IT‑Sicherheits‑Digest (2026-09-02)

Aktuelle Security‑News

heise security

  • Jetzt patchen! Angreifer attackieren Langflow-Instanzen mit Schadcode (2026-09-02 07:21 UTC)
    • Kurz: Angreifer nutzen derzeit eine kritische Sicherheitslücke im KI-Tool Langflow aus. Ein Sicherheitspatch ist schon länger verfügbar.
    • Quelle: Link
  • „Passwort“ Folge 65: Wasserzeichen, Schlüsselprüfungen und langsame Logs (2026-09-02 07:00 UTC)
    • Kurz: Der Podcast beleuchtet Wasserzeichen für KI, Schutzmaßnahmen gegen KI, Messengersicherheit ohne KI – und mal wieder ein Thema aus der Web-P…KI.
    • Quelle: Link
  • KI-Agenten führen git-Schadcode beim Starten automatisch aus (2026-09-02 05:23 UTC)
    • Kurz: Agenten von Claude, Qwen, Grok usw. starten in manipulierten Repositories automatisch Schadcode – ohne Zutun des Anwenders, aber mit dessen vollen Rechten.
    • Quelle: Link

BleepingComputer

  • SonicWall warns of actively exploited SMA1000 zero-day flaws (2026-09-02 06:39 UTC)
    • Kurz: SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. […]
    • Quelle: Link
  • Hackers abuse Faronics Deploy admin tool to install ScreenConnect (2026-09-01 20:53 UTC)
    • Kurz: Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. […]
    • Quelle: Link
  • Aesto Health says data breach affects over 9.5 million patients (2026-09-01 19:28 UTC)
    • Kurz: Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. […]
    • Quelle: Link

The Hacker News

  • Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another (2026-09-02 07:47 UTC)
    • Kurz: Forescout Research - Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcod…
    • Quelle: Link
  • Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials (2026-09-02 07:08 UTC)
    • Kurz: Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a crit…
    • Quelle: Link
  • Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads (2026-09-02 06:56 UTC)
    • Kurz: The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authori…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • CVE-2026-19766 — CVSS 9.6 (CRITICAL)
    • Kurz: An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a …
    • Quelle: Link
  • CVE-2026-73700 — CVSS 9.0 (CRITICAL)
    • Kurz: A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administra…
    • Quelle: Link
  • CVE-2026-73701 — CVSS 9.0 (CRITICAL)
    • Kurz: An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker’s control are met…
    • Quelle: Link
  • CVE-2026-73702 — CVSS 8.8 (HIGH)
    • Kurz: A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an admi…
    • Quelle: Link
  • CVE-2026-73703 — CVSS 8.8 (HIGH)
    • Kurz: A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interfa…
    • Quelle: Link
  • CVE-2026-73704 — CVSS 8.8 (HIGH)
    • Kurz: A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrat…
    • Quelle: Link

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.