IT-Sicherheits-Digest (2026-08-12)

IT‑Sicherheits‑Digest (2026-08-12) Aktuelle Security‑News heise security Patchday: Angreifer attackieren Windows und verschaffen sich System-Rechte (2026-08-12 07:25 UTC) Kurz: Microsoft kümmert sich um rund 400 Sicherheitsprobleme in Azure, Office, Windows & Co. Mehrere Lücken gelten als kritisch. Quelle: Link Patch seit Mai verfügbar: Ransomware attackiert Microsoft Sharepoint (2026-08-11 19:39 UTC) Kurz: Eine schwere Sicherheitslücke in Microsoft SharePoint wird nun von Ransomware ausgenutzt. Ein Patch steht bereit, ungeschützte Systeme auch. Quelle: Link Brandenburg: Cyberangriff legt IT-System der Gedenkstätten lahm (2026-08-11 16:43 UTC) Kurz: Die Stiftung Brandenburgische Gedenkstätten wurde Opfer eines Ransomware-Angriffs. IT-Systeme sind derzeit außer Betrieb, ein Datenabfluss wird vermutet. Quelle: Link BleepingComputer Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse (2026-08-12 01:15 UTC) Kurz: Google says Chrome’s anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. […] Quelle: Link DeadLock ransomware uses blockchain to resist infrastructure takedown (2026-08-11 22:15 UTC) Kurz: The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. […] Quelle: Link Sandworm hackers target IT pros with trojanized WireGuard VPN client (2026-08-11 21:07 UTC) Kurz: Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. […] Quelle: Link The Hacker News SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code (2026-08-12 07:31 UTC) Kurz: SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on … Quelle: Link ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access (2026-08-12 06:41 UTC) Kurz: The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Micro… Quelle: Link Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS (2026-08-12 06:15 UTC) Kurz: Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-203… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 12, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-08-11)

IT‑Sicherheits‑Digest (2026-08-11) Aktuelle Security‑News heise security Steam-Hardware: Käufer müssen nach Cyberangriff mit Betrugsmails rechnen (2026-08-11 05:54 UTC) Kurz: Bei Valves Logistikpartner CEVA sind Namen und Adressen europäischer Steam-Hardware-Käufer abgeflossen. Valve warnt vor falschen Nachrichten. Quelle: Link Lahmer x86-Befehl hebelt triviale Schutzfunktion aus (2026-08-10 17:02 UTC) Kurz: Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus. Quelle: Link Dobrindt baut Drohnenabwehr nach Vorfall in Leipzig massiv aus (2026-08-10 16:12 UTC) Kurz: Nach dem versuchten Drohnenanschlag auf dem Leipziger Flughafen wächst der politische Druck. Innenminister Dobrindt reagiert mit mehr Abwehreinheiten. Quelle: Link BleepingComputer Hackers breached a small Polish energy plant via private APN last year (2026-08-10 23:07 UTC) Kurz: Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. […] Quelle: Link BdThemes plugins supply-chain hack creates rogue WordPress admins (2026-08-10 21:12 UTC) Kurz: A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. […] Quelle: Link OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users (2026-08-10 19:24 UTC) Kurz: OpenAI has developed a new model called “GPT 5.6 Cyber,” designed for vulnerability research, penetration testing, incident response, and remediation. […] Quelle: Link The Hacker News Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine (2026-08-11 06:55 UTC) Kurz: Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies h… Quelle: Link BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins (2026-08-11 05:48 UTC) Kurz: Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily disable their downloads. “Unlike traditiona… Quelle: Link Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development (2026-08-10 17:29 UTC) Kurz: AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, t… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches CVE-2026-68325 — CVSS n/a Kurz: In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the… Quelle: Link VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 11, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-08-10)

IT‑Sicherheits‑Digest (2026-08-10) Aktuelle Security‑News heise security Jetzt patchen! Admin-Attacken auf Metabase beobachtet (2026-08-10 07:41 UTC) Kurz: Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln. Quelle: Link BleepingComputer Keine neuen, nicht bereits gestern gelisteten Meldungen im 36h-Fenster. The Hacker News OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause (2026-08-10 05:50 UTC) Kurz: OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. I… Quelle: Link Lageeinschätzung Heute sind nur wenige frische, nicht doppelte Meldungen im 36h-Fenster aufgelaufen. Das ist typisch nach Wochenenden/Feiertagen oder wenn Feeds erst später am Vormittag aktualisieren. Ausgeblendet: 83 ältere oder bereits gestern verwendete Feed-Einträge. Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) CVE-2026-19369 — CVSS 5.3 (MEDIUM) Kurz: A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl result… Quelle: Link HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 10, 2026 · 2 min · Betty

IT-Sicherheits-Digest (2026-08-09)

IT‑Sicherheits‑Digest (2026-08-09) Aktuelle Security‑News heise security Google-Threat-Intelligence-Chefin: Dank KI „mehr Zero-Days als je zuvor“ (2026-08-08 08:24 UTC) Kurz: Bug-Bounty-Programme werden mit Fehlerberichten geflutet, User und Firmen leiden unter KI-Angriffen: Der Security-Bereich ändert sich rasant, sagt Sandra Joyce. Quelle: Link BleepingComputer Hackers breach TrueConf to trojanize client installers with backdoors (2026-08-08 14:16 UTC) Kurz: The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. […] Quelle: Link The Hacker News Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers (2026-08-08 08:54 UTC) Kurz: Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different rou… Quelle: Link New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens (2026-08-08 08:03 UTC) Kurz: New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture p… Quelle: Link Lageeinschätzung Heute sind nur wenige frische, nicht doppelte Meldungen im 36h-Fenster aufgelaufen. Das ist typisch nach Wochenenden/Feiertagen oder wenn Feeds erst später am Vormittag aktualisieren. Ausgeblendet: 81 ältere oder bereits gestern verwendete Feed-Einträge. Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 9, 2026 · 2 min · Betty

IT-Sicherheits-Digest (2026-08-08)

IT‑Sicherheits‑Digest (2026-08-08) Aktuelle Security‑News heise security OpenAI: Neue, erschreckende Details zum Hugging-Face-Vorfall (2026-08-07 11:16 UTC) Kurz: Mitarbeiter von OpenAI enthüllen weitere Details rund um den Einbruch ihrer KI-Agenten bei anderen Firmen und offenbaren erschreckende Fahrlässigkeit. Quelle: Link Lieferketten-Angriff auf keyv: Shai-Hulud-Wurm infiziert mehr als 440 npm-Pakete (2026-08-07 10:54 UTC) Kurz: Die populäre Key‑Value‑Datenbank keyv und andere weit verbreitete npm-Pakete waren Ziel einer Lieferkettenattacke. Der potenzielle Schaden ist groß. Quelle: Link Verschlüsselte iPhone-Backups: Apple kämpft gegen Londoner Begehrlichkeiten (2026-08-07 10:49 UTC) Kurz: Auch unter dem neuen Labour-Premierminister Burnham verlangt der britische Staat Hintertüren von Apple. Dessen Anwälte versuchen, sich zu wehren. Quelle: Link BleepingComputer Metabase SQLi zero-day exploited in customer data-theft attacks (2026-08-07 20:14 UTC) Kurz: A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. […] Quelle: Link Unlimited Technology Systems breach impacts 3.8 million people (2026-08-07 19:30 UTC) Kurz: Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. […] Quelle: Link Levi Strauss & Co. says hackers stole corporate data in cyberattack (2026-08-07 15:48 UTC) Kurz: Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. […] Quelle: Link The Hacker News Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication (2026-08-08 06:58 UTC) Kurz: Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a… Quelle: Link N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist (2026-08-08 06:57 UTC) Kurz: N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding pr… Quelle: Link Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts (2026-08-08 06:52 UTC) Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploita… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 8, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-08-07)

IT‑Sicherheits‑Digest (2026-08-07) Aktuelle Security‑News heise security Auslegungssache 165: Europas Datenschutz in Bewegung (2026-08-07 04:10 UTC) Kurz: Der c’t-Datenschutz-Podcast beleuchtet den Datentransfer in die USA, neue Entscheidungen des EuGH und die stockende Reform der EU-Digitalregeln. Quelle: Link Cyberkrimineller bekennt sich der Millionen-Erpressung von Cloud-Kunden schuldig (2026-08-07 03:03 UTC) Kurz: Nach dem Datenklau beim US-Cloud-Anbieter Snowflake hat ein Kanadier Millionen von dessen Kunden erpresst. Nach Schuldbekenntnis drohen ihm 2 bis 30 Jahre Haft. Quelle: Link Fehlende Kontaktmöglichkeit: Deutschland verschläft Sicherheit per security.txt (2026-08-06 15:40 UTC) Kurz: Nur 1,8 Prozent der deutschen Webseiten bieten eine standardisierte security.txt an. Das BSI warnt vor den Risiken und verweist auf kommende Meldepflichten. Quelle: Link BleepingComputer OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it (2026-08-06 22:48 UTC) Kurz: OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. […] Quelle: Link ClickFix attack pushes macOS infostealer for crypto theft attacks (2026-08-06 22:37 UTC) Kurz: A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. […] Quelle: Link Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (2026-08-06 20:07 UTC) Kurz: A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. […] Quelle: Link The Hacker News TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign (2026-08-07 06:50 UTC) Kurz: A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sig… Quelle: Link New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts (2026-08-06 17:58 UTC) Kurz: Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed … Quelle: Link Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs (2026-08-06 17:13 UTC) Kurz: Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software,… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) CVE-2026-67261 — CVSS 9.8 (CRITICAL) Kurz: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit … Quelle: Link CVE-2026-54489 — CVSS 9.1 (CRITICAL) Kurz: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulne… Quelle: Link Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 7, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-08-06)

IT‑Sicherheits‑Digest (2026-08-06) Aktuelle Security‑News heise security Auch KI von Meta hackte sich in eine andere Firma (2026-08-06 05:04 UTC) Kurz: Nach OpenAI und Anthropic räumt nun auch Meta ein, dass sich eigene KI-Software in fremde Systeme gehackt hat. Quelle: Link Weitere KI-Attacke: Modell schleust Schwachstelle ein und manipuliert Menschen (2026-08-05 10:03 UTC) Kurz: Ein KI-Modell von Anthropic versuchte, eine Schwachstelle in Software einzuschleusen und manipulierte Menschen per E-Mail. Quelle: Link Sicherheitsupdates: TP-Links Netzwerk-Ökosystem Omada ist kompromittierbar (2026-08-05 09:32 UTC) Kurz: Sicherheitsforscher entdecken unter anderem kritische Lücken in TP-Link Omada, die sich auf weitere Netzwerkkomponenten ausweiten. Quelle: Link BleepingComputer Ransom Cartel ransomware creator sentenced to 16 years in prison (2026-08-05 23:00 UTC) Kurz: Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. […] Quelle: Link Canadian pleads guilty to Snowflake cloud data-theft attacks (2026-08-05 21:53 UTC) Kurz: A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. […] Quelle: Link Hackers run khunt post-exploitation toolkit from Oracle database (2026-08-05 19:55 UTC) Kurz: Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. […] Quelle: Link The Hacker News Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People (2026-08-06 06:04 UTC) Kurz: Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at leas… Quelle: Link Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures (2026-08-05 18:44 UTC) Kurz: A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for wee… Quelle: Link OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes (2026-08-05 18:33 UTC) Kurz: OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that e… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches CVE-2026-63457 — CVSS 6.5 (MEDIUM) Kurz: A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. Quelle: Link VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 6, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-08-05)

IT‑Sicherheits‑Digest (2026-08-05) Aktuelle Security‑News heise security „Passwort“ Folge 63: Ein Rotes Kreuz für den Cyberspace (2026-08-05 07:00 UTC) Kurz: Mit einem Gast von der ETH Zürich geht es in dieser Podcastfolge um digitale Embleme. Die sollen, analog zum Roten Kreuz, im Cyberspace vor Angriffen schützen. Quelle: Link Check Point: Angreifer können Security-Management-Server übernehmen (2026-08-04 12:05 UTC) Kurz: Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download. Quelle: Link Jetzt patchen! Angreifer attackieren N-able N-central (2026-08-04 09:04 UTC) Kurz: N-ables Endpoint-Managementlösung N-central ist verwundbar und Angreifer attackieren bereits Instanzen. Admins sollten zügig handeln. Quelle: Link BleepingComputer OpenAI, Anthropic AI agents targeted real people and systems in cyber tests (2026-08-04 23:39 UTC) Kurz: OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people out… Quelle: Link TP-Link patches Omada ZTP flaws allowing hackers to breach networks (2026-08-04 22:18 UTC) Kurz: TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). […] Quelle: Link Phishing service spoofs RingCentral to steal Microsoft 365 accounts (2026-08-04 21:45 UTC) Kurz: The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. […] Quelle: Link The Hacker News QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer (2026-08-05 05:47 UTC) Kurz: Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet … Quelle: Link Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens (2026-08-04 17:27 UTC) Kurz: The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorizati… Quelle: Link Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks (2026-08-04 13:30 UTC) Kurz: A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 pac… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches CVE-2026-63455 — CVSS 9.8 (CRITICAL) Kurz: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful expl… Quelle: Link CVE-2026-63456 — CVSS 9.8 (CRITICAL) Kurz: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful expl… Quelle: Link VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 5, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-08-04)

IT‑Sicherheits‑Digest (2026-08-04) Aktuelle Security‑News heise security Wenn die IT ausfällt: Krisensimulation für Krankenhäuser (2026-08-04 04:11 UTC) Kurz: Wie Krankenhäuser bei IT-Ausfällen reagieren, testet Nico Brüggemann vom Fraunhofer SIT. Er erklärt, warum Abläufe oft nur auf dem Papier funktionieren. Quelle: Link Seed phrases leicht zu erraten: Kryptodiebe leeren Offline-Wallets (2026-08-04 03:40 UTC) Kurz: Offline-Wallets sollen besonders sicher sein. Doch wenn der Zufallsgenerator nicht arbeitet, ist die seed phrase nicht wirklich geheim. Quelle: Link Neue Malware-Welle: Arch Linux blockiert AUR-Updates (2026-08-03 19:25 UTC) Kurz: Erneut verbreitet sich Malware über Arch User Repositorys. Daher gibt es vorerst überhaupt keine Updates für AUR. Quelle: Link BleepingComputer Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts (2026-08-04 00:17 UTC) Kurz: Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. […] Quelle: Link New Pass-ta-key attacks let malware hijack Google-synced passkeys (2026-08-03 23:58 UTC) Kurz: Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private key… Quelle: Link New DOUBLECUP ClickFix service hides malware in browser cache images (2026-08-03 20:01 UTC) Kurz: A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named De… Quelle: Link The Hacker News CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises (2026-08-04 07:00 UTC) Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the w… Quelle: Link 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users (2026-08-03 18:43 UTC) Kurz: Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack ta… Quelle: Link Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts (2026-08-03 16:24 UTC) Kurz: Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chro… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 4, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-08-03)

IT‑Sicherheits‑Digest (2026-08-03) Aktuelle Security‑News heise security Kritische Schadcode-Sicherheitslücke bedroht Adobe Campaign Classic (2026-08-03 06:41 UTC) Kurz: Angreifer können Adobe Bridge und Campaign Classic attackieren. Dagegen abgesicherte Versionen stehen zum Download. Quelle: Link Eclipse und OWASP wollen Open-Source-Projekte in Sicherheitsfragen fortbilden (2026-08-02 14:57 UTC) Kurz: Der Cyber Resilience Act rückt näher und auch Open-Source-Projekte müssen sich darauf einstellen. Eclipse und OWASP bündeln nun ihre Hilfsangebote. Quelle: Link BleepingComputer OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems (2026-08-02 22:31 UTC) Kurz: OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. […] Quelle: Link COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft (2026-08-02 21:14 UTC) Kurz: A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. […] Quelle: Link Google Chrome may soon block New Tab hijacker extensions by default (2026-08-02 14:17 UTC) Kurz: Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. […] Quelle: Link The Hacker News N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete (2026-08-03 06:41 UTC) Kurz: N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds p… Quelle: Link Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code (2026-08-03 06:40 UTC) Kurz: Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) s… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

August 3, 2026 · 2 min · Betty