IT‑Sicherheits‑Digest (2026-09-06)

Aktuelle Security‑News

heise security

  • Draht statt Sprengstoff: Angriffe auf Umspannwerke und Grenzen der Netzredundanz (2026-09-05 14:41 UTC)
    • Kurz: Sabotage an Umspannwerken zeigt, wie leicht Gigawatt vom Netz gehen, warum Schutztechnik Blackouts verhinderte – und wo der Kritis-Schutz hinterherhinkt.
    • Quelle: Link

BleepingComputer

  • Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain (2026-09-05 14:29 UTC)
    • Kurz: A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). […]
    • Quelle: Link
  • OpenAI admits it didn’t disclose rogue AI wiki hijacking incident (2026-09-05 11:11 UTC)
    • Kurz: OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model “misalignment” rather than a security …
    • Quelle: Link

The Hacker News

  • Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores (2026-09-05 20:14 UTC)
    • Kurz: Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory …
    • Quelle: Link
  • Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials (2026-09-05 16:52 UTC)
    • Kurz: JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environm…
    • Quelle: Link
  • Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code (2026-09-05 16:05 UTC)
    • Kurz: Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.