IT‑Sicherheits‑Digest (2026-08-12)

Aktuelle Security‑News

heise security

  • Patchday: Angreifer attackieren Windows und verschaffen sich System-Rechte (2026-08-12 07:25 UTC)
    • Kurz: Microsoft kümmert sich um rund 400 Sicherheitsprobleme in Azure, Office, Windows & Co. Mehrere Lücken gelten als kritisch.
    • Quelle: Link
  • Patch seit Mai verfügbar: Ransomware attackiert Microsoft Sharepoint (2026-08-11 19:39 UTC)
    • Kurz: Eine schwere Sicherheitslücke in Microsoft SharePoint wird nun von Ransomware ausgenutzt. Ein Patch steht bereit, ungeschützte Systeme auch.
    • Quelle: Link
  • Brandenburg: Cyberangriff legt IT-System der Gedenkstätten lahm (2026-08-11 16:43 UTC)
    • Kurz: Die Stiftung Brandenburgische Gedenkstätten wurde Opfer eines Ransomware-Angriffs. IT-Systeme sind derzeit außer Betrieb, ein Datenabfluss wird vermutet.
    • Quelle: Link

BleepingComputer

  • Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse (2026-08-12 01:15 UTC)
    • Kurz: Google says Chrome’s anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. […]
    • Quelle: Link
  • DeadLock ransomware uses blockchain to resist infrastructure takedown (2026-08-11 22:15 UTC)
    • Kurz: The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. […]
    • Quelle: Link
  • Sandworm hackers target IT pros with trojanized WireGuard VPN client (2026-08-11 21:07 UTC)
    • Kurz: Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. […]
    • Quelle: Link

The Hacker News

  • SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code (2026-08-12 07:31 UTC)
    • Kurz: SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on …
    • Quelle: Link
  • ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access (2026-08-12 06:41 UTC)
    • Kurz: The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Micro…
    • Quelle: Link
  • Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS (2026-08-12 06:15 UTC)
    • Kurz: Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-203…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.