IT‑Sicherheits‑Digest (2026-09-04)

Aktuelle Security‑News

heise security

  • Jetzt patchen! Es laufen derzeit Schadcode-Attacken auf Chrome (2026-09-04 06:48 UTC)
    • Kurz: Google hat mehrere Sicherheitslücken im Webbrowser Chrome geschlossen. Eine Schwachstelle nutzen Angreifer bereits aus.
    • Quelle: Link
  • Auslegungssache 167: Datenschutz mit System (2026-09-04 04:10 UTC)
    • Kurz: Wie Unternehmen Datenschutz praxistauglich organisieren, erklärt Beraterin Regina Mühlich im c’t-Datenschutz-Podcast.
    • Quelle: Link
  • Kehrtwende bei Cybersicherheit: Bund gibt Plan für BSI-Grundgesetzänderung auf (2026-09-03 16:58 UTC)
    • Kurz: Trotz der verschärften Bedrohungslage und verstärkter IT-Angriffe verzichtet die Bundesregierung überraschend auf eine Verfassungsänderung zur Stärkung des BSI.
    • Quelle: Link

BleepingComputer

  • French hospital fined €500,000 after breach exposes data of 727,000 (2026-09-03 22:01 UTC)
    • Kurz: France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. […]
    • Quelle: Link
  • Coder’s registry infrastructure compromised to push malicious modules (2026-09-03 20:04 UTC)
    • Kurz: Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. […]
    • Quelle: Link
  • HPE patches critical ArubaOS-CX remote code execution flaw (2026-09-03 18:28 UTC)
    • Kurz: Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. […]
    • Quelle: Link

The Hacker News

  • ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories (2026-09-03 18:02 UTC)
    • Kurz: The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, …
    • Quelle: Link
  • Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root (2026-09-03 15:52 UTC)
    • Kurz: Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7…
    • Quelle: Link
  • BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory (2026-09-03 15:26 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. “Unlike the standard infostealer m…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.