IT‑Sicherheits‑Digest (2026-09-01)

Aktuelle Security‑News

heise security

  • KI-Agenten in der Container-Security: Erfahrungen aus der Praxis (2026-09-01 05:53 UTC)
    • Kurz: Zero-CVE-Images durch Agentic AI: Red Hats Hummingbird-Projekt zeigt, wie KI-Agenten Container-Security automatisieren – und wo Menschen unverzichtbar bleiben.
    • Quelle: Link
  • Bayern: Anstieg bei Cyberangriffen durch ausländische Nachrichtendienste (2026-09-01 05:14 UTC)
    • Kurz: Ob Online-Erpressung oder Sabotage: Cyberkriminalität ist Alltag, ein Rückgang nicht in Sicht. Laut Staatsregierung sind Geheimdienste dreier Staaten beteiligt.
    • Quelle: Link
  • PayPal-App streikt auf GrapheneOS: Ursache und Lösung (2026-08-31 14:06 UTC)
    • Kurz: Auf Smartphones mit GrapheneOS startet die PayPal-App derzeit nicht. Der Grund ist ein fehlerhafter Manipulationsschutz, der sich jedoch umgehen lässt.
    • Quelle: Link

BleepingComputer

  • Recently patched PaperCut zero-days used in data theft attacks (2026-09-01 07:48 UTC)
    • Kurz: Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. […]
    • Quelle: Link
  • Cronos blockchain restarts after $74 million Tectonic exploit (2026-08-31 20:47 UTC)
    • Kurz: The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. […]
    • Quelle: Link
  • Microsoft warns of TerminalFix attacks deploying reverse tunnels (2026-08-31 18:51 UTC)
    • Kurz: A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. […]
    • Quelle: Link

The Hacker News

  • Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity (2026-09-01 07:22 UTC)
    • Kurz: Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation…
    • Quelle: Link
  • North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales (2026-08-31 17:24 UTC)
    • Kurz: Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected work…
    • Quelle: Link
  • ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More (2026-08-31 13:50 UTC)
    • Kurz: The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even …
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.