IT‑Sicherheits‑Digest (2026-08-19)

Aktuelle Security‑News

heise security

  • Google führt erweiterten Sideloading-Ablauf für Android schrittweise ein (2026-08-19 07:20 UTC)
    • Kurz: Google startet den „Advanced Flow“ für das Sideloading von Apps. Nutzer müssen bei nicht verifizierten Entwicklern künftig eine 24-stündige Wartezeit einplanen.
    • Quelle: Link
  • „Passwort“ Folge 64: Alarmierende Ausbrüche agentischer Angreifer (2026-08-19 07:00 UTC)
    • Kurz: PR-Stunt oder reale Bedrohung? Die Passwort-Hosts finden, dass die Agenten-Angriffe von Anthropic und Co. viel mit Schludrigkeit und Desinteresse zu tun haben.
    • Quelle: Link
  • Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS (2026-08-19 06:04 UTC)
    • Kurz: Die IT-Sicherheitsbehörde CISA warnt aktuell vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS.
    • Quelle: Link

BleepingComputer

  • Comcast turns your Xfinity WiFi into a home motion detector (2026-08-18 20:14 UTC)
    • Kurz: Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. […]
    • Quelle: Link
  • Clop created custom web shell for Windchill data theft attacks (2026-08-18 17:29 UTC)
    • Kurz: A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. […]
    • Quelle: Link
  • Your Controls Block Known Attacks. What About the Behavior? (2026-08-18 14:01 UTC)
    • Kurz: Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security’s Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is nee…
    • Quelle: Link

The Hacker News

  • Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps (2026-08-18 17:47 UTC)
    • Kurz: Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim’s Copilo…
    • Quelle: Link
  • Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets (2026-08-18 17:44 UTC)
    • Kurz: Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing ma…
    • Quelle: Link
  • Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 (2026-08-18 16:58 UTC)
    • Kurz: A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a fee ranging from $20,000 to $60,000.…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • CVE-2026-21580 — CVSS n/a
    • Kurz: This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.…
    • Quelle: Link
  • CVE-2026-21582 — CVSS n/a
    • Kurz: This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vuln…
    • Quelle: Link
  • CVE-2026-21584 — CVSS n/a
    • Kurz: This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of…
    • Quelle: Link

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.