IT‑Sicherheits‑Digest (2026-08-27)

Aktuelle Security‑News

heise security

  • CISA warnt vor Angriffen auf diverse Software (2026-08-27 07:50 UTC)
    • Kurz: Angriffe wurden auf Red Hat, MS SQL, Ajax.NET, Linux, Citrix NetScaler und Gitea beobachtet. Admins sollten rasch updaten.
    • Quelle: Link
  • Angreifer können an rund 550 Lücken in Dell PowerProtect Cyber Recovery ansetzen (2026-08-27 07:28 UTC)
    • Kurz: Dells IT-Sicherheitslösung PowerProtect Cyber Recovery bietet viele Angriffspunkte. Admins sollten ihre Instanzen zeitnah über Updates absichern.
    • Quelle: Link
  • Mobilfunk: IMEI-Kennungen gelangten beim Rufaufbau unbemerkt zu Anrufern (2026-08-27 05:00 UTC)
    • Kurz: Recherchen des Bayerischen Rundfunks haben eine Schwachstelle bei Mobilfunkanbietern aufgedeckt, über die sich Handys tracken lassen könnten.
    • Quelle: Link

BleepingComputer

  • Critical Avada WordPress theme flaw enables zero-click RCE (2026-08-26 21:33 UTC)
    • Kurz: A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. […]
    • Quelle: Link
  • New GPUThor attack defeats NVIDIA ECC protection for root access (2026-08-26 18:48 UTC)
    • Kurz: A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. […]
    • Quelle: Link
  • Meta agrees to $18 billion settlement over teen social media harms (2026-08-26 16:41 UTC)
    • Kurz: Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by childre…
    • Quelle: Link

The Hacker News

  • CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs (2026-08-27 07:05 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScale…
    • Quelle: Link
  • FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations (2026-08-26 16:42 UTC)
    • Kurz: The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. Th…
    • Quelle: Link
  • Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler (2026-08-26 15:35 UTC)
    • Kurz: Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.