IT‑Sicherheits‑Digest (2026-08-20)

Aktuelle Security‑News

heise security

  • Cisco-Sicherheitslücken: Angreifer können Anmeldung von Secure Workload umgehen (2026-08-20 07:41 UTC)
    • Kurz: Es sind wichtige Sicherheitsupdates für unter anderem Cisco BroadWorks, Crosswork Security und Secure Workload erschienen.
    • Quelle: Link
  • Anonymisierendes Linux: Tails 7.11 pflegt Software und schließt Schwachstellen (2026-08-20 07:36 UTC)
    • Kurz: Die Entwickler der anonymisierenden Linux-Distribution Tails für USB-Sticks aktualisieren in Version 7.11 Kernkomponenten.
    • Quelle: Link
  • Windows-Updates: Microsoft untersucht Spieleprobleme (2026-08-20 06:50 UTC)
    • Kurz: Nach der Installation der Windows-Updates vom August-Patchday erhält Microsoft vermehrt Meldungen zu Problemen mit einigen Spielen.
    • Quelle: Link

BleepingComputer

  • Microsoft says August Windows updates may cause gaming issues (2026-08-20 06:51 UTC)
    • Kurz: Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. […]
    • Quelle: Link
  • OpenAI confirms ChatGPT is down as logins and signups fail (2026-08-20 00:20 UTC)
    • Kurz: ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. […]
    • Quelle: Link
  • Rogue ransomware affiliate poses as recovery firm to steal payments (2026-08-19 20:59 UTC)
    • Kurz: A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee…
    • Quelle: Link

The Hacker News

  • Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code (2026-08-20 06:04 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS sco…
    • Quelle: Link
  • Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second (2026-08-19 19:02 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate…
    • Quelle: Link
  • OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior (2026-08-19 18:06 UTC)
    • Kurz: OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert anothe…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.