IT‑Sicherheits‑Digest (2026-08-18)

Aktuelle Security‑News

heise security

  • OWASP Top 10 für KI-Anwendungen: Risiken mit Daten belegt (2026-08-18 07:43 UTC)
    • Kurz: Die neue Rangliste der größten Sicherheitsrisiken von KI-Anwendungen nennt wenig Neues. Die Relevanz der bestehenden Punkte unterfüttert OWASP nun mit Daten.
    • Quelle: Link
  • Weitere Sicherheitsupdates: iOS 26.6.1, macOS 26.6.2 und mehr veröffentlicht (2026-08-18 07:18 UTC)
    • Kurz: Kleine Aktualisierung, viele Lücken: Gut 30 Sicherheitslöcher hat Apple in insgesamt sechs Betriebssystemen gestopft. KI dürfte geholfen haben.
    • Quelle: Link
  • Webmailer Roundcube: Updates stopfen zahlreiche Sicherheitslecks (2026-08-18 07:06 UTC)
    • Kurz: Der Webmailer Roundcube ist in aktualisierten Fassungen verfügbar. Sie schließen etwa Lücken, die Einschleusen von Schadcode erlauben.
    • Quelle: Link

BleepingComputer

  • Hacker claims 3.6 million Azure account records stolen from major companies (2026-08-17 19:35 UTC)
    • Kurz: A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. […]
    • Quelle: Link
  • Pokémon Center data breach exposes customer info, cancels some orders (2026-08-17 19:12 UTC)
    • Kurz: Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. […]
    • Quelle: Link
  • Microsoft confirms GitHub is down worldwide (2026-08-17 14:47 UTC)
    • Kurz: GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. […]
    • Quelle: Link

The Hacker News

  • CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE (2026-08-18 06:34 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-nativ…
    • Quelle: Link
  • Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects (2026-08-17 21:03 UTC)
    • Kurz: GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or…
    • Quelle: Link
  • Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection (2026-08-17 18:44 UTC)
    • Kurz: Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to exe…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.