IT‑Sicherheits‑Digest (2026-08-28)

Aktuelle Security‑News

heise security

  • TeamViewer stopft Codeschmuggel-Leck (2026-08-28 07:46 UTC)
    • Kurz: Die TeamViewer-Clients können Angreifern das Ausführen von Schadcode ermöglichen. Updates stopfen die hochriskanten Sicherheitslücken.
    • Quelle: Link
  • Jetzt patchen! Angreifer attackieren PaperCut NG/MF (2026-08-28 07:02 UTC)
    • Kurz: Der Hersteller der Druckerverwaltungssoftware PaperCut NG/MF hat ein Notfall-Sicherheitsupdate veröffentlicht.
    • Quelle: Link
  • Windows-Update-Vorschau: Taskleiste an allen Seiten positionierbar (2026-08-28 06:14 UTC)
    • Kurz: Die Vorschau auf die Windows-Updates zum kommenden Microsoft-Patchday bringt Änderungen für die Taskleiste und die Administrator Protection.
    • Quelle: Link

BleepingComputer

  • Nearly 700 rogue AI agents coordinated in the Hugging Face attack (2026-08-27 21:38 UTC)
    • Kurz: New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI’s internal IM1 model coordinated the compromise through an unauthorized message board. […]
    • Quelle: Link
  • PaperCut warns of NG, MF flaw exploited in zero-day attacks (2026-08-27 16:31 UTC)
    • Kurz: PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. […]
    • Quelle: Link
  • Manchester Airports Group says hackers stole travelers’ data (2026-08-27 16:12 UTC)
    • Kurz: The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. […]
    • Quelle: Link

The Hacker News

  • OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face (2026-08-27 18:36 UTC)
    • Kurz: OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the …
    • Quelle: Link
  • Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE (2026-08-27 15:13 UTC)
    • Kurz: Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files …
    • Quelle: Link
  • ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories (2026-08-27 15:12 UTC)
    • Kurz: A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.