IT‑Sicherheits‑Digest (2026-09-08)

Aktuelle Security‑News

heise security

  • Ein Start-up entfernt Verweigerung aus KI-Modellen und verdient daran (2026-09-08 05:54 UTC)
    • Kurz: Das Start-up Abliteration AI entfernt Verweigerungsmechanismen aus KI-Modellen. Das hilft Security-Teams, schafft aber auch neue Missbrauchsrisiken.
    • Quelle: Link
  • Sicherheitsvorfall bei Liquid Network: 320 Millionen US-Dollar in Bitcoin weg (2026-09-07 19:24 UTC)
    • Kurz: „Angebliche White-Hat-Hacker“ haben mutmaßlich rund 4.000 der 4.200 Bitcoins abgezogen, die in der Liquid-Federation-Wallet des Unternehmens verwahrt waren.
    • Quelle: Link
  • NetBSD 9.5 schließt Sicherheitslücken – und beendet Support (2026-09-07 15:45 UTC)
    • Kurz: Zum Abschied von NetBSD 9.x gibt es noch einmal einige Sicherheits- und Stabilitätskorrekturen. Ein Umstieg auf NetBSD 10 oder 11 wird ausdrücklich empfohlen.
    • Quelle: Link

BleepingComputer

  • 220 million traveler records exposed in Vietnam-linked APIS leak (2026-09-08 07:35 UTC)
    • Kurz: Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers …
    • Quelle: Link
  • Magento StyleSmuggler zero-day exploited to deploy Linux backdoor (2026-09-07 16:50 UTC)
    • Kurz: A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. […]
    • Quelle: Link
  • BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations (2026-09-07 15:39 UTC)
    • Kurz: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. […]
    • Quelle: Link

The Hacker News

  • PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution (2026-09-07 18:12 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. “Requiring prior administrative or code execution access, its …
    • Quelle: Link
  • Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks (2026-09-07 15:51 UTC)
    • Kurz: Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-i…
    • Quelle: Link
  • ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More (2026-09-07 14:36 UTC)
    • Kurz: Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precauti…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.