IT-Sicherheits-Digest (2026-04-30)
IT‑Sicherheits‑Digest (2026-04-30) Aktuelle Security‑News heise security Digitale Rasterfahndung: Regierung stimmt für Biometrie-Abgleich und KI-Analysen (2026-04-29 14:32 UTC) Kurz: Die Bundesregierung will BKA und Bundespolizei die automatisierte Rasterfahndung im Netz erlauben. Kritiker warnen vor Massenüberwachung. Quelle: Link IT-Sicherheitsplattform: Anreifer können Wazuh kompromittieren (2026-04-29 12:20 UTC) Kurz: In der aktuellen Wazuh-Version haben die Entwickler mehrere Schwachstellen geschlossen. Es kann Schadcode auf Systeme gelangen. Quelle: Link GitHub und GitHub Enterprise Server: Codeschmuggel per Push (2026-04-29 11:58 UTC) Kurz: In GitHub und GitHub Enterprise Server können Angreifer mit Push-Rechten auf Repositories Schadcode einschleusen. Updates korrigieren das. Quelle: Link BleepingComputer Official SAP npm packages compromised to steal credentials (2026-04-29 22:43 UTC) Kurz: Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers’ systems. […] Quelle: Link Popular WordPress redirect plugin hid dormant backdoor for years (2026-04-29 22:13 UTC) Kurz: The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users’ sites. […] Quelle: Link Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining (2026-04-29 20:50 UTC) Kurz: Hackers are exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptominers on developers’ servers. […] Quelle: Link The Hacker News SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack (2026-04-29 16:26 UTC) Kurz: Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Goo… Quelle: Link New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs (2026-04-29 14:43 UTC) Kurz: Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic’s Claude Opus large language model (LLM). The package in question is “@validate-sdk/v2,” which … Quelle: Link Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks (2026-04-29 12:02 UTC) Kurz: In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren’t just talking about AI writing better phishing emails … Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den letzten 24h. VMware ESXi/vCenter (7.x) (NVD‑Abfrage fehlgeschlagen für ‘vCenter’: HTTP Error 429: Too Many Requests) VMware ESXi/vCenter (7.x) Keine neuen Treffer in den letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).