IT‑Sicherheits‑Digest (2026-08-21)

Aktuelle Security‑News

heise security

  • Zimbra: Warnung vor Angriffen auf Befehlsschmuggel-Lücke (2026-08-21 07:12 UTC)
    • Kurz: Das polnische CERT warnt vor Angriffen auf eine Befehlsschmuggel-Lücke in der Zimbra Collaboration Suite. Ein Update ist verfügbar.
    • Quelle: Link
  • Cyberangriff in Berlin: Behörden weiterhin offline (2026-08-21 05:11 UTC)
    • Kurz: Zwei Senatsverwaltungen sind nach einem Cyberangriff vom Landesnetz isoliert. Das hat auch Auswirkungen auf die Auszahlung von Wohngeld.
    • Quelle: Link
  • Auslegungssache 166: Datenherausgabe auf Zuruf? (2026-08-21 04:10 UTC)
    • Kurz: Neue EU-Regeln erlauben Ermittlern, Daten direkt bei Anbietern im Ausland anzufordern. Wir diskutieren über kurze Fristen und Risiken für Grundrechte.
    • Quelle: Link

BleepingComputer

  • Hackers poison arrayref Rust crate to push infostealer malware (2026-08-20 17:53 UTC)
    • Kurz: Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation. […]
    • Quelle: Link
  • Critical Elementor Pro bug exposes WordPress sites to RCE attacks (2026-08-20 14:39 UTC)
    • Kurz: A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. […]
    • Quelle: Link
  • How MSPs can catch phishing attacks email filters miss (2026-08-20 14:01 UTC)
    • Kurz: AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past …
    • Quelle: Link

The Hacker News

  • Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution (2026-08-21 06:06 UTC)
    • Kurz: Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a c…
    • Quelle: Link
  • Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads (2026-08-20 20:22 UTC)
    • Kurz: The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remo…
    • Quelle: Link
  • Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts (2026-08-20 19:59 UTC)
    • Kurz: Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe,…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.