle Security‑News

heise security

  • Steam-Hardware: Käufer müssen nach Cyberangriff mit Betrugsmails rechnen (2026-08-11 05:54 UTC)
    • Kurz: Bei Valves Logistikpartner CEVA sind Namen und Adressen europäischer Steam-Hardware-Käufer abgeflossen. Valve warnt vor falschen Nachrichten.
    • Quelle: Link
  • Lahmer x86-Befehl hebelt triviale Schutzfunktion aus (2026-08-10 17:02 UTC)
    • Kurz: Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus.
    • Quelle: Link
  • Dobrindt baut Drohnenabwehr nach Vorfall in Leipzig massiv aus (2026-08-10 16:12 UTC)
    • Kurz: Nach dem versuchten Drohnenanschlag auf dem Leipziger Flughafen wächst der politische Druck. Innenminister Dobrindt reagiert mit mehr Abwehreinheiten.
    • Quelle: Link

BleepingComputer

  • Hackers breached a small Polish energy plant via private APN last year (2026-08-10 23:07 UTC)
    • Kurz: Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. […]
    • Quelle: Link
  • BdThemes plugins supply-chain hack creates rogue WordPress admins (2026-08-10 21:12 UTC)
    • Kurz: A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. […]
    • Quelle: Link
  • OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users (2026-08-10 19:24 UTC)
    • Kurz: OpenAI has developed a new model called “GPT 5.6 Cyber,” designed for vulnerability research, penetration testing, incident response, and remediation. […]
    • Quelle: Link

The Hacker News

  • Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine (2026-08-11 06:55 UTC)
    • Kurz: Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies h…
    • Quelle: Link
  • BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins (2026-08-11 05:48 UTC)
    • Kurz: Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily disable their downloads. “Unlike traditiona…
    • Quelle: Link
  • Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development (2026-08-10 17:29 UTC)
    • Kurz: AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, t…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • CVE-2026-68325 — CVSS n/a
    • Kurz: In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the…
    • Quelle: Link

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.