IT-Sicherheits-Digest (2026-08-12)
IT‑Sicherheits‑Digest (2026-08-12) Aktuelle Security‑News heise security Patchday: Angreifer attackieren Windows und verschaffen sich System-Rechte (2026-08-12 07:25 UTC) Kurz: Microsoft kümmert sich um rund 400 Sicherheitsprobleme in Azure, Office, Windows & Co. Mehrere Lücken gelten als kritisch. Quelle: Link Patch seit Mai verfügbar: Ransomware attackiert Microsoft Sharepoint (2026-08-11 19:39 UTC) Kurz: Eine schwere Sicherheitslücke in Microsoft SharePoint wird nun von Ransomware ausgenutzt. Ein Patch steht bereit, ungeschützte Systeme auch. Quelle: Link Brandenburg: Cyberangriff legt IT-System der Gedenkstätten lahm (2026-08-11 16:43 UTC) Kurz: Die Stiftung Brandenburgische Gedenkstätten wurde Opfer eines Ransomware-Angriffs. IT-Systeme sind derzeit außer Betrieb, ein Datenabfluss wird vermutet. Quelle: Link BleepingComputer Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse (2026-08-12 01:15 UTC) Kurz: Google says Chrome’s anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. […] Quelle: Link DeadLock ransomware uses blockchain to resist infrastructure takedown (2026-08-11 22:15 UTC) Kurz: The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. […] Quelle: Link Sandworm hackers target IT pros with trojanized WireGuard VPN client (2026-08-11 21:07 UTC) Kurz: Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. […] Quelle: Link The Hacker News SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code (2026-08-12 07:31 UTC) Kurz: SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on … Quelle: Link ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access (2026-08-12 06:41 UTC) Kurz: The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Micro… Quelle: Link Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS (2026-08-12 06:15 UTC) Kurz: Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-203… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.