IT‑Sicherheits‑Digest (2026-08-29)

Aktuelle Security‑News

heise security

  • Wie OpenAI die Cybersecurity mit fiesen Tricks vor den eigenen Karren spannt (2026-08-28 12:34 UTC)
    • Kurz: OpenAIs Cybersecurity-Aufruf ist ein manipulativer Trick. Denn natürlich brauchen wir mehr Security – aber nicht zwingend von denen, meint Jürgen Schmidt.
    • Quelle: Link
  • (OEM-)China-Router von ZBT mit Backdoors (2026-08-28 10:39 UTC)
    • Kurz: IT-Forscher haben Router vom OEM-Hersteller ZBT untersucht, die weltweit von Anbietern verkauft werden. Darin fanden sie Backdoors.
    • Quelle: Link
  • Zwei kritische Lücken in Next.js – Remote-Code-Ausführung unter Windows (2026-08-28 10:11 UTC)
    • Kurz: Die zwei kritischen von Vercel gemeldeten Lücken im JavaScript-Framework Next.js ermöglichen es Angreifern, Code auszuführen.
    • Quelle: Link

BleepingComputer

  • McKesson discloses breach after ShinyHunters claims patient data theft (2026-08-28 22:40 UTC)
    • Kurz: Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million p…
    • Quelle: Link
  • PaperCut releases second emergency patch for exploited flaws (2026-08-28 19:08 UTC)
    • Kurz: PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. […]
    • Quelle: Link
  • GiveWP WordPress donation plugin flaw lets hackers execute server commands (2026-08-28 18:18 UTC)
    • Kurz: A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. […]
    • Quelle: Link

The Hacker News

  • Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network (2026-08-28 21:30 UTC)
    • Kurz: Berlin’s state government has confirmed that it is the target of an extortion attempt following the August compromise of the city’s state administrative network, and said it will not meet the extortionists’ demands. The same statement discl…
    • Quelle: Link
  • Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable (2026-08-28 20:38 UTC)
    • Kurz: Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rate…
    • Quelle: Link
  • Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication (2026-08-28 17:12 UTC)
    • Kurz: Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. “This vulnerability gives an un…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • CVE-2026-55841 — CVSS 7.5 (HIGH)
    • Kurz: Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/…
    • Quelle: Link

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • CVE-2026-41012 — CVSS 7.7 (HIGH)
    • Kurz: Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, lea…
    • Quelle: Link

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.