IT‑Sicherheits‑Digest (2026-08-25)

Aktuelle Security‑News

heise security

  • Angreifer nehmen Oracle Weblogic und HTTP-Server ins Visier (2026-08-25 06:11 UTC)
    • Kurz: Angreifer missbrauchen eine Sicherheitslücke in Oracle HTTP-Server und Weblogic Server, die komplette Kompromittierung ermöglicht.
    • Quelle: Link
  • Kriminalisierung: Informatiker verlangen Freipass für IT-Sicherheitsforscher (2026-08-25 03:30 UTC)
    • Kurz: Die Gesellschaft für Informatik fordert die Bundesregierung auf, ethische Hacker endlich wirksam vor Strafverfolgung zu schützen.
    • Quelle: Link
  • AliExpress trackt Nutzer via unhörbarem Audio-Fingerprinting (2026-08-24 15:35 UTC)
    • Kurz: AliExpress nutzte die Web Audio API, um Geräte per unhörbarem Audiosignal zu identifizieren. Ein Entwickler entdeckte das Tracking durch Bluetooth-Probleme.
    • Quelle: Link

BleepingComputer

  • Unpatched Calix flaw lets hackers bypass NAT to expose internal devices (2026-08-24 21:14 UTC)
    • Kurz: An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the publi…
    • Quelle: Link
  • Hackers target WordPress sites in miniOrange auth bypass attacks (2026-08-24 19:26 UTC)
    • Kurz: Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. […]
    • Quelle: Link
  • TikTok reaches $400M settlement with US over COPPA violations (2026-08-24 17:56 UTC)
    • Kurz: The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA). […]
    • Quelle: Link

The Hacker News

  • Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data (2026-08-25 06:12 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence …
    • Quelle: Link
  • Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt (2026-08-24 17:41 UTC)
    • Kurz: If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at…
    • Quelle: Link
  • Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning (2026-08-24 17:41 UTC)
    • Kurz: Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts …
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • CVE-2026-66908 — CVSS n/a
    • Kurz: Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authen…
    • Quelle: Link

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.