<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"><title>CERT.at - Tagesberichte</title><link rel="alternate" href="https://www.cert.at"/><subtitle>Dieser Feed beinhaltet die Tagesberichte von www.CERT.at</subtitle><entry><title>Tageszusammenfassung - 10.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-10072026"/><author><name>CERT.at</name></author><updated>2026-07-10T18:16:23Z</updated><published>2026-07-10T18:16:23Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 09-07-2026 18:00 - Freitag 10-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers&lt;/h3&gt;

A single wrong variable on one line in XQUIC, Alibabas QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server process down. [..] FoxIO demonstrated a crash, not code execution, and reported no exploitation in the wild. [..] XRING is the latest in a string of remote crashes in HTTP/2 and HTTP/3 stacks.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html&quot;&gt;https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites&lt;/h3&gt;

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operations inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html&quot;&gt;https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Software developers are the target. New trojan attacks supply chains and inflicts multifaceted damage on infected PCs&lt;/h3&gt;

A new trojan engaging in supply chain attacks has recently come under the scrutiny of our antivirus laboratory. The malware primarily targets C++ and C# project files. This malicious sample is particularly dangerous as its payload incorporates multiple damaging features, allowing it to steal data, access clipboard content, operate as a backdoor, engage in rogue mining and also infect other files. [..] It mainly spreads over the Internet via infected executable files and Python scripts. The infection process is quite complex, so let-s examine the entire sequence phase by phase.
&lt;p /&gt;
&lt;A HREF=&quot;https://news.drweb.com/show/?i=15276&amp;lng=en&amp;c=9&quot;&gt;https://news.drweb.com/show/?i=15276&amp;lng=en&amp;c=9&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;&quot;Comment stuffing&quot; in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)&lt;/h3&gt;

Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional message that does something a little out of the ordinary.
&lt;p /&gt;
&lt;A HREF=&quot;https://isc.sans.edu/diary/rss/33144&quot;&gt;https://isc.sans.edu/diary/rss/33144&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk&lt;/h3&gt;

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA).
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html&quot;&gt;https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft warns customers AI will mean busier Patch Tuesdays&lt;/h3&gt;

More patches mean more reasons to buy Redmond-s auto-patching tools
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-ai-will-mean-busier-patch-tuesdays/5269618&quot;&gt;https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-ai-will-mean-busier-patch-tuesdays/5269618&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware&lt;/h3&gt;

In October 2025, Microsoft Threat Intelligence identified destructive wiping activity and uncovered a sophisticated Go programming language (Golang)-based backdoor we now track as GigaWiper, a versatile implant that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including disk wiping, fake ransomware, and system-level sabotage. [..] In this blog, we provide a code-level analysis of GigaWiper-s architecture.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/&quot;&gt;https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Flying with the Flipper Zero&lt;/h3&gt;

Why is the world so alarmed about taking the Flipper on board planes? Is it just poorly educated armchair cyber commentators of the -don-t use open Wi-Fi / USB juicejacking- style of fearmongering, or is there something to it? [..] Flippers are not a threat to the safety of a flight.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.pentestpartners.com/security-blog/flying-with-the-flipper-zero/&quot;&gt;https://www.pentestpartners.com/security-blog/flying-with-the-flipper-zero/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Organized Cybercrime Merging with Other Crime&lt;/h3&gt;

In a recent report, the FBI warns that Silent Ransom Group has also begun recruiting gig workers in the victims- area under the guise of hiring helpdesk personnel. Gig workers are people who earn money through short-term, flexible jobs rather than a traditional permanent role. They are usually paid per task, project or assignment.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.truesec.com/hub/blog/organized-cybercrime-merging-with-other-crime&quot;&gt;https://www.truesec.com/hub/blog/organized-cybercrime-merging-with-other-crime&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense&lt;/h3&gt;

Verizons latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. [..] The lesson from this year's DBIR is that familiar weaknesses remain highly effective when combined with cloud scale, interconnected trust relationships, and increasingly rapid exploitation cycles.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wiz.io/blog/verizon-dbir-2026-ai-cloud-security&quot;&gt;https://www.wiz.io/blog/verizon-dbir-2026-ai-cloud-security&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;

&lt;h3&gt;GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/&quot;&gt;https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1082272/&quot;&gt;https://lwn.net/Articles/1082272/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-10T18:16:23Z</dc:date></entry><entry><title>Tageszusammenfassung - 09.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-09072026"/><author><name>CERT.at</name></author><updated>2026-07-09T18:26:11Z</updated><published>2026-07-09T18:26:11Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 08-07-2026 18:00 - Donnerstag 09-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Microsoft patches RoguePlanet Defender zero-day vulnerability&lt;/h3&gt;

Microsoft has released a security patch to address a Defender zero-day vulnerability known as &quot;RoguePlanet,&quot; disclosed after the June 2026 Patch Tuesday. The flaw (tracked as CVE-2026-50656) was disclosed by a security researcher using the &quot;Nightmare Eclipse&quot; handle as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/&quot;&gt;https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Schwachstelle in Coding-Agenten: Zugriff auf beliebige Dateien über Symlinks&lt;/h3&gt;

In sechs großen Coding-Agenten findet sich eine Sicherheitslücke: Über ein Repository mit Schadcode können Angreifer die KI-Modelle dazu bewegen, auf beliebige Dateien zuzugreifen - auch außerhalb einer Sandbox. [..] Betroffen sind Amazon Q Developer, Anthropics Claude Code, Augment, Cursor, Google Antigravity und Windsurf. Für die meisten Tools existiert inzwischen ein Update, das die Schwachstelle behebt, aber für Augment und Windsurf existieren noch keine Patches.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11358849&quot;&gt;https://heise.de/-11358849&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years&lt;/h3&gt;

GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.
&lt;p /&gt;
&lt;A HREF=&quot;https://nebusec.ai/research/ionstack-part-2/&quot;&gt;https://nebusec.ai/research/ionstack-part-2/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Entra passkey enrollment vishing targets Microsoft 365 users&lt;/h3&gt;

A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/&quot;&gt;https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New Forg365 phishing platform uses AI to target Microsoft 365 accounts&lt;/h3&gt;

A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims&lt;/h3&gt;

Residential proxies are one of the hottest topics in cybersecurity today. Turns out, they are often not in residences, and they facilitate a wide range of criminal activity. In the simplest terms, a little piece of software in a TV, digital picture frame, or your phone might enable a company to sell access to your device-s bandwidth to their own customers. [..] Our discovery started with a single campaign: In early 2026, the actor, who we track as Lurking Lizard, fooled users into downloading a fake version of the 7-Zip archive utility.

Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims


&lt;h3&gt;GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses&lt;/h3&gt;

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, which, in turn, was an enhanced version of Monster, a Delphi-based ransomware that surfaced in March 2022.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html&quot;&gt;https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GitHub Copilot: Sorry Dave, I cant do that harmful thing - unless you ask me in code&lt;/h3&gt;

t's the latest example of AI safety guardrails being bypassed. GitHub Copilot refuses harmful prompts almost always if asked in chat - like, &quot;how to fool a breathalyzer test&quot; or &quot;smuggle bulk cash out of the US&quot; - but then will write them in code 100 percent of the time if the prompt is broken into smaller steps and distributed across multiple stages of a software development workflow.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i-cant-do-that-harmful-thing-unless-you-ask-me-in-code/5268654&quot;&gt;https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i-cant-do-that-harmful-thing-unless-you-ask-me-in-code/5268654&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Eintrag wider Willen: Wenn Unternehmen ungefragt auf dubiosen Portalen landen&lt;/h3&gt;

Taucht das eigene Unternehmen plötzlich auf unbekannten Portalen auf, ist die Überraschung groß. Unangenehm wird es dann, wenn sich das Profil ohne Registrierung nicht löschen lässt und sich die Plattformbetreiber regelmäßig mit aufdringlichen Spam-Mails melden. Und wie war das nochmal mit dem Urheberrecht? Das Problem, dargestellt am Beispiel evepla.com.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/eintrag-wider-willen-dubiose-portale/&quot;&gt;https://www.watchlist-internet.at/news/eintrag-wider-willen-dubiose-portale/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;n8n: CERT-Bund veröffentlicht Warnmeldung zu kürzlich beseitigten Schwachstellen&lt;/h3&gt;

Kritisch ist keine der jüngst gefixten Lücken in der Automatisierungslösung n8n. Dennoch betont eine Warnmeldung des BSI die hohe Update-Relevanz.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11359656&quot;&gt;https://heise.de/-11359656&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drupal Security Advisories 2026-July-08&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/security&quot;&gt;https://www.drupal.org/security&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1082030/&quot;&gt;https://lwn.net/Articles/1082030/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Paloalto: PAN-SA-2026-0010 Chromium: Monthly Vulnerability Update (July 2026) (Severity: HIGH)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://security.paloaltonetworks.com/PAN-SA-2026-0010&quot;&gt;https://security.paloaltonetworks.com/PAN-SA-2026-0010&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Paloalto: PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) (Severity: HIGH)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://security.paloaltonetworks.com/PAN-SA-2026-0010&quot;&gt;https://security.paloaltonetworks.com/PAN-SA-2026-0010&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Chrome-Browser &amp; ChromeOS LTS : Updates schließen teils kritische Lücken&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11359376&quot;&gt;https://heise.de/-11359376&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Wireshark 4.6.7 Fixes 12 Security Issues Across SSH, IEEE 802.11, Catapult DCT2000 and Other Protocols&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/wireshark-4-6-7/&quot;&gt;https://thecyberexpress.com/wireshark-4-6-7/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-09T18:26:11Z</dc:date></entry><entry><title>Tageszusammenfassung - 08.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-08072026"/><author><name>CERT.at</name></author><updated>2026-07-08T19:16:01Z</updated><published>2026-07-08T19:16:01Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 07-07-2026 18:00 - Mittwoch 08-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Accenture confirms breach after hacker offers stolen data for sale&lt;/h3&gt;

IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [..] According to the threat actor, the data includes source code, RSA keys, SSH keys, Azure PAT (personal access tokens), Azure Storage access keys, and configuration files.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/&quot;&gt;https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GitHub AI agent leaks private repos when asked nicely&lt;/h3&gt;

Malicious prompters could easily trick GitHub agents into pulling data from private repositories and then leaking the information as a public comment for anyone to access, according to Noma Labs researchers who named the vulnerability GitLost. The issue exists in GitHub-s Agentic Workflows, which allow an AI agent powered by Claude or GitHub Copilot to autonomously execute tasks in GitHub Actions.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924&quot;&gt;https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;-Ihr Paket liegt im Logistikzentrum!- - Über eine Zollgebühr in die Phishing-Falle&lt;/h3&gt;

Zwei Sätze, eine Aufforderung, eine Frist. Mehr braucht es nicht - und die Phishing-Falle ist fertig. Eine zurzeit besonders häufig gemeldete Masche nutzt den Paketdienstleister DPD als Tarnung. Da sich entsprechende Hinweise im Posteingang der Redaktion stapeln, ist es an der Zeit, die Masche erneut unter die Lupe zu nehmen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/dpd-paket-im-logistikzentrum/&quot;&gt;https://www.watchlist-internet.at/news/dpd-paket-im-logistikzentrum/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation&lt;/h3&gt;

In April 2026, Unit 42 researchers identified a financially motivated campaign delivering Vidar stealer and the XMRig cryptocurrency miner to consumer and small- and medium-sized business victims worldwide. [..] We assess the operator of the campaign to be a Vidar stealer malware-as-a-service (MaaS) affiliate involved in operations targeting victims in the U.S. and European Union. This article provides a technical analysis of the campaign.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/&quot;&gt;https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck&lt;/h3&gt;

Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11358275&quot;&gt;https://heise.de/-11358275&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Joomla Security Advisories (Fixed Date: 2026-07-07)&lt;/h3&gt;

Joomla has released 12 new security advisories.
&lt;p /&gt;
&lt;A HREF=&quot;https://developer.joomla.org/security-centre/&quot;&gt;https://developer.joomla.org/security-centre/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Foxit-Entwickler schließen Schwachstellen in PDF Reader und Editor&lt;/h3&gt;

Nicht kritisch, aber zahlreich: Aktuelle Sicherheitsupdates dichten Foxits PDF Reader und Editor gegen eine lange Lückenliste ab.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Foxit-Entwickler-schliessen-Schwachstellen-in-PDF-Reader-und-Editor-11358393.html&quot;&gt;https://www.heise.de/news/Foxit-Entwickler-schliessen-Schwachstellen-in-PDF-Reader-und-Editor-11358393.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ILIAS: Wichtige Aktualisierungen für Lernplattform beseitigen Schwachstellen&lt;/h3&gt;

Für die von Hochschulen, Kliniken und anderen öffentlichen Institutionen genutzte offene Lernplattform ILIAS stehen Aktualisierungen bereit. Die neuen Versionen 9.21, 10.9 und 11.2 schließen Sicherheitslücken, von denen alle früheren Ausgaben betroffen waren. Von drei Lücken geht ein hohes, von den übrigen ein mittleres Sicherheitsrisiko aus.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11357739&quot;&gt;https://heise.de/-11357739&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker (CVE-2026-57028)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-A-port-which-has-been-inadvertently-exposed-can-be-reached-by-an-attacker-CVE-2026-57028&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-A-port-which-has-been-inadvertently-exposed-can-be-reached-by-an-attacker-CVE-2026-57028&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash (CVE-2026-57026)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-with-SPC3-SRX-Series-Processing-of-a-specifically-malformed-SIP-invite-causes-a-flowd-crash-CVE-2026-57026&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-with-SPC3-SRX-Series-Processing-of-a-specifically-malformed-SIP-invite-causes-a-flowd-crash-CVE-2026-57026&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash (CVE-2026-57023)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-with-SPC3-SRX-Series-A-specifically-malformed-TCP-packet-causes-a-flowd-crash-CVE-2026-57023&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-with-SPC3-SRX-Series-A-specifically-malformed-TCP-packet-causes-a-flowd-crash-CVE-2026-57023&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash (CVE-2026-33799)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Receipt-of-a-specific-SNMPv3-request-results-in-memory-leak-and-eventual-snmpd-crash-CVE-2026-33799&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Receipt-of-a-specific-SNMPv3-request-results-in-memory-leak-and-eventual-snmpd-crash-CVE-2026-33799&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash (CVE-2026-21901)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Configuration-of-a-specific-SSH-option-results-in-mgd-crash-CVE-2026-21901&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Configuration-of-a-specific-SSH-option-results-in-mgd-crash-CVE-2026-21901&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: cRPD: Multiple vulnerabilities resolved in cRPD 26.2R1&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-cRPD-Multiple-vulnerabilities-resolved-in-cRPD-26-2R1&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-cRPD-Multiple-vulnerabilities-resolved-in-cRPD-26-2R1&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Junos Space: Multiple vulnerabilities resolved in 26.1R1 Patch V1 Release&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-Space-Multiple-vulnerabilities-resolved-in-26-1R1-Patch-V1-Release&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-Space-Multiple-vulnerabilities-resolved-in-26-1R1-Patch-V1-Release&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Network Director: Multiple vulnerabilities resolved in 7.1R3 release&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Network-Director-Multiple-vulnerabilities-resolved-in-7-1R3-release&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Network-Director-Multiple-vulnerabilities-resolved-in-7-1R3-release&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: Junos OS Evolved: URL handling vulnerability in libfetch results in heap buffer overflow (CVE-2020-7450)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-URL-handling-vulnerability-in-libfetch-results-in-heap-buffer-overflow-CVE-2020-7450&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-URL-handling-vulnerability-in-libfetch-results-in-heap-buffer-overflow-CVE-2020-7450&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Juniper: 2026-07 Security Bulletin: CTPView: Multiple vulnerabilities resolved in 9.3R2-3 Release&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-CTPView-Multiple-vulnerabilities-resolved-in-9-3R2-3-Release&quot;&gt;https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-CTPView-Multiple-vulnerabilities-resolved-in-9-3R2-3-Release&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1081798/&quot;&gt;https://lwn.net/Articles/1081798/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-08T19:16:01Z</dc:date></entry><entry><title>Tageszusammenfassung - 07.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-07072026"/><author><name>CERT.at</name></author><updated>2026-07-07T18:59:45Z</updated><published>2026-07-07T18:59:45Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 06-07-2026 18:00 - Dienstag 07-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Angreifer können Balkonkraftwerke aus der Ferne abschalten&lt;/h3&gt;

Geräte des chinesischen Herstellers Hoymiles lassen sich durch eine Sicherheitslücke fernsteuern.
&lt;p /&gt;
&lt;A HREF=&quot;https://futurezone.at/digital-life/balkonkraftwerk-sicherheitsluecke-hoymiles-pv-anlage-passwort/403174823&quot;&gt;https://futurezone.at/digital-life/balkonkraftwerk-sicherheitsluecke-hoymiles-pv-anlage-passwort/403174823&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Air-Gapped-Systeme: Malware leitet Daten über Monitorkabel aus&lt;/h3&gt;

Air Gapping schützt vor einer unerwünschten Datenausleitung. Ein neuartiger Angriff umgeht diesen Schutz über das Monitor-Kabel - und das ziemlich performant.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/air-gapped-systeme-malware-leitet-daten-ueber-monitorkabel-aus-2607-210592.html&quot;&gt;https://www.golem.de/news/air-gapped-systeme-malware-leitet-daten-ueber-monitorkabel-aus-2607-210592.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Geheimdienstbericht in Kanada: Cyberoperationen im Ausland&lt;/h3&gt;

Kanadas Nachrichtendienst führt Cyberangriffe gegen Drogenhändler, Extremisten und Cyberkriminelle durch. Ungewöhnlich ist das öffentliche Bekenntnis.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Geheimdienstbericht-in-Kanada-Cyberoperationen-im-Ausland-11355701.html&quot;&gt;https://www.heise.de/news/Geheimdienstbericht-in-Kanada-Cyberoperationen-im-Ausland-11355701.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;OpenSSH bringt erstmals hybride Post-Quantum-Signaturen&lt;/h3&gt;

OpenSSH 10.4 behebt mehrere Sicherheitslücken in SSH, SCP und SFTP. Zudem gibt es Protokollverschärfungen und experimentelle Post-Quantum-Signaturen. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/OpenSSH-bringt-erstmals-hybride-Post-Quantum-Signaturen-11356381.html&quot;&gt;https://www.heise.de/news/OpenSSH-bringt-erstmals-hybride-Post-Quantum-Signaturen-11356381.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Woodruff: You shouldnt trust trusted publishing&lt;/h3&gt;

Trusted Publishing is a mechanism for establishing trust between an external machine identity (like a CI/CD workflow) and one or more projects on a package index/registry. The &quot;trust&quot; in &quot;Trusted Publishing&quot; refers to that trust relationship, and not to anything else. It is not, and cannot be, a signal for package trust or quality. You cannot use it to determine whether a package is safe or &quot;good,&quot; and PyPI consciously stymies attempts to misuse it for that purpose by not rendering it as a &quot;green checkmark&quot; or anything else of the sort. Or as another framing: Trusted Publishing is just a form of authentication. It doesn't tell you anything other than that an upload was authenticated, which all uploads to PyPI are.
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1081690/&quot;&gt;https://lwn.net/Articles/1081690/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Scattered Spider-Mitglied Peter Stokes durch Windows GUID identifiziert und überführt&lt;/h3&gt;

Vor einiger Zeit wurde Peter Stokes als mutmaßliches Mitglied der Cybergang Scattered Spider in Finnland verhaftet und ist inzwischen in die USA ausgeliefert worden. Aus Gerichtsdokumenten geht nun hervor, dass die von Windows vergebene eindeutige GDID, per Telemetrie - samt weiteren Daten - an Microsoft übertragen, Stokes bei seinen Aktivitäten, die er bestmöglich verschleierte, verraten und zu seiner Identifizierung geführt hat.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/07/06/scattered-spider-mitglied-peter-stokes-durch-windows-guid-identifiziert-und-ueberfuehrt/&quot;&gt;https://borncity.com/blog/2026/07/06/scattered-spider-mitglied-peter-stokes-durch-windows-guid-identifiziert-und-ueberfuehrt/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Joomla Helix3-Lücke: Hacked by Antonkill&lt;/h3&gt;

Kurzer Hinweis für Leute, die eine Joomla-Instanz betreiben oder eine solche Installation in ihrem Umfeld kennen. Eine Schwachstelle im Helix3-Framework von JoomShaper wird durch ein Botnetz ausgenutzt, um Joomla-Instanzen zu infizieren. Dort taucht dann die Meldung &quot;Hacked by AntonKill&quot; oder auch &quot;Hacked by trenggalek6etar&quot; auf.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/07/07/joomla-helix3-luecke-hacked-by-antonkill/&quot;&gt;https://borncity.com/blog/2026/07/07/joomla-helix3-luecke-hacked-by-antonkill/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Reducing Microsoft Sentinel Costs Without Compromising Detection - Part 2: The Firewall Quest&lt;/h3&gt;

Continuing our journey through Sentinel ingestion cost reduction, this part focuses on one of the most expensive log sources: firewalls, and more specifically, network traffic events.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.nviso.eu/2026/07/07/reducing-microsoft-sentinel-costs-without-compromising-detection-part-2-the-firewall-quest/&quot;&gt;https://blog.nviso.eu/2026/07/07/reducing-microsoft-sentinel-costs-without-compromising-detection-part-2-the-firewall-quest/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;UAT-7810 continues building ORB networks using new malware&lt;/h3&gt;

Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor based on the infrastructure that it provides to secondary China-nexus APTs such as UAT-5918. Open-source reporting has also illustrated overlapping tooling between UAT-5918 and UAT-7810. However, at this time, Talos considers UAT-5918 and UAT-7810 separate APT actors tasked with their own set of objectives and targets.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.talosintelligence.com/uat-7810/&quot;&gt;https://blog.talosintelligence.com/uat-7810/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Software vom BSI und Fraunhofer: Wie KI ihre eigenen Deepfakes entlarvt&lt;/h3&gt;

Forschende vom Fraunhofer-Institut und Bundesamt für Sicherheit haben ein neues Verfahren entwickelt, um Deepfakes zu erkennen. Doch es bietet noch mehr.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11355899&quot;&gt;https://heise.de/-11355899&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Sicherheitsalbtraum Wechselrichter: Hoymiles lässt Nachbarschaften verstummen&lt;/h3&gt;

Schwere Funkschwachstellen bei Hunderttausenden PV-Anlagen erlauben laut Forschern das Abschalten im Vorbeifahren und sogar die physische Zerstörung der Geräte. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11357067&quot;&gt;https://heise.de/-11357067&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Entra Agent ID: Protect, detect, respond&lt;/h3&gt;

This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant.
&lt;p /&gt;
&lt;A HREF=&quot;https://securitylabs.datadoghq.com/articles/agent-id-protect-detect-respond/&quot;&gt;https://securitylabs.datadoghq.com/articles/agent-id-protect-detect-respond/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;KYC : Bypass age verification using generative video models&lt;/h3&gt;

Historically reserved for the banking sector, the KYC (Know Your Customer) process is now making its way into many online services, driven by increasingly strict legislation on anonymity and age verification. To comply, platforms deploy significant measures aimed at guaranteeing the &quot;proof of life&quot; of the user behind their webcam or smartphone. However, the meteoric rise of generative video AI models completely reshuffles the deck, offering attackers formidable and accessible tools to fool these systems. The French PVID framework aims to counter this new threat.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.synacktiv.com/en/publications/kyc-bypass-age-verification-using-generative-video-models.html&quot;&gt;https://www.synacktiv.com/en/publications/kyc-bypass-age-verification-using-generative-video-models.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Phishing poses as big-brand job interview to steal Google accounts&lt;/h3&gt;

A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/&quot;&gt;https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;BeyondTrust warns of critical flaws in remote access software&lt;/h3&gt;

BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/&quot;&gt;https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Tenda firmware (multiple versions) contains hidden authentication backdoor&lt;/h3&gt;

Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials.
&lt;p /&gt;
&lt;A HREF=&quot;https://kb.cert.org/vuls/id/213560&quot;&gt;https://kb.cert.org/vuls/id/213560&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Samsung-Sicherheitsupdate: Juli-Patches für Galaxy-Geräte&lt;/h3&gt;

Samsung hat sein Security-Bulletin für Juli 2026 veröffentlicht und verteilt wichtige Sicherheitspatches vor allem für die Topmodelle der Galaxy-Reihe. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Samsung-Sicherheitsupdate-Juli-Patches-fuer-Galaxy-Geraete-11356339.html&quot;&gt;https://www.heise.de/news/Samsung-Sicherheitsupdate-Juli-Patches-fuer-Galaxy-Geraete-11356339.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zimbra Collaboration Suite: Kritische Lücke macht Classic Web Client angreifbar&lt;/h3&gt;

Die Zimbra-Entwickler haben im Zuge eines Patch Release Updates auf Version 10.1.19 der Zimbra Collaboration Suite (ZCS) auf ein mögliches Sicherheitsrisiko aufmerksam gemacht. Laut Patch Release Notes kann die zugrundeliegende Schwachstelle ausschließlich über die Komponente Classic Web Client missbraucht werden, wird in diesem Kontext allerdings als -kritisch- bezeichnet.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Zimbra-Collaboration-Suite-Kritische-Luecke-macht-Classic-Web-Client-angreifbar-11356522.html&quot;&gt;https://www.heise.de/news/Zimbra-Collaboration-Suite-Kritische-Luecke-macht-Classic-Web-Client-angreifbar-11356522.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cloudsysteme gefährdet: 16 Jahre alte KVM-Lücke ermöglicht VM-Ausbruch unter Linux&lt;/h3&gt;

Eine seit 2010 bestehende Lücke im KVM-Code des Linux-Kernels gefährdet unter anderem Cloudsysteme. Angreifer können damit VM-Hosts kapern.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/cloudsysteme-gefaehrdet-16-jahre-alte-kvm-luecke-ermoeglicht-vm-ausbruch-unter-linux-2607-210581.html&quot;&gt;https://www.golem.de/news/cloudsysteme-gefaehrdet-16-jahre-alte-kvm-luecke-ermoeglicht-vm-ausbruch-unter-linux-2607-210581.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1081644/&quot;&gt;https://lwn.net/Articles/1081644/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-07T18:59:45Z</dc:date></entry><entry><title>Tageszusammenfassung - 06.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-06072026"/><author><name>CERT.at</name></author><updated>2026-07-06T18:14:32Z</updated><published>2026-07-06T18:14:32Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 03-07-2026 18:00 - Montag 06-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Sicherheitswarnungen: Node.js will KI-Flut mit KI bekämpfen&lt;/h3&gt;

In der Node.js-Community ist eine Diskussion darüber entstanden, wie sie weiter mit der Vielzahl an LLM-generierten Sicherheitsmeldungen verfahren soll.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Sicherheitswarnungen-Node-js-will-KI-Flut-mit-KI-bekaempfen-11355142.html&quot;&gt;https://www.heise.de/news/Sicherheitswarnungen-Node-js-will-KI-Flut-mit-KI-bekaempfen-11355142.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WhatsApp-Benutzernamen wecken Befürchtungen an möglichem Identitätsdiebstahl&lt;/h3&gt;

Betrüger könnten WhatsApp-Benutzernamen bekannter Personen zu kriminellen Zwecken missbrauchen, warnen Sicherheitsexperten. Reservierungen sind bereits möglich.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11354304&quot;&gt;https://heise.de/-11354304&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;When checking the URL isn-t enough: a Device Code Phishing attack via a Microsoft website&lt;/h3&gt;

The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/microsoft-device-code-phishing-attack/120350/&quot;&gt;https://securelist.com/microsoft-device-code-phishing-attack/120350/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing&lt;/h3&gt;

Scanners meant to catch malicious add-on &quot;skills&quot; for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped past every scanner tested more than 90% of the time, and the same team built a runtime checker that catches most of the disguised skills the scanners miss.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html&quot;&gt;https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages&lt;/h3&gt;

Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits.In a proof of concept, they reconstructed a signed-in users full Gmail address from a single visit, with no click. [..] The fix shipped in Opera GX version 130.0.5847.89, so anyone on a current build is already covered; you can confirm yours at opera://about. There is no CVE.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html&quot;&gt;https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;PDF-Abo-Falle: Wenn aus 99 Cent ein teures Abo wird&lt;/h3&gt;

Wer eine PDF-Datei schnell online bearbeiten möchte, stößt auf zahlreiche Dienste, die kostenlos oder besonders günstig wirken. Nach der Bearbeitung wird häufig lediglich ein kleiner Betrag von 99 Cent für den Download verlangt. Was viele nicht bemerken: Im Hintergrund wird oft ein teures Abo abgeschlossen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/pdf-abo-falle/&quot;&gt;https://www.watchlist-internet.at/news/pdf-abo-falle/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;AI Used in Ransomware Attack&lt;/h3&gt;

Using AI to automate part or all of the attack chain is also more of an evolution than a revolution in ransomware. [..] Nevertheless, the attack shows how the use of AI can lead to faster, if still unsophisticated, attacks that give victims less time to react.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.truesec.com/hub/blog/ai-used-in-ransomware-attack&quot;&gt;https://www.truesec.com/hub/blog/ai-used-in-ransomware-attack&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;OPNsense-Update beseitigt kritische Rootlücke und weitere Sicherheitsrisiken&lt;/h3&gt;

Die kürzlich erschienenen Versionen 26.1.11 und 26.4.1(p1) von OPNsense, einer quelloffenen Firewall- und Routing-Plattform auf FreeBSD-Basis, bringen Sicherheitsfixes mit. Unter den geschlossenen Lücken befindet sich auch eine kritische: CVE-2026-57155 (CVSS-Score 9.9 von 10.0) hätte unter bestimmten Voraussetzungen zur Rechteausweitung und letztlich zur kompletten Firewall-Übernahme missbraucht werden können.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/OPNsense-Update-beseitigt-kritische-Rootluecke-und-weitere-Sicherheitsrisiken-11355118.html&quot;&gt;https://www.heise.de/news/OPNsense-Update-beseitigt-kritische-Rootluecke-und-weitere-Sicherheitsrisiken-11355118.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;HestiaCP Admin Takeover &amp; RCE&lt;/h3&gt;

A low privileged user in HestiaCP can exploit a Broken Authorisation flaw to takeover Admin accounts. [..] A patch can be found here. This currently needs to be applied manually until HestiaCP decide to create a release. CVE-2026-12196
&lt;p /&gt;
&lt;A HREF=&quot;https://projectblack.io/blog/hestiacp-admin-takeover-rce/&quot;&gt;https://projectblack.io/blog/hestiacp-admin-takeover-rce/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Dell: DSA-2026-278: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.dell.com/support/kbdoc/de-de/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities&quot;&gt;https://www.dell.com/support/kbdoc/de-de/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression - host root&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://github.com/coollabsio/coolify/security/advisories/GHSA-chg4-63hm-xv9x&quot;&gt;https://github.com/coollabsio/coolify/security/advisories/GHSA-chg4-63hm-xv9x&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1081495/&quot;&gt;https://lwn.net/Articles/1081495/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Roundcube: Security updates 1.6.17 and 1.7.2 released&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2&quot;&gt;https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-06T18:14:32Z</dc:date></entry><entry><title>Tageszusammenfassung - 03.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-03072026"/><author><name>CERT.at</name></author><updated>2026-07-03T18:15:57Z</updated><published>2026-07-03T18:15:57Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 02-07-2026 18:00 - Freitag 03-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices&lt;/h3&gt;

Google has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people's traffic.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html&quot;&gt;https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials&lt;/h3&gt;

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html&quot;&gt;https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer&lt;/h3&gt;

A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/armored-likho-targets-government.html&quot;&gt;https://thehackernews.com/2026/07/armored-likho-targets-government.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Indirect Prompt Injection in Web Content Targets AI Agents&lt;/h3&gt;

AI agents are increasingly changing how users interact with web content, making the content itself a growing attack surface for threat actors. Just as a human user can be socially engineered through phishing, AI agents are also susceptible to similar attacks. Indirect prompt injection (IPI) is an example of these types of attacks that embed malicious instructions in the content retrieved by an AI agent (websites, documents, email, etc.) to influence the agent-s reasoning during task execution. Zscaler ThreatLabz has observed malicious websites that impersonate legitimate services and use IPI to manipulate AI-driven workflows. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents&quot;&gt;https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake Google and Cloudflare verification pages spread multiple malware families&lt;/h3&gt;

ClickFix attacks, which trick people into running malicious commands themselves, continue to evolve. This latest campaign uses fake Google and Cloudflare verification pages to convince victims to infect their own devices.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families&quot;&gt;https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The Gentlemen ransomware: what you need to know&lt;/h3&gt;

Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. In little more than a year, The Gentlemen has gone from relative obscurity to becoming one of the most active ransomware operations on the planet. First surfacing in mid-2025, The Gentlemen is a ransomware-as-a-service (RaaS) operation that appears to have splintered away from the notorious Qilin ransomware group.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.fortra.com/blog/gentlemen-ransomware-what-you-need-know&quot;&gt;https://www.fortra.com/blog/gentlemen-ransomware-what-you-need-know&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;It-s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)&lt;/h3&gt;

We-re back, melting - we-ve tried shouting, screaming, and throwing things at the Sun, and it is just not working.
&lt;p /&gt;
&lt;A HREF=&quot;https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza/&quot;&gt;https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mitglied im Sonderausschuss zu Pegasus: EU-Abgeordneter mit Spyware attackiert&lt;/h3&gt;

Vor Jahren hat das Europaparlament Angriffe mit der Pegasus-Spyware in der EU untersucht. Ein stellvertretendes Ausschussmitglied wurde da selbst angegriffen. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11352514&quot;&gt;https://heise.de/-11352514&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;How GitHub used secret scanning to reach inbox zero&lt;/h3&gt;

GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here-s how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months.
&lt;p /&gt;
&lt;A HREF=&quot;https://github.blog/security/application-security/how-github-used-secret-scanning-to-reach-inbox-zero/&quot;&gt;https://github.blog/security/application-security/how-github-used-secret-scanning-to-reach-inbox-zero/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Behörde warnt: Microsoft-Sharepoint-Server werden attackiert&lt;/h3&gt;

Angreifer nutzen eine gefährliche Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten handeln.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/behoerde-warnt-microsoft-sharepoint-server-werden-attackiert-2607-210462.html&quot;&gt;https://www.golem.de/news/behoerde-warnt-microsoft-sharepoint-server-werden-attackiert-2607-210462.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Jetzt updaten: Kritische Lücken in Ubiquiti UniFi erlauben Remote-Angriffe&lt;/h3&gt;

Mehrere Produkte aus Ubiquitis UniFi-Ökosystem sind von teils kritischen Lücken betroffen. Admins sollten die abgesicherten Versionen zügig einspielen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Jetzt-updaten-Kritische-Luecken-in-Ubiquiti-UniFi-erlauben-Remote-Angriffe-11352622.html&quot;&gt;https://www.heise.de/news/Jetzt-updaten-Kritische-Luecken-in-Ubiquiti-UniFi-erlauben-Remote-Angriffe-11352622.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Angriff per USB-Stick: KI findet gefährliche Lücke in populärem FatFs-Treiber&lt;/h3&gt;

Das bloße Anschließen eines USB-Sticks reicht aus, um auf vielen Embedded- und IoT-Geräten Schadcode einzuschleusen. Einen Patch gibt es bisher nicht. (Sicherheitslücke, Speichermedien)
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luecke-in-populaerem-fatfs-treiber-2607-210484.html&quot;&gt;https://www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luecke-in-populaerem-fatfs-treiber-2607-210484.html&lt;/a&gt;

&lt;hr&gt;
&lt;h3&gt;LWN Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1081187/&quot;&gt;https://lwn.net/Articles/1081187/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NCSC-2026-0219 [1.00] [M/H] Kwetsbaarheden verholpen in GitHub Enterprise Server&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0219&quot;&gt;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0219&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NCSC-2026-0220 [1.00] [M/H] Kwetsbaarheden verholpen in Rancher door Rancher Labs&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0220&quot;&gt;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0220&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-03T18:15:57Z</dc:date></entry><entry><title>Tageszusammenfassung - 02.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-02072026"/><author><name>CERT.at</name></author><updated>2026-07-02T18:23:08Z</updated><published>2026-07-02T18:23:08Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 01-07-2026 18:00 - Donnerstag 02-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Cisco finally confirms attackers exploiting Unified CM flaw&lt;/h3&gt;

Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/cisco-finally-confirms-attackers-exploiting-unified-cm-flaw/&quot;&gt;https://www.bleepingcomputer.com/news/security/cisco-finally-confirms-attackers-exploiting-unified-cm-flaw/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;6 security settings every GitHub maintainer should enable this week&lt;/h3&gt;

These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.
&lt;p /&gt;
&lt;A HREF=&quot;https://github.blog/security/6-security-settings-every-github-maintainer-should-enable-this-week/&quot;&gt;https://github.blog/security/6-security-settings-every-github-maintainer-should-enable-this-week/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ransomware im Anmarsch: Hacker greifen mit fieser Interpol-Masche an&lt;/h3&gt;

Angreifer geben sich bei Unternehmen als Personal von Interpol aus und ködern mit angeblichen Beweismitteln. Doch stattdessen gibt es Ransomware.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-interpol-masche-an-2607-210436.html&quot;&gt;https://www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-interpol-masche-an-2607-210436.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Falsche Rechnungen und Chatpartner bei ZumDaten, MichVerlieben &amp; Co.&lt;/h3&gt;

Eine Rechnung über mehrere hundert Euro von einer Datingplattform, bei der Sie nie ein Konto angelegt haben? Genau das berichten derzeit zahlreiche Betroffene. Doch nicht nur Menschen, die sich nie angemeldet haben, geraten ins Visier: Auch Registrierte können durch fragwürdige Praktiken viel Geld verlieren. Was hinter den Maschen von michverlieben.com, zumdaten.com und Co. steckt - und wie Sie sich dagegen wehren können.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/falsche-zahlungsaufforderungen-von-datingplattformen/&quot;&gt;https://www.watchlist-internet.at/news/falsche-zahlungsaufforderungen-von-datingplattformen/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New ChocoPoC malware targets researchers via trojanized PoC exploits&lt;/h3&gt;

Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Medtronic notifies customers impacted by ShinyHunters data breach&lt;/h3&gt;

Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/&quot;&gt;https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Opera rolls out Paste Protect feature to fight ClickFix attacks&lt;/h3&gt;

Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/opera-rolls-out-paste-protect-feature-to-fight-clickfix-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/opera-rolls-out-paste-protect-feature-to-fight-clickfix-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer&lt;/h3&gt;

Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/veildrop-malware-chain-uses-blogger.html&quot;&gt;https://thehackernews.com/2026/07/veildrop-malware-chain-uses-blogger.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters&lt;/h3&gt;

Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal network port. Synacktiv, which found the bug, says it can lead to a full cluster takeover. There is no fix and no CVE. The firm says it reported the flaw to Argo CD's maintainers in January 2025; roughly eighteen months later, it remains unpatched, so it published the details to warn users.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html&quot;&gt;https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations&lt;/h3&gt;

The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html&quot;&gt;https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fehler in -E-Mail-Adresse verbergen- von Apple weiter ohne Fix&lt;/h3&gt;

-Hide my E-Mail- oder -E-Mail-Adresse verbergen- soll eigentlich User vor Spam und Co. schützen. Es gibt aber eine Lücke. Die Entdecker warten weiter auf Apple. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11351055&quot;&gt;https://heise.de/-11351055&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;PamStealer: a Rust-based macOS infostealer that validates credentials through PAM&lt;/h3&gt;

Jamf Threat Labs investigates PamStealer, a macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/&quot;&gt;https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;WinRAR flaw could allow attackers to take control of your computer&lt;/h3&gt;

A new WinRAR update fixes a serious security flaw, but without automatic updates many users could miss the patch.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/news/2026/07/winrar-flaw-could-allow-attackers-to-take-control-of-your-computer&quot;&gt;https://www.malwarebytes.com/blog/news/2026/07/winrar-flaw-could-allow-attackers-to-take-control-of-your-computer&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Schwachstellen in Synology MailPlus Server lassen Angreifer passieren&lt;/h3&gt;

Netzwerkspeicher von Synology mit MailPlus Server sind attackierbar. Ein Sicherheitspatch schafft Abhilfe.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11351331&quot;&gt;https://heise.de/-11351331&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ClamAV Vulnerabilities Affecting Cisco Products: July 2026&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Catalyst Center Arbitrary File Read Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drupal Security Advisories 2026-July-01&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/security&quot;&gt;https://www.drupal.org/security&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SVD-2026-0701: Third-Party Package Updates in Python for Scientific Computing - July 2026&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0701&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0701&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1080956/&quot;&gt;https://lwn.net/Articles/1080956/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-02T18:23:08Z</dc:date></entry><entry><title>Tageszusammenfassung - 01.07.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/7/tagesberichte-01072026"/><author><name>CERT.at</name></author><updated>2026-07-01T18:23:47Z</updated><published>2026-07-01T18:23:47Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 30-06-2026 18:00 - Mittwoch 01-07-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)&lt;/h3&gt;

For those that don-t start violently wretching when the phrase -Citrix NetScaler- is uttered, we have another word to whisper: -CitrixBleed-. As many know, the term CitrixBleed now refers to not a single vulnerability, but an entire class of Memory Disclosure-esque vulnerabilities in Citrix NetScaler devices, many of which have played roles in breaches and incidents in recent memory. [..] We-ve given up counting the numbers, and so we-ve decided to call this vulnerability -CitrixBleed To Infinity And Beyond-.
&lt;p /&gt;
&lt;A HREF=&quot;https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/&quot;&gt;https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Over 900 Oracle E-Business instances exposed to ongoing attacks&lt;/h3&gt;

Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign&lt;/h3&gt;

Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/tr/the-soc-files-screenconnect-campaign-with-asyncrat/120472/&quot;&gt;https://securelist.com/tr/the-soc-files-screenconnect-campaign-with-asyncrat/120472/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data&lt;/h3&gt;

New Microsoft research shows how attackers can hijack AI agents that act on a users behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/microsoft-warns-poisoned-mcp-tool.html&quot;&gt;https://thehackernews.com/2026/06/microsoft-warns-poisoned-mcp-tool.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS&lt;/h3&gt;

A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. [..] RustDuck does not lean on a single clever trick. It sprays a mix of old, well-known weaknesses and hopes one sticks. The first is the oldest in the book: devices left on the internet with weak or default passwords on their remote-login services (Telnet and SSH). Guess the password, walk in.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html&quot;&gt;https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector&lt;/h3&gt;

Unit 42 researchers found that large language models (LLMs) consistently hallucinate web domains for legitimate brands. Adversaries are actively weaponizing this vector by registering these nonexistent domains to intercept traffic generated by AI systems. We call this phenomenon phantom squatting, and it poses a significant risk to the software supply chain.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/&quot;&gt;https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365&lt;/h3&gt;

Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded &quot;ARToken,&quot; that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/&quot;&gt;https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique&lt;/h3&gt;

In this research, DeepSeek connected unrealistic browser-malware concepts with a real browser capability, turning an AI-generated malware hallucination into a plausible browser-native ransomware technique. Although the generated sample was incomplete, it exposed a practical abuse path based on the File System Access API and access to photo directories.
&lt;p /&gt;
&lt;A HREF=&quot;https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/&quot;&gt;https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Adobe patches seven max severity ColdFusion, Campaign flaws&lt;/h3&gt;

Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/&quot;&gt;https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Riesiges Update: 382 Sicherheitslücken in Google Chrome entdeckt&lt;/h3&gt;

Die neueste Chrome-Version schließt fast 400 teils kritische Sicherheitslücken. Auch für Edge, Vivaldi und Brave dürften entsprechende Updates folgen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-chrome-entdeckt-2607-210372.html&quot;&gt;https://www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-chrome-entdeckt-2607-210372.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service&lt;/h3&gt;

Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. CVE-2026-8451 (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/07/citrix-patches-six-netscaler-flaws.html&quot;&gt;https://thehackernews.com/2026/07/citrix-patches-six-netscaler-flaws.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Root-Sicherheitslücken in alternativer Router-Firmware OpenWRT geschlossen&lt;/h3&gt;

Die OpenWRT-Entwickler haben in einer aktuellen Version unter anderem mehrere kritische Sicherheitslücken geschlossen. [..] Am gefährlichsten gilt eine -kritische- Lücke mit einem CVSSS Score 9.9 von 10 in LuCI. Eine CVE-Nummer wurde offensichtlich bislang nicht vergeben. Voraussetzung für eine Attacke ist, dass der VPN-Dienst Tailscale installiert ist.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Root-Sicherheitsluecken-in-alternativer-Router-Firmware-OpenWRT-geschlossen-11350761.html&quot;&gt;https://www.heise.de/news/Root-Sicherheitsluecken-in-alternativer-Router-Firmware-OpenWRT-geschlossen-11350761.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;HCL BigFix: PC-Fernverwaltung: Man-in-the-Middle-Attacken auf HCL BigFix möglich&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/PC-Fernverwaltung-Man-in-the-Middle-Attacken-auf-HCL-BigFix-moeglich-11350301.html&quot;&gt;https://www.heise.de/news/PC-Fernverwaltung-Man-in-the-Middle-Attacken-auf-HCL-BigFix-moeglich-11350301.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1080689/&quot;&gt;https://lwn.net/Articles/1080689/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;mozilla: Security Vulnerabilities fixed in Thunderbird 140.12.1&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/&quot;&gt;https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;mozilla: Security Vulnerabilities fixed in Thunderbird 152.0.1&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.mozilla.org/en-US/security/advisories/mfsa2026-63/&quot;&gt;https://www.mozilla.org/en-US/security/advisories/mfsa2026-63/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Genucenter: Publish SBA-ADV-20260424-01: Genucenter Disclosure of SNMP Credentials&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://github.com/sbaresearch/advisories/commit/d78bf80a4103af68e8c17ba027e813efc3780d50&quot;&gt;https://github.com/sbaresearch/advisories/commit/d78bf80a4103af68e8c17ba027e813efc3780d50&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-07-01T18:23:47Z</dc:date></entry><entry><title>Tageszusammenfassung - 30.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-30062026"/><author><name>CERT.at</name></author><updated>2026-06-30T18:47:44Z</updated><published>2026-06-30T18:47:44Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 29-06-2026 18:00 - Dienstag 30-06-2026 18:00
Handler:     Guenes Holler
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Parkstrafe per SMS? Kriminelle haben es auf Kreditkartendaten abgesehen!&lt;/h3&gt;

Alles beginnt mit einer SMS-Nachricht zu einer angeblich offenen Parkstrafe. Am Ende hat das Opfer den Kriminellen sein Auto-Kennzeichen und die Kreditkartendaten übermittelt. Eine Phishing-Falle, die klassischer nicht sein könnte. Und so funktioniert sie.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/parkstrafe-per-sms-kreditkartendaten/&quot;&gt;https://www.watchlist-internet.at/news/parkstrafe-per-sms-kreditkartendaten/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Sicherheitslücken ohne Ende: Flut an KI-Bug-Reports überfordert Github&lt;/h3&gt;

Github kommt bei der Bearbeitung von Sicherheitsmeldungen nicht mehr hinterher. Es gibt wohl einen Rückstau von mehreren Wochen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/sicherheitsluecken-ohne-ende-flut-an-ki-bug-reports-ueberfordert-github-2606-210347.html&quot;&gt;https://www.golem.de/news/sicherheitsluecken-ohne-ende-flut-an-ki-bug-reports-ueberfordert-github-2606-210347.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fernwartung SimpleHelp: Schwachstelle wird angegriffen&lt;/h3&gt;

In der Fernwartungssoftware SimpleHelp klafft eine Sicherheitslücke, die die Höchstwertung beim Risiko erreicht. Sie wurde Mitte des Monats bekannt. Jetzt haben IT-Sicherheitsexperten Cyberangriffe auf das Sicherheitsleck beobachtet.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11348620&quot;&gt;https://heise.de/-11348620&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA: Windows BlueHammer flaw now exploited by ransomware gangs&lt;/h3&gt;

CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs/&quot;&gt;https://www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input&lt;/h3&gt;

Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html&quot;&gt;https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Daktronics: Straßenschilder durch Controller-Lücken manipulierbar&lt;/h3&gt;

Durch Sicherheitslücken in Daktronics-Controllern können Angreifer LED-Anzeigetafeln kompromittieren - unter anderem solche am Straßenrand.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/daktronics-strassenschilder-durch-controller-luecken-manipulierbar-2606-210333.html&quot;&gt;https://www.golem.de/news/daktronics-strassenschilder-durch-controller-luecken-manipulierbar-2606-210333.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)&lt;/h3&gt;

This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and CVE-2026-8037 keeps that streak alive: a pre-authentication Remote Code Execution vulnerability accessible to anyone who can access the API. So, in probably a predictable turn of events, we're back doing what we do best. 
&lt;p /&gt;
&lt;A HREF=&quot;https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/&quot;&gt;https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Bot-Schutz: Googles reCaptcha mit Handgesten fällt auf Fotos rein&lt;/h3&gt;

Google hat vergangene Woche angekündigt, den reCaptcha-Bot-Schutz mit Handgesten auszustatten. Das lässt sich mit Fotos aushebeln. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11348830&quot;&gt;https://heise.de/-11348830&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Longinus: 2 Boundaries in One Bug, Piercing Chrome-s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307&lt;/h3&gt;

To understand the bug, we first need a high-level overview of TurboFan, how it inlines JS-to-Wasm calls, and how its deoptimization metadata decides what kind of value should be reconstructed after a lazy deopt. Furthermore, we need to understand how V8 heap sandbox works and why this single vulnerability allows attackers to do two things at once: 1) gain arbitrary read/write primitives in the sandbox, and 2) escape the sandbox to write outside of it.
&lt;p /&gt;
&lt;A HREF=&quot;https://nebusec.ai/research/v8-cve-2026-6307-writeup/&quot;&gt;https://nebusec.ai/research/v8-cve-2026-6307-writeup/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215)&lt;/h3&gt;

A use-after-free in the DRM GEM core ioctl DRM_IOCTL_GEM_CHANGE_HANDLE lets any local user with access to a render node escalate to root. drm_gem_change_handle_ioctl() moves a GEM object from one handle to another, but it never adjusts the object-s handle_count. For a short window the object has two IDR entries while its handle count still reads 1, and a concurrent DRM_IOCTL_GEM_CLOSE on the old handle drives that count to 0 and frees the object while the new handle is still pointing at it. The dangling handle is the use-after-free.
&lt;p /&gt;
&lt;A HREF=&quot;https://cyberstan.co.uk/drm-lpe-linux/&quot;&gt;https://cyberstan.co.uk/drm-lpe-linux/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates&lt;/h3&gt;

Malicious Chrome and Firefox extensions posed as free VPNs while stealing clipboard data through later extension updates.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers?utm_medium=feed&quot;&gt;https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers?utm_medium=feed&lt;/a&gt;

&lt;hr&gt;

&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;iOS 26.5.2, iPadOS 26.5.2 und macOS 26.5.2: Wichtige Sicherheitsfixes wegen KI&lt;/h3&gt;

Apple hat am Montagabend insgesamt drei Betriebssysteme aktualisiert sowie seinen Browser Safari für macOS 15 (Sequoia) und 14 (Sonoma) auf einen neuen Stand gebracht. Systeme und Browser enthalten keine bekannten Neuerungen, dafür stopfen sie diverse Sicherheitslöcher, die Apple laut eigenen Angaben auch aufgrund der neuen Gefahren durch KI flotter liefert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/iOS-26-5-2-iPadOS-26-5-2-und-macOS-26-5-2-Wichtige-Sicherheitsfixes-wegen-KI-11348504.html&quot;&gt;https://www.heise.de/news/iOS-26-5-2-iPadOS-26-5-2-und-macOS-26-5-2-Wichtige-Sicherheitsfixes-wegen-KI-11348504.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ipv6_frag_escape: Linux LPE - Reliable Jail/Container Escape&lt;/h3&gt;

A reliable unprivileged container / jail escape proof of concept for CentOS / RHEL 10.It rides a now fixed IPv6 fragmentation bug in __ip6_append_data() (closed upstream by 38becddc, no CVE), an in-slab linear overflow into the skb_shared_info at the tail of a packet's own head object. This README documents the exploitation chain only. It does not cover the trigger.
&lt;p /&gt;
&lt;A HREF=&quot;https://github.com/sgkdev/ipv6_frag_escape&quot;&gt;https://github.com/sgkdev/ipv6_frag_escape&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1080439/&quot;&gt;https://lwn.net/Articles/1080439/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;DGM3103SCT vulnerable to OS command injection&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://jvn.jp/en/jp/JVN28979424/&quot;&gt;https://jvn.jp/en/jp/JVN28979424/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Security Vulnerabilities fixed in Firefox 152.0.4&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.mozilla.org/en-US/security/advisories/mfsa2026-62/&quot;&gt;https://www.mozilla.org/en-US/security/advisories/mfsa2026-62/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-30T18:47:44Z</dc:date></entry><entry><title>Tageszusammenfassung - 29.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-29062026"/><author><name>CERT.at</name></author><updated>2026-06-29T18:12:40Z</updated><published>2026-06-29T18:12:40Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 26-06-2026 18:00 - Montag 29-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Cybersecurity firms targeted by fraudulent OpenAI organization invites&lt;/h3&gt;

Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites/&quot;&gt;https://www.bleepingcomputer.com/news/security/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Polymarket customers lose $3 million in supply-chain attack&lt;/h3&gt;

Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platforms frontend following a breach at a third-party vendor.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/&quot;&gt;https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hackers now exploit critical Oracle E-Business flaw in attacks&lt;/h3&gt;

Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Root-Zugriff möglich: Exploits für gefährliche Lücke im Linux-Kernel geleakt&lt;/h3&gt;

Admins sollten zügig ihre Linux-Systeme absichern. Auf Github sind Exploits für eine Root-Lücke in Debian, Ubuntu und RHEL aufgetaucht.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/root-zugriff-moeglich-exploits-fuer-gefaehrliche-luecke-im-linux-kernel-geleakt-2606-210283.html&quot;&gt;https://www.golem.de/news/root-zugriff-moeglich-exploits-fuer-gefaehrliche-luecke-im-linux-kernel-geleakt-2606-210283.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The Gentlemen are knocking: -ustom backdoors and evolving tactics&lt;/h3&gt;

Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/the-gentlemen-raas/120447/&quot;&gt;https://securelist.com/the-gentlemen-raas/120447/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Adds Another Year To Windows 10 Extended Update Program&lt;/h3&gt;

Microsoft has quietly extended free Windows 10 security updates for consumers by another year, pushing the Extended Security Updates (ESU) programs end date from October 12, 2026, to October 12, 2027. &quot;The ESU support page was updated with that date, and Microsofts blog post on the program has a new editors note confirming the change,&quot; reports Ars Technica. From the report: The prevalence of Windows across so many devices and form factors has given Microsoft a ..
&lt;p /&gt;
&lt;A HREF=&quot;https://tech.slashdot.org/story/26/06/26/0029235/microsoft-adds-another-year-to-windows-10-extended-update-program&quot;&gt;https://tech.slashdot.org/story/26/06/26/0029235/microsoft-adds-another-year-to-windows-10-extended-update-program&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks&lt;/h3&gt;

A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, ..
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html&quot;&gt;https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft keeps Windows Server 2022 hotpatching alive into 2027&lt;/h3&gt;

In the Azure Edition, of course
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/06/29/microsoft-keeps-windows-server-2022-hotpatching-alive-into-2027/5263688&quot;&gt;https://www.theregister.com/security/2026/06/29/microsoft-keeps-windows-server-2022-hotpatching-alive-into-2027/5263688&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253)&lt;/h3&gt;

Splunk disclosed a critical unauthenticated remote code execution (RCE) vulnerability in Splunk Enterprise tracked as CVE-2026-20253 on June 10, 2026. The vulnerability has a CVSS score of 9.8 and stems from missing authentication on a PostgreSQL sidecar service recovery endpoint that can be reached through the Splunk Web interface, which proxies requests to the internal PostgreSQL sidecar service without enforcing authentication. A successful attacker can create or truncate ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zscaler.com/blogs/security-research/critical-unauthenticated-remote-code-execution-splunk-enterprise-cve-2026&quot;&gt;https://www.zscaler.com/blogs/security-research/critical-unauthenticated-remote-code-execution-splunk-enterprise-cve-2026&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Taiwan: Cybersicherheitsbehörde warnt vor Überwachung durch billige eSIMs&lt;/h3&gt;

Günstig für den Urlaub erworbene eSIMs könnten Datenverkehr durch China leiten, warnt Taiwans Digitalministerium. Dabei könnten Daten abgegriffen werden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Taiwanische-Cybersicherheitsbehoerde-warnt-vor-Ueberwachung-durch-billige-eSIMs-11347212.html&quot;&gt;https://www.heise.de/news/Taiwanische-Cybersicherheitsbehoerde-warnt-vor-Ueberwachung-durch-billige-eSIMs-11347212.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FBI-Warnung: Russischer Geheimdienst sieht es auf Messenger-Backup-Keys ab&lt;/h3&gt;

Russische Angreifer geben sich inzwischen als Messenger-Support aus, der Zugriff auf die Backup-Wiederherstellungsschlüssel braucht.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/FBI-Warnung-Russischer-Geheimdienst-sieht-es-auf-Messenger-Backup-Keys-ab-11347302.html&quot;&gt;https://www.heise.de/news/FBI-Warnung-Russischer-Geheimdienst-sieht-es-auf-Messenger-Backup-Keys-ab-11347302.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cyberangriffe auf Hotel- und Gastgewerbe: Täter nisten sich ein&lt;/h3&gt;

Microsoft Threat Intelligence beobachtet eine mehrstufige Angriffswelle auf das Hotel- und Gastgewerbe in Asien und Europa.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Cyberangriffe-auf-Hotel-und-Gastgewerbe-Taeter-nisten-sich-ein-11347609.html&quot;&gt;https://www.heise.de/news/Cyberangriffe-auf-Hotel-und-Gastgewerbe-Taeter-nisten-sich-ein-11347609.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Kritische libssh2-Lücke: Proof-of-Concept-Exploit veröffentlicht&lt;/h3&gt;

Vergangene Woche wurde eine Sicherheitslücke in libssh2 bekannt. Jetzt ist Exploit-Code aufgetaucht, der sie missbrauchen kann.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Kritische-libssh2-Luecke-Proof-of-Concept-Exploit-veroeffentlicht-11347855.html&quot;&gt;https://www.heise.de/news/Kritische-libssh2-Luecke-Proof-of-Concept-Exploit-veroeffentlicht-11347855.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hacking-Fähigkeiten von Chinas KI Z.ai angeblich so gut wie die von Claude&lt;/h3&gt;

Zhipu AIs offenes Modell GLM-5.2 erreicht laut Sicherheitsexperten die Fähigkeiten von Anthropics Mythos bei der Bug-Erkennung.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Hacking-Faehigkeiten-von-Chinas-KI-Z-ai-angeblich-so-gut-wie-die-von-Claude-11348003.html&quot;&gt;https://www.heise.de/news/Hacking-Faehigkeiten-von-Chinas-KI-Z-ai-angeblich-so-gut-wie-die-von-Claude-11348003.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Harnessing Harnesses - Climbing the LLM Hills&lt;/h3&gt;

Trying to coerce useful work out of LLMs without the harness is like supervising a room full of drunk toddlers, each convinced theyre helping, none of them checking with each other and falling over the next.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.zsec.uk/harnessing-harnesses/&quot;&gt;https://blog.zsec.uk/harnessing-harnesses/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;From Perimeter to Proof: The New Architecture of Email Security&lt;/h3&gt;

How identity, investigation, browser security, and AI are reshaping the future of email defense.
&lt;p /&gt;
&lt;A HREF=&quot;https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture&quot;&gt;https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages&lt;/h3&gt;

Latest wave affects legitimate @immobiliarelabs Backstage packages, with malicious npm releases published across GitLab and LDAP authentication plugin families on June 26, 2026.Socket Threat Research is tracking a fresh compromise in the ongoing Miasma Mini Shai-Hulud supply chain campaign. The latest activity affects legitimate npm packages published under the @immobiliarelabs scope, including Backstage plugins used for GitLab integration and LDAP authentication ..
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/miasma-mini-shai-hulud-hits-immobiliarelabs-npm-packages&quot;&gt;https://socket.dev/blog/miasma-mini-shai-hulud-hits-immobiliarelabs-npm-packages&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-29T18:12:40Z</dc:date></entry><entry><title>Tageszusammenfassung - 26.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-26062026"/><author><name>CERT.at</name></author><updated>2026-06-26T18:05:19Z</updated><published>2026-06-26T18:05:19Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 25-06-2026 18:00 - Freitag 26-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;New macOS malware embeds fake errors to confuse AI analysis tools&lt;/h3&gt;

A newly discovered macOS malware dubbed &quot;Gaslight&quot; is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-macos-malware-embeds-fake-errors-to-confuse-ai-analysis-tools/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-macos-malware-embeds-fake-errors-to-confuse-ai-analysis-tools/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Order-tracking app Shop abused to push callback phishing attacks&lt;/h3&gt;

Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users order histories to trick them into providing sensitive data or installing remote access software.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/order-tracking-app-shop-abused-to-push-callback-phishing-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/order-tracking-app-shop-abused-to-push-callback-phishing-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Security boss thought MFA would be too much security&lt;/h3&gt;

One rule for the workers, another for execs
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/06/26/security-boss-thought-mfa-would-be-too-much-security/5261934&quot;&gt;https://www.theregister.com/security/2026/06/26/security-boss-thought-mfa-would-be-too-much-security/5261934&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Miasma campaign poisons 20-plus npm packages, hunts for developer secrets&lt;/h3&gt;

Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/06/26/miasma-campaign-poisons-20-plus-npm-packages-hunts-for-developer-secrets/5262886&quot;&gt;https://www.theregister.com/security/2026/06/26/miasma-campaign-poisons-20-plus-npm-packages-hunts-for-developer-secrets/5262886&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds&lt;/h3&gt;

Researchers warn many AI coding assistants now execute commands from project configurations
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/cyber-crime/2026/06/26/amazon-q-flaw-let-booby-trapped-git-repos-execute-code-swipe-cloud-creds/5263202&quot;&gt;https://www.theregister.com/cyber-crime/2026/06/26/amazon-q-flaw-let-booby-trapped-git-repos-execute-code-swipe-cloud-creds/5263202&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;YouTube-Werbeblocker mit 11 Millionen Installationen mit möglicher Hintertür&lt;/h3&gt;

Adblock for YouTube kommt auf mehr als 11 Millionen Installationen. Es kann jedoch unkontrolliert Script-Code in jede Seite injizieren.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/YouTube-Werbeblocker-mit-11-Millionen-Installationen-mit-moeglicher-Hintertuer-11345655.html&quot;&gt;https://www.heise.de/news/YouTube-Werbeblocker-mit-11-Millionen-Installationen-mit-moeglicher-Hintertuer-11345655.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Polymarket: Kriminelle sollen Kryptowerte in Millionenhöhe gestohlen haben&lt;/h3&gt;

Bei Polymarket haben Angreifer über eingeschleusten Schadcode Geld von Nutzerkonten gestohlen. Das Wettportal will Betroffene entschädigen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Polymarket-Kriminelle-entwenden-Kryptowerte-in-Millionenhoehe-11345764.html&quot;&gt;https://www.heise.de/news/Polymarket-Kriminelle-entwenden-Kryptowerte-in-Millionenhoehe-11345764.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Malware steals Chrome session cookies to take over your accounts&lt;/h3&gt;

A phishing campaign installs a malicious Chrome extension to hijack browser sessions and compromise Windows devices.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/news/2026/06/malware-steals-chrome-session-cookies-to-take-over-your-accounts&quot;&gt;https://www.malwarebytes.com/blog/news/2026/06/malware-steals-chrome-session-cookies-to-take-over-your-accounts&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The &quot;Akrites&quot; vulnerability-mitigation project launches&lt;/h3&gt;

The Linux Foundation, in aletter co-signed by a large range of organizations and companies, hasannounced the launch of &quot;Akrites&quot;, a project to fast-track vulnerabilityfixes into projects. As Akrites works upstream to fix projects at the source, we commit to support downstream efforts to secure critical infrastructure before it can be exploited. When patches are ..
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1079657/&quot;&gt;https://lwn.net/Articles/1079657/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Russia used social engineering to breach prominent messaging accounts, Ukraine says&lt;/h3&gt;

Ukraines SBU described a long-running Russian operation that used fake tech-support workers to persuade people to hand over credentials to their messaging apps.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/russia-ukraine-social-engineering-messaging-accounts&quot;&gt;https://therecord.media/russia-ukraine-social-engineering-messaging-accounts&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;DHS chief says president has met with likely CISA nominee; agency plans to hire 600&lt;/h3&gt;

Once a new CISA director is in place, the agency will ramp up hiring efforts, Homeland Security Secretary Markwayne Mullin told lawmakers. The White House has not yet announced a nominee.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/cisa-director-nominee-workforce-hires-mullin-house-hearing&quot;&gt;https://therecord.media/cisa-director-nominee-workforce-hires-mullin-house-hearing&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;macOS Flaw Allowed Standard Users to Disable CrowdStrike and Kandji Security Tools&lt;/h3&gt;

A macOS XPC flaw let regular users disable CrowdStrike and Kandji tools, exposing security gaps that vendors patched after XM Cyber reported the security issue.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/macos-flaw-users-disable-crowdstrike-kandji-security-tools/&quot;&gt;https://hackread.com/macos-flaw-users-disable-crowdstrike-kandji-security-tools/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem&lt;/h3&gt;

Latest wave affects LeoPlatform/RStreams npm packages, three llxlr-published npm packages, the Verana Blockchain Go module, and GitHub Actions/developer-tool workflows.Socket Threat Research is tracking a new ..
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem&quot;&gt;https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;



&lt;h3&gt;Synology-SA-26:11 Synology MailPlus Server&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.synology.com/en-global/support/security/Synology_SA_26_11&quot;&gt;https://www.synology.com/en-global/support/security/Synology_SA_26_11&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;[R2] Nessus Version 10.12.1 Fixes SQL Injection Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.tenable.com/security/tns-2026-17&quot;&gt;https://www.tenable.com/security/tns-2026-17&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;[R3] Tenable Identity Exposure Version 3.93.5 Fixes Multiple Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.tenable.com/security/tns-2026-16&quot;&gt;https://www.tenable.com/security/tns-2026-16&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-26T18:05:19Z</dc:date></entry><entry><title>Tageszusammenfassung - 25.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-25062026"/><author><name>CERT.at</name></author><updated>2026-06-25T19:41:57Z</updated><published>2026-06-25T19:41:57Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 24-06-2026 18:00 - Donnerstag 25-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Malicious Edge extension abuses Native Messaging as bridge to malware&lt;/h3&gt;

A malicious Microsoft Edge extension dubbed Edgecution has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/&quot;&gt;https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access&lt;/h3&gt;

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/&quot;&gt;https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools&lt;/h3&gt;

In the first four months of 2026, Kaspersky solutions detected over 33,300 cyberattacks on SMBs masquerading as popular artificial intelligence (AI) tools - almost five times more than in 2025 and 39% more than the number of attacks disguised as the office and collaboration tools that Kaspersky-s research focuses on.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/smb-threat-report-2026/120357/&quot;&gt;https://securelist.com/smb-threat-report-2026/120357/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;What do Ports Hear When Nobodys Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)&lt;/h3&gt;

For network defenders and analysts, it's important to understand the depth of the noise and how it should be treated. Observing patterns and structural shifts within the static is essential for keeping pace with an automated, multi-directional threat that never stops running. The infrastructure persists, campaigns evolve, payloads update, and the ports keep listening.
&lt;p /&gt;
&lt;A HREF=&quot;https://isc.sans.edu/diary/rss/33104&quot;&gt;https://isc.sans.edu/diary/rss/33104&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;StealC Historical Bot Infection Special Report&lt;/h3&gt;

On Wednesday 24th June 2026, international law enforcement partners announced additional successful cyber crime disruption actions as part of the ongoing Operation Endgame initiative. This time the StealC infostealer and Amadey malware-as-a-service families were targeted.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.shadowserver.org/news/stealc-historical-bot-infection-special-report/&quot;&gt;https://www.shadowserver.org/news/stealc-historical-bot-infection-special-report/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Verfassungsschutz zu Spionage: Unis sollen wachsamer sein&lt;/h3&gt;

Sicherheitsbehörden warnen vor chinesischer Wissenschaftsspionage an deutschen Hochschulen. Sind die Forschungseinrichtungen wachsam genug?
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Verfassungsschutz-zu-Spionage-Unis-sollen-wachsamer-sein-11343924.html&quot;&gt;https://www.heise.de/news/Verfassungsschutz-zu-Spionage-Unis-sollen-wachsamer-sein-11343924.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Raiffeisen Phishingmail fordert zur pushTAN-Aktivierung auf&lt;/h3&gt;

Aktuell versenden Kriminelle betrügerische E-Mails im Namen der Raiffeisen Bank. Die Nachrichten fordern Kund:innen auf, über einen Link den pushTAN-Dienst zu aktivieren und führen dabei auf eine gefälschte Website, die Kontodaten abgreift.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/raiffeisen-phishingmail-fordert-pushtan-aktivierung-auf/&quot;&gt;https://www.watchlist-internet.at/news/raiffeisen-phishingmail-fordert-pushtan-aktivierung-auf/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Introduction to COM usage by Windows threats&lt;/h3&gt;

Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threats/&quot;&gt;https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threats/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Windows 10: Sicherheitsupdates für Privatkunden jetzt doch noch bis Oktober 2027&lt;/h3&gt;

Microsoft hat das ESU-Programm für Privatkunden ohne große Vorankündigung um ein weiteres Jahr verlängert.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11344923&quot;&gt;https://heise.de/-11344923&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond&lt;/h3&gt;

Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.
&lt;p /&gt;
&lt;A HREF=&quot;https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/&quot;&gt;https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ignore DNSSEC if you like MITM attacks&lt;/h3&gt;

It really bothers me that almost all distributions and operating systems don-t validate DNSSEC by default. The above attacks are feasible on almost anyone, purely because of lousy defaults.
&lt;p /&gt;
&lt;A HREF=&quot;https://whynothugo.nl/journal/2026/06/24/ignore-dnssec-if-you-like-mitm-attacks/&quot;&gt;https://whynothugo.nl/journal/2026/06/24/ignore-dnssec-if-you-like-mitm-attacks/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;

&lt;h3&gt;LWN: Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1079551/&quot;&gt;https://lwn.net/Articles/1079551/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-25T19:41:57Z</dc:date></entry><entry><title>Tageszusammenfassung - 24.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-24062026"/><author><name>CERT.at</name></author><updated>2026-06-24T18:20:32Z</updated><published>2026-06-24T18:20:32Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 23-06-2026 18:00 - Mittwoch 24-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;New macOS ClickFix attack silently mounts DMGs to push infostealer&lt;/h3&gt;

A new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks&lt;/h3&gt;

A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Stealthy Mistic backdoor linked to ransomware access broker KongTuke&lt;/h3&gt;

A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/&quot;&gt;https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Sicherheitslücke: Millionen von Samsung-Smartphones durch Kernel-Bug gefährdet&lt;/h3&gt;

Forscher haben einen gefährlichen Bug im Android-Kernel von Samsung entdeckt, der unzählige Smartphones zwischen Galaxy S9 und S25 betrifft.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/sicherheitsluecke-acht-jahre-alter-kernel-bug-gefaehrdet-samsung-smartphones-2606-210117.html&quot;&gt;https://www.golem.de/news/sicherheitsluecke-acht-jahre-alter-kernel-bug-gefaehrdet-samsung-smartphones-2606-210117.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root&lt;/h3&gt;

Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, ..
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html&quot;&gt;https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Home Assistant: Update stopft Informationsleck&lt;/h3&gt;

Die jüngeren Home-Assistant-Updates stopfen unter anderem Informationslecks. Zudem gibt es das Home Assistant OS in neuer Version.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Home-Assistant-Update-stopft-Informationsleck-11342266.html&quot;&gt;https://www.heise.de/news/Home-Assistant-Update-stopft-Informationsleck-11342266.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ubiquiti UniFi OS-Sicherheitslücken werden angegriffen&lt;/h3&gt;

Ende Mai wurden kritische Sicherheitslücken in Ubiquiti UniFi OS bekannt. Inzwischen haben Angreifer diese im Visier.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Ubiquiti-UniFi-OS-Sicherheitsluecken-werden-angegriffen-11343015.html&quot;&gt;https://www.heise.de/news/Ubiquiti-UniFi-OS-Sicherheitsluecken-werden-angegriffen-11343015.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cyberkriminelle: Die -Wirtschaftsprüfer-, die Sie nie beauftragt haben&lt;/h3&gt;

Jede Organisation wird geprüft. Die Frage ist, wer die Prüfung durchführt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.welivesecurity.com/de/business-security/cyberkriminelle-die-wirtschaftsprufer-die-sie-nie-beauftragt-haben/&quot;&gt;https://www.welivesecurity.com/de/business-security/cyberkriminelle-die-wirtschaftsprufer-die-sie-nie-beauftragt-haben/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hackergruppe will den Flughafen Wien angegriffen haben&lt;/h3&gt;

Als Beweis wurden Frachtpapiere mit Waffenlieferungen veröffentlicht. Laut dem Flughafen Wien sind keine personenbezogenen Daten darunter
&lt;p /&gt;
&lt;A HREF=&quot;https://www.derstandard.at/story/3000000328608/hackergruppe-will-den-flughafen-wien-angegriffen-haben&quot;&gt;https://www.derstandard.at/story/3000000328608/hackergruppe-will-den-flughafen-wien-angegriffen-haben&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zoho Corp. ManageEngine: Kritische SSO-Lücke ermöglicht Kontenübernahme&lt;/h3&gt;

Angreifer können eine kritische Sicherheitslücke in mehreren Zoho Corp. ManageEngine-Produkten missbrauchen, um Konten zu übernehmen.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11342888&quot;&gt;https://heise.de/-11342888&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;



&lt;h3&gt;Security updates for Wednesday&lt;/h3&gt;

Security updates have been issued by AlmaLinux (corosync, firefox, kernel, kernel-rt, libpq, memcached, postgresql, postgresql16, postgresql:13, postgresql:16, python-urllib3, python3.14-urllib3, redis:6, skopeo, and vim), Debian (beets, gst-plugins-bad1.0, imagemagick, libmatio, python-urllib3, and u-boot), Fedora (chromium, coturn, frr, grout, materialx, perl-Crypt-DSA, and yt-dlp), Mageia (opensc, perl-Archive-Tar, and podofo), Oracle (fence-agents, libpq, mysql:8.4, and postgresql:16), ..
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1079365/&quot;&gt;https://lwn.net/Articles/1079365/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;[R1] Tenable Identity Exposure Version 3.93.5 Fixes Multiple Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.tenable.com/security/tns-2026-16&quot;&gt;https://www.tenable.com/security/tns-2026-16&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-24T18:20:32Z</dc:date></entry><entry><title>Tageszusammenfassung - 23.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-23062026"/><author><name>CERT.at</name></author><updated>2026-06-23T18:36:50Z</updated><published>2026-06-23T18:36:50Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 22-06-2026 18:00 - Dienstag 23-06-2026 18:00
Handler:     Guenes Holler
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Auswirkungen auf die Cybersicherheit von Organisationen durch die Entwicklung im Bereich Künstlicher Intelligenz&lt;/h3&gt;

Künstliche Intelligenz verändert die Cybersicherheitslage grundlegend und erfordert neue Maßstäbe in der Reaktionsgeschwindigkeit. Während böswillige Akteure in der Vergangenheit bereits arbeitsteilig auf Künstliche Intelligenz gesetzt hatten - beispielsweise um Phishing-Mails zu verfassen - sind aktuelle KI-Systeme derart leistungsfähig, dass Schwachstellen in Software innerhalb kurzer Zeit sowohl umfassend als auch teilweise autonom erkannt, analysiert und in verwertbare Angriffspfade überführt können. Daraus kann eine Lage entstehen, die Organisationen mit einer erheblich steigenden Zahl neu entdeckter Schwachstellen, Exploits, Patches und Folgevorfällen konfrontiert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-262788-1032.pdf&quot;&gt;https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-262788-1032.pdf&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WhatsApp phishing attack uses fake business docs to hack PCs&lt;/h3&gt;

An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs/&quot;&gt;https://www.bleepingcomputer.com/news/security/whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Nearly Half of LG Smart TV Apps Are Laced with Proxies&lt;/h3&gt;

Everyone worries about the apps on their phone. Almost no one looks at the ones on their TV. We scanned 6,038 of them across LG and Samsung; 2,058 were selling your IP address. On screen, its a relaxing fish tank. Or a clock. Or solitaire. Or puppies. Under the hood, it is a residential proxy: software that can send other peoples internet traffic out through your living room. And we found it everywhere.
&lt;p /&gt;
&lt;A HREF=&quot;https://spur.us/blog/smart-tv-apps-residential-proxy-sdks&quot;&gt;https://spur.us/blog/smart-tv-apps-residential-proxy-sdks&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Nach Protesten: AMD bringt RAM-Verschlüsselung TSME zurück&lt;/h3&gt;

Ohne Ankündigung hat AMD das Sicherheitsmerkmal TSME bei bestimmten Ryzen-Prozessoren deaktiviert. Kunden protestierten, AMD reagiert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Nach-Protesten-AMD-bringt-RAM-Verschluesselung-TSME-zurueck-11340937.html&quot;&gt;https://www.heise.de/news/Nach-Protesten-AMD-bringt-RAM-Verschluesselung-TSME-zurueck-11340937.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Secure-Boot: Zertifikatablauf steht an, Microsoft gibt weitere Hilfestellung&lt;/h3&gt;

Die ersten Secure-Boot-Zertifikate laufen in diesen Tagen ab. Microsoft legt noch mal Handreichungen nach, für Linux auf Azure-VMs.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Secure-Boot-Zertifikate-Ablauf-startet-weitere-Handreichungen-von-Microsoft-11341007.html&quot;&gt;https://www.heise.de/news/Secure-Boot-Zertifikate-Ablauf-startet-weitere-Handreichungen-von-Microsoft-11341007.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration&lt;/h3&gt;

We recently identified a bucket hijacking technique impacting multiple services across major cloud service providers (CSPs). The attack technique exploits a fundamental architectural flaw that is common across cloud providers and could potentially affect other cloud providers as well.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/&quot;&gt;https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Detecting the Klue supply chain attack in Salesforce instances&lt;/h3&gt;

We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.
&lt;p /&gt;
&lt;A HREF=&quot;https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/&quot;&gt;https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake-Shops, Abo-Fallen, Phishing-Gewinnspiele: Wie Kriminelle das Fußball-Fieber nutzen&lt;/h3&gt;

Die Weltmeisterschaft in den USA, Mexiko und Kanada ist in vollem Gange. Dass Betrüger:innen von diesem Hype profitieren möchten, überrascht nicht. Dieser Artikel zeigt, welche Strategien und Mechanismen sie für ihre Fallen nutzen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/fake-shops-abofallen-fussball/&quot;&gt;https://www.watchlist-internet.at/news/fake-shops-abofallen-fussball/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Introducing Patch the Planet&lt;/h3&gt;

What happens when you clear dozens of Trail of Bits engineers- schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we can report that the impact is hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects (with many more still undergoing coordinated disclosure). That was just the first week of Patch the Planet.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/&quot;&gt;https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Pixelsmash: Lücke in FFmpeg-Decoder gefährdet unzählige Systeme&lt;/h3&gt;

Sicherheitsforscher von JFrog haben eine gefährliche Sicherheitslücke in dem weitverbreiteten freien Multimedia-Framework FFmpeg aufgedeckt. Wie die Forscher in einem Blogbeitrag schildern, können Angreifer damit zahlreiche auf FFmpeg angewiesene Softwarelösungen zum Absturz bringen. In einigen Fällen, etwa bei Jellyfin und Nextcloud, soll sogar eine Schadcodeausführung möglich sein.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/pixelsmash-luecke-in-ffmpeg-decoder-gefaehrdet-unzaehlige-systeme-2606-210068.html&quot;&gt;https://www.golem.de/news/pixelsmash-luecke-in-ffmpeg-decoder-gefaehrdet-unzaehlige-systeme-2606-210068.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1079083/&quot;&gt;https://lwn.net/Articles/1079083/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NCSC-2026-0209 [1.00] [M/H] Kwetsbaarheden verholpen in MongoDB Server&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0209&quot;&gt;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0209&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-23T18:36:50Z</dc:date></entry><entry><title>Tageszusammenfassung - 22.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-22062026"/><author><name>CERT.at</name></author><updated>2026-06-22T18:20:23Z</updated><published>2026-06-22T18:20:23Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 19-06-2026 18:00 - Montag 22-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Angriffswelle gegen FortiGate Devices - &quot;FortiBleed&quot;&lt;/h3&gt;

Fortinet hat letzten Freitag, am 19.5.2026, nun auch ein offizielles Statement zu &quot;FortiBleed&quot; veröffentlicht. Wir hatten zuvor in einem Blog-Artikel unseren aktuellen Wissensstand beschrieben. Bei dieser Angriffswelle handelt es sich nicht um die Ausnutzung einer neuen Schwachstelle. Die Angreifer:innen verwenden stattdessen Zugangsdaten, die bei früheren Sicherheitsvorfällen (u. a. im Zusammenhang mit CVE-2025-59718, CVE-2025-59719 und CVE-2026-24858) erlangt wurden, sowie Brute-Force-Methoden gegen Geräte mit schwacher Passworthygiene und ohne Multi-Faktor-Authentifizierung (MFA).
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/warnungen/2026/6/angriffswelle-gegen-fortigate-devices-fortibleed&quot;&gt;https://www.cert.at/de/warnungen/2026/6/angriffswelle-gegen-fortigate-devices-fortibleed&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New Prinz Eugen ransomware prioritizes recent files for encryption&lt;/h3&gt;

A new ransomware operation named Prinz Eugen prioritizes recently modified files for encryption and leaves no ransom note on the system.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Squidbleed: 29 Jahre alte Lücke in populärer Proxy-Software entdeckt&lt;/h3&gt;

Die zuletzt unter anderem durch die Entdeckung von HTTP/2 Bomb aufgefallenen Sicherheitsforscher von Calif haben mithilfe von Claude Mythos eine Sicherheitslücke in der weitverbreiteten freien Proxyserver-Software Squid entdeckt. Angreifer können damit Speicherinhalte leaken und Daten aus von Squid verarbeiteten HTTP-Requests abgreifen. Die Besonderheit dabei: Die Lücke wurde 1997 eingeführt und blieb damit fast drei Jahrzehnte unentdeckt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/squidbleed-29-jahre-alte-luecke-in-populaerer-proxy-software-entdeckt-2606-210022.html&quot;&gt;https://www.golem.de/news/squidbleed-29-jahre-alte-luecke-in-populaerer-proxy-software-entdeckt-2606-210022.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network&lt;/h3&gt;

A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. [..] The campaign goes after routers built on Realtek's RTL819X chips, hardware that was current around 2012 to 2015. XLab first saw it on March 12, 2026, spreading from a single IP, 107.150.106.14. [..] The infected pool is mostly D-Link, with the DIR-850L alone making up about 75 percent.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html&quot;&gt;https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer&lt;/h3&gt;

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html&quot;&gt;https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Anlagebetrug mit Promi-Namen: Gefälschter oe24-Artikel lockt in die Falle&lt;/h3&gt;

Angebliche Anlagetipps von Prominenten sind oft Teil einer Betrugsmasche. Aktuell missbrauchen Kriminelle den Namen von Armin Wolf und der Raiffeisen Bank für eine gefälschte Berichterstattung im Design von oe24. Das Ziel besteht darin, Leser:innen auf eine betrügerische Anlageplattform zu locken.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/anlagebetrug-mit-promi-namen-gefaelschter-oe24-artikel-lockt-in-die-falle/&quot;&gt;https://www.watchlist-internet.at/news/anlagebetrug-mit-promi-namen-gefaelschter-oe24-artikel-lockt-in-die-falle/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Popa Botnetz kapert Smart TVs für Web-Scraping&lt;/h3&gt;

icherheitsforscher haben ein Botnetz enttarnt, welches Millionen Smart TVs gekapert hat. Die Millionen Android Smart TV-Geräte, die Teil des Popa-Botnets sind, leiteten Webverkehr (Web-Scaping) an dessen Betreiber weiter.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/06/22/popa-botnetz-kapert-smart-tvs-fuer-web-scraping/&quot;&gt;https://borncity.com/blog/2026/06/22/popa-botnetz-kapert-smart-tvs-fuer-web-scraping/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mark-of-the-web and pinning installers to sites&lt;/h3&gt;

While MoTW is intended for the operating system and other origin-aware applications such as MSFT Office to make security decisions, an executable can also access its own MoTW. This is the basis for a proof-of-concept with a simple Win32 GUI application ...
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.randomoracle.io/2026/06/20/mark-of-the-web-and-pinning-installers-to-sites/&quot;&gt;https://blog.randomoracle.io/2026/06/20/mark-of-the-web-and-pinning-installers-to-sites/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;libssh2: Teils kritische Lücken in populärer SSH-Bibliothek&lt;/h3&gt;

Angreifer können CVE-2026-55200 ausnutzen, indem sie speziell gestaltete SSH-Pakete mit übermäßig großen package_length-Werten übermitteln und dadurch Schreibvorgänge außerhalb vorgesehener Grenzen auslösen. Die Folge ist eine Korruption des Heap-Speichers, wodurch im schlimmsten Fall Schadcode eingeschleust und zur Ausführung gebracht werden kann. [..] Alle Versionen von libssh2 bis einschließlich der seit Oktober 2024 als aktuell geltenden Version 1.11.1 sollen anfällig für CVE-2026-55199 und CVE-2026-55200 sein. Korrekturen wurden mit den Commits 1762685 und 97acf3d bereitgestellt. Wann ein neues Release mit den beiden Patches erscheint, ist noch unklar.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/libssh2-teils-kritische-luecken-in-populaerer-ssh-bibliothek-2606-210011.html&quot;&gt;https://www.golem.de/news/libssh2-teils-kritische-luecken-in-populaerer-ssh-bibliothek-2606-210011.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Bamboo, Confluence &amp; Co.: Atlassian schließt 100 Sicherheitslücken&lt;/h3&gt;

Wie aus dem Sicherheitsbereich der Atlassian-Website hervorgeht, haben die Entwickler in aktuellen Versionen insgesamt 100 Lücken geschlossen. Davon sind neben dem eigenen Code auch Abhängigkeiten zu etwa Apache Tomcat betroffen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Bamboo-Confluence-Co-Atlassian-schliesst-100-Sicherheitsluecken-11336541.html&quot;&gt;https://www.heise.de/news/Bamboo-Confluence-Co-Atlassian-schliesst-100-Sicherheitsluecken-11336541.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1078922/&quot;&gt;https://lwn.net/Articles/1078922/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-22T18:20:23Z</dc:date></entry><entry><title>Tageszusammenfassung - 19.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-19062026"/><author><name>CERT.at</name></author><updated>2026-06-19T18:14:16Z</updated><published>2026-06-19T18:14:16Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 18-06-2026 18:00 - Freitag 19-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;USB worm spreads crypto-stealing malware via Windows shortcut files&lt;/h3&gt;

Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/usb-worm-spreads-crypto-stealing-malware-via-windows-shortcut-files/&quot;&gt;https://www.bleepingcomputer.com/news/security/usb-worm-spreads-crypto-stealing-malware-via-windows-shortcut-files/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Jailbreak möglich: Wohl unpatchbarer Hardware-Bug gefährdet iPhones&lt;/h3&gt;

Forscher haben einen offenbar unpatchbaren Bug entdeckt, der Jailbreaks für mehrere iPhone-, iPad- und Apple-Watch-Modelle ermöglichen könnte.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/jailbreak-moeglich-wohl-unpatchbarer-hardware-bug-gefaehrdet-iphones-2606-209965.html&quot;&gt;https://www.golem.de/news/jailbreak-moeglich-wohl-unpatchbarer-hardware-bug-gefaehrdet-iphones-2606-209965.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Warnung vor Fake-Rechnungen von Sixt Server&lt;/h3&gt;

Derzeit melden sich zahlreiche Unternehmen bei uns, die Rechnungen für angebliche Cloud-Dienstleistungen erhalten haben. Tatsächlich handelt es sich dabei um einen Betrugsversuch: Die gefälschten Rechnungen sollen Unternehmen zu einer unberechtigten Zahlung verleiten.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/fake-rechnungen-von-sixt-server/&quot;&gt;https://www.watchlist-internet.at/news/fake-rechnungen-von-sixt-server/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Killing me gently: Inside Gentlemen-s EDR killer framework&lt;/h3&gt;

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/&quot;&gt;https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Brand der Floridsdorfer Brücke: Glasfaserausfälle in Wien&lt;/h3&gt;

Heute hat es auf der Floridsdorfer Brücke gebrannt. Was der ORF nicht meldet ist, dass über diese Brücke auch Glasfasertrassen geführt werden, und dass durch den Brand einige dieser Leitungen ausgefallen sind. Wenn man die Standorte der relevanten Rechenzentren in Wien kennt, dann ist sofort klar, dass das sehr relevant ist. Bei uns ging bis jetzt eine formelle NIS Meldung ein, weiters haben wir informell von anderen Organisationen gehört, dass sie betroffen sind.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/aktuelles/2026/6/brand-der-floridsdorfer-brucke-glasfaserausfalle-in-wien&quot;&gt;https://www.cert.at/de/aktuelles/2026/6/brand-der-floridsdorfer-brucke-glasfaserausfalle-in-wien&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says&lt;/h3&gt;

The nonprofit Human Rights Watch obtained export licensing records covering 2018 through 2023, which show the Bulgarian government allowed the surveillance firm Circles to peddle the tech to law enforcement and intelligence agencies in several countries known for human rights abuses.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/bulgaria-allowed-surveillance-tech-firm-to-sell-to-repressive-regimes-report&quot;&gt;https://therecord.media/bulgaria-allowed-surveillance-tech-firm-to-sell-to-repressive-regimes-report&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM&lt;/h3&gt;

A pre-authentication remote code execution (RCE) chain in Oracle PeopleSoft PeopleTools reaches an internal-only management servlet through a server-side request forgery (SSRF) in the PSIGW gateway, then gains code execution through Java XMLDecoder deserialization. Oracle assigned CVE-2026-35273 (CVSS 9.8) and released an out-of-band patch on June 10, 2026. [..] Our researchers discovered new information about this vulnerability, which was responsibly disclosed to Oracle as part of our investigation.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.trendmicro.com/en_us/research/26/f/PeopleTools.html&quot;&gt;https://www.trendmicro.com/en_us/research/26/f/PeopleTools.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Anthropics KI Mythos: Unternehmen haben weiter Zugriff auf Preview-Version&lt;/h3&gt;

Trotz US-Anordnung haben manche Unternehmen weiterhin Zugriff auf eine Preview-Version von Anthropics KI-Modell Mythos.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11338742&quot;&gt;https://heise.de/-11338742&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;I discovered a large-scale malware distribution on GitHub&lt;/h3&gt;

This is the story of how I found 10,000 repositories on GitHub that distribute Trojan malware. They are all from different contributors, have different names, and are not forks of other repositories. But they share a common pattern, which is what allowed me to write a script to find such repositories.
&lt;p /&gt;
&lt;A HREF=&quot;https://orchidfiles.com/github-repositories-distributing-malware/&quot;&gt;https://orchidfiles.com/github-repositories-distributing-malware/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Windows 10/11: Rechteausweitung in AMD-RAID-Treiber&lt;/h3&gt;

Im AMD RAID-Treiber für Windows 10 und Windows 11 ist ein gravierender Bug bekannt geworden, der die Sicherheit des Systems gefährdet. Die Schwachstelle CVE-2024-21962, hat einen CVSS-Score von 8.6. AMD und auch der Hersteller HP haben Sicherheitshinweise sowie eine neue Treiberversion veröffentlicht.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/06/19/windows-10-11-rechteausweitung-in-amd-raid-treiber/&quot;&gt;https://borncity.com/blog/2026/06/19/windows-10-11-rechteausweitung-in-amd-raid-treiber/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1078662/&quot;&gt;https://lwn.net/Articles/1078662/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-19T18:14:16Z</dc:date></entry><entry><title>Tageszusammenfassung - 18.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-18062026"/><author><name>CERT.at</name></author><updated>2026-06-18T18:05:31Z</updated><published>2026-06-18T18:05:31Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 17-06-2026 18:00 - Donnerstag 18-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Rogueplanet-Exploit: Microsoft verspricht ein &quot;High-Quality-Sicherheitsupdate&quot;&lt;/h3&gt;

Microsoft will mit einem Update die Ausnutzung des Rogueplanet-Exploits auf Windows-Geräten unterbinden. Wann das passiert, bleibt aber ein Rätsel.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/rogueplanet-exploit-microsoft-verspricht-ein-high-quality-sicherheitsupdate-2606-209904.html&quot;&gt;https://www.golem.de/news/rogueplanet-exploit-microsoft-verspricht-ein-high-quality-sicherheitsupdate-2606-209904.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Jetzt patchen: Nginx-Webserver durch kritische Lücken angreifbar&lt;/h3&gt;

Angreifer können aufgrund von Sicherheitslücken in drei Nginx-Modulen Webserver lahmlegen oder Schadcode einschleusen. Patches verhindern das.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/jetzt-patchen-nginx-webserver-durch-kritische-luecken-angreifbar-2606-209926.html&quot;&gt;https://www.golem.de/news/jetzt-patchen-nginx-webserver-durch-kritische-luecken-angreifbar-2606-209926.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline&lt;/h3&gt;

A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.Ordinary stuff, until one move near the end.Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victims machine, building a way back in that did not run through the C2 at all. When the Havoc server went ..
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html&quot;&gt;https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments&lt;/h3&gt;

An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research.The threat actor also has at their disposal a dedicated WordPress ..
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html&quot;&gt;https://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Operation Endgame: Ermittler säubern tausende Blogs von SocGholish&lt;/h3&gt;

Strafverfolger aus vier Ländern zerschlugen ein Botnet und Wordpress-Blogs, die Kriminelle als Verteilstationen für Schadsoftware mißbrauchten.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Operation-Endgame-Ermittler-saeubern-tausende-Blogs-von-SocGholish-11337399.html&quot;&gt;https://www.heise.de/news/Operation-Endgame-Ermittler-saeubern-tausende-Blogs-von-SocGholish-11337399.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Auslaufende Secure Boot-Zertifikate - was war, was ist, was kommt&lt;/h3&gt;

Zwei völlig unterschiedliche Technologien, eine sehr ähnliche Problematik - DNS und Secure Boot sind beides Technologien die (idealerweise) problemfrei im Hintergrund laufen .. bis sie dann plötzlich zum Thema werden. Genau das könnte im Laufe dieses Jahres bei Secure Boot der Fall sein - die kryptographischen Vertrauensanker, auf denen UEFI Secure Boot beruht, stammen größtenteils aus dem Jahr 2011. Und das Ende fünfzehnjährigen ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/blog/2026/6/auslaufende-secure-boot-zertifikate-was-ist-was-kommt&quot;&gt;https://www.cert.at/de/blog/2026/6/auslaufende-secure-boot-zertifikate-was-ist-was-kommt&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Aktueller Stand rund um &quot;FortiBleed&quot;&lt;/h3&gt;

Vergangenes Wochenende entdeckte ein Sicherheitsforscher im Rahmen seiner Arbeit eine ungewöhnlich strukturierte Sammlung gestohlener Daten, welche sich nach weiterer Analyse als kompromittierte Zugangsdaten für zehntausende Fortinet-Systeme weltweit herausstellten. Die Echtheit der Daten wurden in weiterer Folge sowohl durch unabhängige Sicherheitsexperten als auch das Sicherheitsunternehmen Hudson Rock bestätigt. Die rund 75.000 betroffenen Fortinet-Systeme ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/blog/2026/6/aktueller-stand-rund-um-fortibleed&quot;&gt;https://www.cert.at/de/blog/2026/6/aktueller-stand-rund-um-fortibleed&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;EU grants Ukraine access to cybersecurity reserve for major attacks&lt;/h3&gt;

As Kyiv takes steps toward formal accession to the EU, the bloc is integrating Ukraine with its pool of pre-approved cybersecurity incident response companies.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/ukraine-access-eu-cybersecurity-reserve&quot;&gt;https://therecord.media/ukraine-access-eu-cybersecurity-reserve&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Von Blaster bis BlueHammer: Wiederholt sich die Geschichte bei Microsoft?&lt;/h3&gt;

Seit einigen Wochen gibt es ja einen ziemlichen Disput zwischen einem Sicherheitsforscher mit dem Alias Nightmare Eclipse und dem Microsoft Security Response Center-Team (MSRC-Team). Es geht um die Art, wie Sicherheitslücken gemeldet, ..
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/06/18/von-blaster-bis-bluehammer-wiederholt-sich-die-geschichte-bei-microsoft/&quot;&gt;https://borncity.com/blog/2026/06/18/von-blaster-bis-bluehammer-wiederholt-sich-die-geschichte-bei-microsoft/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The Road to Post-Quantum Readiness Part 1 of 2: Understanding the Risk&lt;/h3&gt;

Post-Quantum Cryptography is no longer a future-only concern. Standards are final, major providers have already deployed hybrid protection, and the real risk now is data captured today and decrypted later. Part 1 explains the fundamentals, the threat, and why organizations can no longer afford to wait.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.nviso.eu/2026/06/18/the-road-to-post-quantum-readiness-part-1/&quot;&gt;https://blog.nviso.eu/2026/06/18/the-road-to-post-quantum-readiness-part-1/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign&lt;/h3&gt;

Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ais own platform, turning the trusted domain into a delivery mechanism for credential-stealing malware.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html&quot;&gt;https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;



&lt;h3&gt;Drupal core - Critical - PHP object injection - SA-CORE-2026-005&lt;/h3&gt;

Project: Drupal coreDate: 2026-June-05Security risk: Critical 18 - 25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: PHP object injectionAffected versions: =10.6.0 =11.2.0 =11.3.0 CVE IDs: CVE-2026-55803Description: SA-CORE-2019-003 added protection for fields that store serialized data to disallow direct writes via web ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-core-2026-005&quot;&gt;https://www.drupal.org/sa-core-2026-005&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050&lt;/h3&gt;

Project: Plotly.js GraphingDate: 2026-June-17Security risk: Critical 19 - 25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: PHP object injectionAffected versions: CVE IDs: ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-050&quot;&gt;https://www.drupal.org/sa-contrib-2026-050&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049&lt;/h3&gt;

Project: Flag attendance fieldDate: 2026-June-17Security risk: Critical 19 - 25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: PHP object injectionAffected versions: CVE IDs: CVE-2026-55809Description: The Flag attendance field module gives you the ability to add attendance by depending on Flag module.flag_attendance_field stores ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-049&quot;&gt;https://www.drupal.org/sa-contrib-2026-049&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048&lt;/h3&gt;

Project: Formatter FieldDate: 2026-June-17Security risk: Critical 19 - 25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: PHP object injectionAffected versions: CVE IDs: CVE-2026-12535Description: The Formatter Field module provides a mechanism for specifying a formatter and formatter settings to be used for displaying a ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-048&quot;&gt;https://www.drupal.org/sa-contrib-2026-048&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SVD-2026-0614: OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit&lt;/h3&gt;

In Splunk AI Toolkit versions below 5.7.4, a user who holds the -admin- Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance.The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0614&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0614&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Webex App Open Redirect Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-redirect-KOyxhffH&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-redirect-KOyxhffH&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-umbrella-priv-esc-F4wJB7AU&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-umbrella-priv-esc-F4wJB7AU&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies Worksnaps&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec-consult.com/vulnerability-lab/advisory/hardcoded-root-cloud-credentials-in-application-binaries-in-silver-leaf-technologies-worksnaps/&quot;&gt;https://sec-consult.com/vulnerability-lab/advisory/hardcoded-root-cloud-credentials-in-application-binaries-in-silver-leaf-technologies-worksnaps/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-18T18:05:31Z</dc:date></entry><entry><title>Tageszusammenfassung - 17.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-17062026"/><author><name>CERT.at</name></author><updated>2026-06-17T18:05:14Z</updated><published>2026-06-17T18:05:14Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 16-06-2026 18:00 - Mittwoch 17-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Kodak confirms data breach claimed by ShinyHunters extortion gang&lt;/h3&gt;

Kodak has confirmed that its working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the companys data.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/&quot;&gt;https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Historischer Anstieg: KI lässt Anzahl gemeldeter Sicherheitslücken explodieren&lt;/h3&gt;

Neuen Hochrechnungen zufolge könnten 2026 etwa 66.000 neue Sicherheitslücken registriert werden. Im Vorjahr waren es noch deutlich weniger.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/historischer-anstieg-ki-laesst-anzahl-gemeldeter-sicherheitsluecken-explodieren-2606-209853.html&quot;&gt;https://www.golem.de/news/historischer-anstieg-ki-laesst-anzahl-gemeldeter-sicherheitsluecken-explodieren-2606-209853.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fußball-WM: Offizielles Streamingportal der Fifa gehackt&lt;/h3&gt;

Eine Forscherin hat eine unzureichende Sicherheitsprüfung bei Systemen der Fifa entdeckt. Angreifer hätten Streams der laufenden WM sabotieren können.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/fussball-wm-offizielles-streamingportal-der-fifa-gehackt-2606-209873.html&quot;&gt;https://www.golem.de/news/fussball-wm-offizielles-streamingportal-der-fifa-gehackt-2606-209873.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;France To Stop Certifying Products Without Quantum-Safe Encryption&lt;/h3&gt;

Starting in 2027, Frances cybersecurity agency ANSSI will stop certifying security products that lack quantum-resistant encryption, effectively forcing government agencies and critical infrastructure operators to phase out older cryptographic systems. Reuters reports: Samih Souissi, ANSSIs chief of staff, said at the France Quantum conference that ..
&lt;p /&gt;
&lt;A HREF=&quot;https://it.slashdot.org/story/26/06/16/181236/france-to-stop-certifying-products-without-quantum-safe-encryption&quot;&gt;https://it.slashdot.org/story/26/06/16/181236/france-to-stop-certifying-products-without-quantum-safe-encryption&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WordPress PBN Plugin Drops Dual Webshells via Database Injection&lt;/h3&gt;

During a recent incident response engagement, our team uncovered a multi-stage WordPress infection that goes beyond the usual file-based malware. The attacker combined a fake plugin, a remote command-and-control server, and two PHP web shells stored directly inside the WordPress database.The campaign is operated by a Turkish-speaking threat actor ..
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.sucuri.net/2026/06/wordpress-pbn-plugin-drops-dual-webshells-via-database-injection.html&quot;&gt;https://blog.sucuri.net/2026/06/wordpress-pbn-plugin-drops-dual-webshells-via-database-injection.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution&lt;/h3&gt;

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html&quot;&gt;https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Three critical Fortinet sandbox bugs splattered by unknown attackers&lt;/h3&gt;

All have patches, so make sure you upgrade to a fixed version
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461&quot;&gt;https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;-Dangerous- AI Models Are Coming No Matter What&lt;/h3&gt;

The US government crackdown on Anthropic-s Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will soon be the norm.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wired.com/story/dangerous-ai-models-are-coming-no-matter-what/&quot;&gt;https://www.wired.com/story/dangerous-ai-models-are-coming-no-matter-what/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mehrere Plug-ins für JetBrains-IDEs stehlen API-Keys für OpenAI, DeepSeek &amp; Co.&lt;/h3&gt;

Mindestens 15 Plug-ins für JetBrains-IDEs übermitteln API-Keys an einen externen Server. Dabei bieten sie ansonsten die versprochenen Funktionen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Mehrere-Plug-ins-fuer-JetBrains-IDEs-stehlen-API-Keys-fuer-OpenAI-DeepSeek-Co-11335021.html&quot;&gt;https://www.heise.de/news/Mehrere-Plug-ins-fuer-JetBrains-IDEs-stehlen-API-Keys-fuer-OpenAI-DeepSeek-Co-11335021.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Android 17 hat direkt Sicherheitspatches mit an Bord&lt;/h3&gt;

Googles Entwickler haben in der Launchversion von Android 17 diverse Sicherheitslücken geschlossen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Android-17-hat-direkt-Sicherheitspatches-mit-an-Bord-11335345.html&quot;&gt;https://www.heise.de/news/Android-17-hat-direkt-Sicherheitspatches-mit-an-Bord-11335345.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Angriffe auf FortiSandbox-Schwachstellen&lt;/h3&gt;

Schwachstellen in FortiSandbox sind derzeit Ziel von Angriffen im Internet. Patches zum Absichern stehen seit April bereit.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Angriffe-auf-FortiSandbox-Schwachstellen-11335667.html&quot;&gt;https://www.heise.de/news/Angriffe-auf-FortiSandbox-Schwachstellen-11335667.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NIS2-Mahnung: BSI setzt neue Frist zur Registrierung bis Ende Juli&lt;/h3&gt;

Die Registrierungszahlen zum IT-Sicherheitsgesetz enttäuschen. Das BSI mahnt Firmen, NIS2-Vorgaben einzuhalten, und gibt eine neue Deadline vor.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/NIS2-Mahnung-BSI-setzt-neue-Frist-zur-Registrierung-bis-Ende-Juli-11336134.html&quot;&gt;https://www.heise.de/news/NIS2-Mahnung-BSI-setzt-neue-Frist-zur-Registrierung-bis-Ende-Juli-11336134.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say&lt;/h3&gt;

GitHub rejected two formal vulnerability reports identifying design flaws that researchers say are enabling variants of the Shai-Hulud supply-chain worm to infect and compromise hundreds of software packages and developer accounts worldwide.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/github-dismissed-reports-shai-hulud-deep-specter&quot;&gt;https://therecord.media/github-dismissed-reports-shai-hulud-deep-specter&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Reducing Microsoft Sentinel Costs Without Compromising Detection - Part 1: The Summary Rules Quest&lt;/h3&gt;

This blog is the first in a series exploring how Summary Rules, together with Auxiliary or Data Lake storage, can help organizations optimize SIEM costs without compromising core threat detection and monitoring capabilities.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.nviso.eu/2026/06/17/reducing-microsoft-sentinel-costs-without-compromising-detection-part-1-the-summary-rules-quest/&quot;&gt;https://blog.nviso.eu/2026/06/17/reducing-microsoft-sentinel-costs-without-compromising-detection-part-1-the-summary-rules-quest/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FortiBleed - 75k Fortinet firewalls have admin passwords cracked&lt;/h3&gt;

An interesting post popped up on LinkedIn at the weekend from Voldymyr Diachenko saying plain text passwords were found in the wild by Hunt Intelligence Inc for Fortinet firewalls ..
&lt;p /&gt;
&lt;A HREF=&quot;https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8&quot;&gt;https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Threat tactic spotlight: Subdomain takeover&lt;/h3&gt;

In this blog post you-ll learn how to detect and prevent subdomain takeover - a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. We-ll explain the issue, how the situation arises, and how you can use various AWS features and services to help mitigate the impact of this tactic.
&lt;p /&gt;
&lt;A HREF=&quot;https://aws.amazon.com/blogs/security/threat-tactic-spotlight-subdomain-takeover/&quot;&gt;https://aws.amazon.com/blogs/security/threat-tactic-spotlight-subdomain-takeover/&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;



&lt;h3&gt;Critical Security Patch Update Advisory - June 2026&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.oracle.com/security-alerts/cspujun2026.html&quot;&gt;https://www.oracle.com/security-alerts/cspujun2026.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Multiple Vulnerabilities in Quanos Content Solutions SCHEMA ST4&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-quanos-content-solutions-schema-st4/&quot;&gt;https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-quanos-content-solutions-schema-st4/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;A 27-Year-Old Authentication Bypass in OpenBSDs PPP Stack&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html&quot;&gt;https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-17T18:05:14Z</dc:date></entry><entry><title>Tageszusammenfassung - 16.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-16062026"/><author><name>CERT.at</name></author><updated>2026-06-16T18:41:48Z</updated><published>2026-06-16T18:41:48Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 15-06-2026 18:00 - Dienstag 16-06-2026 18:00
Handler:     Guenes Holler
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;ÖIAT-Studie: Über 600.000 betrügerische und problematische Werbeanzeigen auf Facebook und Instagram&lt;/h3&gt;

Eine -Analyse des Betrugsökosystems Online-Werbung auf Meta-Plattformen- hat erstaunliche Ergebnisse geliefert. Über einen Zeitraum von drei Monaten entdeckte die Forschungsabteilung des ÖIAT über 600.000 betrügerische bzw. problematische Werbeanzeigen auf Meta-Plattformen. EU-weit wurden diese über 1 Milliarde Mal ausgespielt, davon 123 Millionen Mal allein in Österreich.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/betruegerische-problematische-werbeanzeigen-meta/&quot;&gt;https://www.watchlist-internet.at/news/betruegerische-problematische-werbeanzeigen-meta/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mit Malware erbeutet: 124 Millionen neue Passwörter bei HaveIBeenPwned&lt;/h3&gt;

Cyberkriminelle greifen mit Infostealer-Malware häufig Zugangsdaten ab. HaveIBeenPwned hat seine Datenbank um eine große Sammlung davon erweitert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/mit-malware-erbeutet-124-millionen-neue-passwoerter-bei-haveibeenpwned-2606-209825.html&quot;&gt;https://www.golem.de/news/mit-malware-erbeutet-124-millionen-neue-passwoerter-bei-haveibeenpwned-2606-209825.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Windows version of SprySOCKS Linux malware used to attack govt orgs&lt;/h3&gt;

Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/windows-version-of-sprysocks-linux-malware-used-to-attack-govt-orgs/&quot;&gt;https://www.bleepingcomputer.com/news/security/windows-version-of-sprysocks-linux-malware-used-to-attack-govt-orgs/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ransomware gang abuses Microsoft Teams relays to hide malicious traffic&lt;/h3&gt;

DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/&quot;&gt;https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels&lt;/h3&gt;

Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes to target nearly 100 organizations in finance, cryptocurrency, education, technology, and several other sectors. The activity has been codenamed UNK_DeadDrop.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/north-korean-hackers-are-turning.html&quot;&gt;https://thehackernews.com/2026/06/north-korean-hackers-are-turning.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;EvilTokens: Neue Phishing-Kampagne verschafft sich Zugriff mit legitimen Mitteln&lt;/h3&gt;

Was passiert, wenn bei einem Phishing-Angriff offizielle Infrastruktur genutzt wird, anstatt diese zu fälschen? EvilTokens markiert eine Weiterentwicklung des Phishing: Es werden nicht mehr Anmeldedaten gestohlen, sondern die Opfer dazu verleitet, legitime Sitzungen zu autorisieren.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.welivesecurity.com/de/cybercrime/eviltokens-neue-phishing-kampagne-verschafft-sich-zugriff-mit-legitimen-mitteln/&quot;&gt;https://www.welivesecurity.com/de/cybercrime/eviltokens-neue-phishing-kampagne-verschafft-sich-zugriff-mit-legitimen-mitteln/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE&lt;/h3&gt;

We discovered a vulnerability in the Google Cloud Vertex AI software development kit (SDK) for Python, and responsibly disclosed it to Google. Before Google-s fix, the vulnerability would have allowed an attacker operating entirely from their own Google Cloud project to hijack a victim's model upload and poison it. By exploiting this flaw in vulnerable versions of the SDK, an attacker can achieve remote code execution (RCE) within a target-s Vertex AI serving infrastructure, with zero initial access to the victim's project.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/&quot;&gt;https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Viel Geduld: Chinesische IT-Spione lauerten lange in Forschungseinrichtungen&lt;/h3&gt;

Viel Geduld haben chinesische Angreifer bewiesen: Sie nisteten sich in Redcap-Servern ein, nutzten das aber erst mehr als ein Jahr später voll aus.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11333355&quot;&gt;https://heise.de/-11333355&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions&lt;/h3&gt;

The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/glasswasm-malware-open-vsx-extensions?utm_medium=feed&quot;&gt;https://socket.dev/blog/glasswasm-malware-open-vsx-extensions?utm_medium=feed&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;A backdoor in a LinkedIn job offer&lt;/h3&gt;

Last week, I got a LinkedIn message from a recruiter at a small crypto startup. We exchanged a few messages over a couple of days, she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to -check out the deprecated Node modules issue.- It-s not uncommon to ask for a review of an existing codebase, but something felt off and raised an alarm in my head, so I decided to get a bit extra paranoid.
&lt;p /&gt;
&lt;A HREF=&quot;https://roman.pt/posts/linkedin-backdoor/&quot;&gt;https://roman.pt/posts/linkedin-backdoor/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Critical Fortinet FortiSandbox flaws now exploited in attacks&lt;/h3&gt;

Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089) on April 14.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/critical-fortinet-fortisandbox-flaws-now-exploited-in-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/critical-fortinet-fortisandbox-flaws-now-exploited-in-attacks/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Root-Attacken auf Cisco Catalyst SD-WAN Manager und cPanel-Plug-in LiteSpeed&lt;/h3&gt;

Admins, die Cisco Catalyst SD-WAN Manager oder cPanel mit LiteSpeed-Plug-in verwalten, sollten aufgrund von laufenden Angriffen umgehend die verfügbaren Sicherheitsupdates installieren. Im schlimmsten Fall können Angreifer als root-Nutzer auf Systeme zugreifen. Damit das klappt, müssen sie aber zuerst einige Hürden überwinden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Root-Attacken-auf-Cisco-Catalyst-SD-WAN-Manager-und-cPanel-Plug-in-LiteSpeed-11333457.html&quot;&gt;https://www.heise.de/news/Root-Attacken-auf-Cisco-Catalyst-SD-WAN-Manager-und-cPanel-Plug-in-LiteSpeed-11333457.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1078158/&quot;&gt;https://lwn.net/Articles/1078158/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Broken Access Control in syracom AG Secure Login (2FA) for Atlassian Jira / Confluence / Bitbucket&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-syracom-ag-secure-login-2fa-for-atlassian-jira-confluence-bitbucket/&quot;&gt;https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-syracom-ag-secure-login-2fa-for-atlassian-jira-confluence-bitbucket/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zyxel security advisory for stack-based buffer overflow vulnerability in GS1900 series switches&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026&quot;&gt;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-16T18:41:48Z</dc:date></entry><entry><title>Tageszusammenfassung - 15.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-15062026"/><author><name>CERT.at</name></author><updated>2026-06-15T18:42:27Z</updated><published>2026-06-15T18:42:27Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 12-06-2026 18:00 - Montag 15-06-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Alexander Riepl


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;New attack turned Microsoft 365 Copilot into 1-click data theft tool&lt;/h3&gt;

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a targets mailbox, OneDrive, or SharePoint account through a specially crafted URL.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites&lt;/h3&gt;

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites.When a site administrator was logged in as the file loaded, the code created an admin account under the attackers control and installed a hidden plugin that opened a way back in.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/popular-wordpress-plugin-scripts.html&quot;&gt;https://thehackernews.com/2026/06/popular-wordpress-plugin-scripts.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;-Sommer der Glückseligkeit-: curl nimmt einen Monat lang keine Bug-Reports an&lt;/h3&gt;

Seit Wochen kämpft der Maintainer von curl mit der Arbeitslast durch die Flut an KI-generierten Bug-Reports. Im Juli soll deshalb keiner angenommen werden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Sommer-der-Glueckseligkeit-curl-nimmt-einen-Monat-lang-keine-Bug-Reports-an-11332339.html&quot;&gt;https://www.heise.de/news/Sommer-der-Glueckseligkeit-curl-nimmt-einen-Monat-lang-keine-Bug-Reports-an-11332339.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WKO-Phishing: Betrugsmail fordert Datenaktualisierung&lt;/h3&gt;

Aktuell behauptet eine E-Mail im Namen der Wirtschaftskammer Österreich (WKO), dass Unternehmensdaten nicht aktualisiert wurden. Wer den enthaltenen Link nicht ausfüllt, dem werden umfassende Strafen angedroht. Tatsächlich haben es Kriminelle auf sensible Unternehmens- und Personendaten abgesehen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/wko-phishing-betrugsmail-fordert-datenaktualisierung/&quot;&gt;https://www.watchlist-internet.at/news/wko-phishing-betrugsmail-fordert-datenaktualisierung/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise&lt;/h3&gt;

Earlier this year, Truesec CSIRT responded to multiple incidents related to the two FortiCloud single-sign-on (SSO) vulnerabilities from December 2025 (tracked as CVE-2025-59718 and CVE-2025-59719).  In this blog post, we share our insights into threat actors- activities and methods for compromising an environment.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.truesec.com/hub/blog/vulnerability-cve-2025-59718-and-cve-2025-59719&quot;&gt;https://www.truesec.com/hub/blog/vulnerability-cve-2025-59718-and-cve-2025-59719&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Routerhersteller fordern Kontrolle importierter Geräte&lt;/h3&gt;

EU-Sicherheitsvorschriften für 5G-Mobilfunk sollen Spionage vorbeugen. Für Heimnetzwerke gibt es keine entsprechenden Regeln, kritisieren nun Hersteller.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11331799&quot;&gt;https://heise.de/-11331799&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic&lt;/h3&gt;

Sockets Threat Research Team identified a family of 152 Chrome Web Store new-tab &quot;live wallpaper&quot; extensions, built from one shared codebase but distributed across 38 separate Chrome Web Store publisher accounts and three brand backends, carrying a combined total of approximately 105,000 reported installs.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking&quot;&gt;https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Präparierte PDF-Datei kann Avira Antivirus gefährlich werden&lt;/h3&gt;

In einer Schwachstellendatenbank sind Lücken in Avira Antivirus aufgetaucht. Bislang listet der Softwarehersteller die Lücken nicht auf. Sie sind aber gepatcht.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Praeparierte-PDF-Datei-kann-Avira-Antivirus-gefaehrlich-werden-11332323.html&quot;&gt;https://www.heise.de/news/Praeparierte-PDF-Datei-kann-Avira-Antivirus-gefaehrlich-werden-11332323.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LibreNMS Authenticated RCE (&lt; 26.5.0)&lt;/h3&gt;

When theres one, theres normally more. This is a part 2 to our previous post on LibreNMS. This vulnerability allows an admin user to inject commands that are passed to the exec function, which will then be executed as the user running the poller.
&lt;p /&gt;
&lt;A HREF=&quot;https://projectblack.io/blog/librenms-authenticated-rce-26-5-0/&quot;&gt;https://projectblack.io/blog/librenms-authenticated-rce-26-5-0/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)&lt;/h3&gt;

On June 10th, Splunk published this CVE-2026-20253 advisory [..] It has everything that we love: No authentication requirements, An almost full-mark CVSS score, Claims to be a security product, Vulnerability name longer than the average piece of spaghetti.
&lt;p /&gt;
&lt;A HREF=&quot;https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/&quot;&gt;https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Splunk: SVD-2026-0603: Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise&lt;/h3&gt;

In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0603&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0603&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;phpBB: Kritische Sicherheitslücke ermöglicht Kompromittierung&lt;/h3&gt;

In der Forensoftware phpBB haben IT-Forscher eine kritische Sicherheitslücke entdeckt, die Zugang mit jedem angelegten Konto ermöglicht.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/phpBB-Kritische-Sicherheitsluecke-ermoeglicht-Kompromittierung-11332689.html&quot;&gt;https://www.heise.de/news/phpBB-Kritische-Sicherheitsluecke-ermoeglicht-Kompromittierung-11332689.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1077945/&quot;&gt;https://lwn.net/Articles/1077945/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zahlreiche kritische Schwachstellen in Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec-consult.com/de/vulnerability-lab/advisory/zahlreiche-kritische-schwachstellen-in-wertheim-safecontroller-software-for-vault-rooms-safe-deposit-locker-system/&quot;&gt;https://sec-consult.com/de/vulnerability-lab/advisory/zahlreiche-kritische-schwachstellen-in-wertheim-safecontroller-software-for-vault-rooms-safe-deposit-locker-system/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-15T18:42:27Z</dc:date></entry><entry><title>Tageszusammenfassung - 12.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-12062026"/><author><name>CERT.at</name></author><updated>2026-06-12T18:04:13Z</updated><published>2026-06-12T18:04:13Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 11-06-2026 18:00 - Freitag 12-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Pharma giant Novo Nordisk discloses breach of clinical trials data&lt;/h3&gt;

Danish pharmaceutical giant Novo Nordisk, the worlds largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/&quot;&gt;https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;336 Millionen Euro in Bitcoin gewaschen: Geldwäschedienst AudiA6 zerschlagen&lt;/h3&gt;

Ein AudiA6 genannter Geldwäschedienst ließ Hacker und Betrüger Bitcoin-Transaktionen in Millionenhöhe verschleiern. Doch damit ist jetzt Schluss.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/336-millionen-euro-in-bitcoin-gewaschen-geldwaeschedienst-audia6-zerschlagen-2606-209687.html&quot;&gt;https://www.golem.de/news/336-millionen-euro-in-bitcoin-gewaschen-geldwaeschedienst-audia6-zerschlagen-2606-209687.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Kernel-Bug: FreeBSD-Exploit &quot;Bumsrakete&quot; verleiht Root-Zugriff&lt;/h3&gt;

Ein Exploit namens Bumsrakete gefährdet alle FreeBSD-Versionen der letzten fünf Jahre. Die Entdecker nehmen es mit reichlich Humor.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/kernel-bug-freebsd-exploit-bumsrakete-verleiht-root-zugriff-2606-209694.html&quot;&gt;https://www.golem.de/news/kernel-bug-freebsd-exploit-bumsrakete-verleiht-root-zugriff-2606-209694.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution&lt;/h3&gt;

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution.LangGraph is an open-source framework created by LangChain to ..
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/langgraph-flaw-chain-exposes-self.html&quot;&gt;https://thehackernews.com/2026/06/langgraph-flaw-chain-exposes-self.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/h3&gt;

An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday.The effort, codenamed Operation Ramz, took place between October 2025 and February ..
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html&quot;&gt;https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drug Sites Hijacked Spotify-s Search Ranking Through Fake Podcasts&lt;/h3&gt;

A joint congressional report describes a spam operation that turned tens of thousands of fake podcasts into search-engine bait for illegal pharmacy and scam sites.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wired.com/story/drug-sites-hijacked-spotifys-search-ranking-through-fake-podcasts-report-finds/&quot;&gt;https://www.wired.com/story/drug-sites-hijacked-spotifys-search-ranking-through-fake-podcasts-report-finds/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ivanti Sentry: Verwirrung um Status von kritischem Befehlsschmuggel-Leck&lt;/h3&gt;

Ivanti warnt aktuell vor kritischen Sicherheitslücken in Sentry. Die CISA warnt vor Angriffen, Ivanti wiegelt jedoch ab.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Ivanti-Sentry-Wirrwar-um-Missbrauch-kritischer-Befehlsschmuggel-Luecke-11329730.html&quot;&gt;https://www.heise.de/news/Ivanti-Sentry-Wirrwar-um-Missbrauch-kritischer-Befehlsschmuggel-Luecke-11329730.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ubiquiti UniFi OS: Kritische Lücken erlauben Codeschmuggel&lt;/h3&gt;

Ubiquiti warnt vor teils kritischen Sicherheitslücken in UniFi OS. Aktualisierte Software steht bereit, um sie zu schließen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Ubiquiti-UniFi-OS-Kritische-Luecken-erlauben-Codeschmuggel-11329967.html&quot;&gt;https://www.heise.de/news/Ubiquiti-UniFi-OS-Kritische-Luecken-erlauben-Codeschmuggel-11329967.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake verification pages are stealing Steam accounts from players&lt;/h3&gt;

A convincing fake FACEIT verification page is stealing Steam accounts by using a fake login window that looks completely legitimate.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/threat-intel/2026/06/fake-verification-pages-are-stealing-steam-accounts-from-players&quot;&gt;https://www.malwarebytes.com/blog/threat-intel/2026/06/fake-verification-pages-are-stealing-steam-accounts-from-players&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hundreds of AUR packages compromised&lt;/h3&gt;

Hundreds of orphaned packages hosted by the Arch User Repository (AUR) have been compromised by an attacker who has added a malicious npm package (atomic-lockfile) that can exfiltrate sensitive data. The project is currently working on cleaning up the mess. There is a list of affected packages and post (possibly NSFW domain) by&quot;sodiboo&quot; with additional information ..
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1077718/&quot;&gt;https://lwn.net/Articles/1077718/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz&lt;/h3&gt;

Group-IB, INTERPOL and Algerian Police dismantle decade-old SniperDZ phishing network used to steal credentials, with its alleged developer arrested.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/authorities-dismantle-sniperdz-phishing-network/&quot;&gt;https://hackread.com/authorities-dismantle-sniperdz-phishing-network/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)&lt;/h3&gt;

It is yet another day in this parallel universe of security, where the devices we bolt onto the edge of our networks to keep the bad people out are, with remarkable consistency, the exact thing that let the bad ..
&lt;p /&gt;
&lt;A HREF=&quot;https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751/&quot;&gt;https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751/&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;



&lt;h3&gt;CVE-2026-45257: LPE in FreeBSD via kTLS-RX&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://bumsrake.de&quot;&gt;https://bumsrake.de&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-12T18:04:13Z</dc:date></entry><entry><title>Tageszusammenfassung - 11.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-11062026"/><author><name>CERT.at</name></author><updated>2026-06-11T18:14:50Z</updated><published>2026-06-11T18:14:50Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 10-06-2026 18:00 - Donnerstag 11-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks&lt;/h3&gt;

Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Neuer Bitlocker-Bypass: Chaotic Eclipse wirft weiter mit Windows-Exploits um sich&lt;/h3&gt;

Chaotic Eclipse ist wohl doch nicht so erschöpft wie behauptet. Ein neuer Exploit zur Umgehung von Bitlocker auf Windows-Geräten ist noch drin.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/neuer-bitlocker-bypass-chaotic-eclipse-wirft-weiter-mit-windows-exploits-um-sich-2606-209646.html&quot;&gt;https://www.golem.de/news/neuer-bitlocker-bypass-chaotic-eclipse-wirft-weiter-mit-windows-exploits-um-sich-2606-209646.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate&lt;/h3&gt;

PRC eyes are watching you
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/06/11/china-linked-operators-revive-botnet-stir-ai-datacenter-debate/5253873&quot;&gt;https://www.theregister.com/security/2026/06/11/china-linked-operators-revive-botnet-stir-ai-datacenter-debate/5253873&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Every employee-s password was stored in a single Excel file&lt;/h3&gt;

The CEO thought this was the best way to deal with some email issues
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/06/11/every-employees-password-was-stored-in-a-single-excel-file/5253784&quot;&gt;https://www.theregister.com/security/2026/06/11/every-employees-password-was-stored-in-a-single-excel-file/5253784&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats&lt;/h3&gt;

-Defenders cannot afford to take weeks to patch,- one Cybersecurity and Infrastructure Security Agency official warned on Wednesday.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wired.com/story/cisa-ai-vulnerability-directive/&quot;&gt;https://www.wired.com/story/cisa-ai-vulnerability-directive/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;OpenSSL: Präparierte Signatur kann Weg für Schadcode ebnen&lt;/h3&gt;

In aktuellen Versionen haben die OpenSSL-Entwickler insgesamt 18 Sicherheitslücken geschlossen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/OpenSSL-Praeparierte-Signatur-kann-Weg-fuer-Schadcode-ebnen-11328258.html&quot;&gt;https://www.heise.de/news/OpenSSL-Praeparierte-Signatur-kann-Weg-fuer-Schadcode-ebnen-11328258.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Intel-Aus: So lange will Apple Sicherheitspatches liefern&lt;/h3&gt;

Mit macOS 27 ist das x86-Zeitalter bei Apple vorbei. Immerhin soll es noch über einen längeren Zeitraum Patches geben. Wie vollständig die sind - unklar.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/macOS-Apple-teilt-mit-wie-lange-es-Intel-Sicherheitsupdates-geben-wird-11327980.html&quot;&gt;https://www.heise.de/news/macOS-Apple-teilt-mit-wie-lange-es-Intel-Sicherheitsupdates-geben-wird-11327980.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FreeBSD: Rechteausweitungslücke mit augenzwinkerndem Codenamen&lt;/h3&gt;

Auch in FreeBSD haben IT-Forscher eine Sicherheitslücke gefunden, die die Rechteausweitung ermöglicht. Name: -Bumsrakete[tm]-.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/FreeBSD-Rechteausweitungsluecke-mit-augenzwinkerndem-Codenamen-11328722.html&quot;&gt;https://www.heise.de/news/FreeBSD-Rechteausweitungsluecke-mit-augenzwinkerndem-Codenamen-11328722.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026&lt;/h3&gt;

This year-s Pwn2Own competition in Berlin revealed just how much of the AI stack remains exposed -- and the gap between what these tools promise and what they can withstand point to the fragile security foundations underneath.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.trendmicro.com/en_us/research/26/f/pwn2own-genai.html&quot;&gt;https://www.trendmicro.com/en_us/research/26/f/pwn2own-genai.html&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;



&lt;h3&gt;SVD-2026-0609: Improper Access Control in Splunk Enterprise&lt;/h3&gt;

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability edit_saved_search_owner could reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks access control.
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0609&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0609&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SVD-2026-0606: Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise&lt;/h3&gt;

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the -admin- or -power- Splunk roles could cause data exfiltration through classic dashboards by redirecting a victim to an external site using a protocol-relative URL in a drill-down link.The vulnerability exists because the URL classifier in classic dashboards
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0606&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0606&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SVD-2026-0605: Improper Input Validation through Classic Dashboards in Splunk Enterprise&lt;/h3&gt;

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the -admin- or -power- Splunk roles could craft a malicious classic dashboard that exfiltrates sensitive data to an external server.The vulnerability exists because URL validation on the external content dialog is incomplete, which can allow for requests to
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0605&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0605&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SVD-2026-0601: Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway&lt;/h3&gt;

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the -admin- or -power- Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.The Remote Code Execution is possible because of unsafe deserialization of App
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0601&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0601&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Oracle Security Alert Advisory - CVE-2026-35273&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.oracle.com/security-alerts/alert-cve-2026-35273.html&quot;&gt;https://www.oracle.com/security-alerts/alert-cve-2026-35273.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-047&quot;&gt;https://www.drupal.org/sa-contrib-2026-047&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Composer - Critical - Unsupported - SA-CONTRIB-2026-046&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-046&quot;&gt;https://www.drupal.org/sa-contrib-2026-046&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-11T18:14:50Z</dc:date></entry><entry><title>Tageszusammenfassung - 10.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-10062026"/><author><name>CERT.at</name></author><updated>2026-06-10T18:27:47Z</updated><published>2026-06-10T18:27:47Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 09-06-2026 18:00 - Mittwoch 10-06-2026 18:00
Handler:     Alexander Riepl
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;OpenClaw AI agent found falling for phishing attacks, spills user data&lt;/h3&gt;

Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/openclaw-ai-agent-found-falling-for-phishing-attacks-spills-user-data/&quot;&gt;https://www.bleepingcomputer.com/news/security/openclaw-ai-agent-found-falling-for-phishing-attacks-spills-user-data/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Wurm-Attacken möglich: Kernel-Lücke lässt Angreifer Windows-Systeme kapern&lt;/h3&gt;

Microsofts Juni-Updates schließen über 500 Sicherheitslücken. Eine davon ermöglicht automatisierte Schadcode-Attacken auf Windows-Systeme.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/wurm-attacken-moeglich-kernel-luecke-laesst-angreifer-windows-systeme-kapern-2606-209595.html&quot;&gt;https://www.golem.de/news/wurm-attacken-moeglich-kernel-luecke-laesst-angreifer-windows-systeme-kapern-2606-209595.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Servicenow: Großer Cloudanbieter informiert Kunden über Datenpanne&lt;/h3&gt;

Bei Servicenow konnten Angreifer ohne Authentifizierung über ein API Kundendaten ausleiten. Mindestens ein Cyberakteur hat das ausgenutzt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/servicenow-grosser-cloudanbieter-informiert-kunden-ueber-datenpanne-2606-209617.html&quot;&gt;https://www.golem.de/news/servicenow-grosser-cloudanbieter-informiert-kunden-ueber-datenpanne-2606-209617.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9&lt;/h3&gt;

Remote, unauthenticated RCE with root privileges is about as bad as it gets
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/patches/2026/06/10/ivanti-urges-sentry-users-to-patch-two-critical-bugs/5253428&quot;&gt;https://www.theregister.com/patches/2026/06/10/ivanti-urges-sentry-users-to-patch-two-critical-bugs/5253428&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GitHub pulls pin on npms auto-run scripts&lt;/h3&gt;

Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/devops/2026/06/10/github-pulls-pin-on-npms-auto-run-scripts/5253453&quot;&gt;https://www.theregister.com/devops/2026/06/10/github-pulls-pin-on-npms-auto-run-scripts/5253453&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Wait, binding.gyp Can Do What? Exploring npms Weirdest Build System&lt;/h3&gt;

It has only been a couple of days since the Miasma attack hit 32 official Red Hat packages on npm. The worm added a malicious preinstall script to each compromised package, so that node index.js ran automatically the moment you installed the dependency, harvesting cloud credentials, CI tokens, SSH keys and more before you ever ran a single line of your ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system&quot;&gt;https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Bundesregierung will KI-Sicherheitsinstitut gründen&lt;/h3&gt;

Mit einer neuen Einrichtung will die Bundesregierung ihre Analysefähigkeiten bei KI-Modellen stärken. Minister Wildberger verspricht -Experten auf Weltniveau-.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Bundesregierung-will-KI-Sicherheitsinstitut-gruenden-11326247.html&quot;&gt;https://www.heise.de/news/Bundesregierung-will-KI-Sicherheitsinstitut-gruenden-11326247.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Datenleck: Cyberangriff auf französischen Regierungs-Messenger Tchap&lt;/h3&gt;

Frankreichs Digitalstelle DINUM räumt ein Datenleck beim Regierungs-Messenger Tchap ein. Angreifer konnten ein Konto kompromittieren.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Datenleck-Cyberangriff-auf-franzoesischen-Regierungs-Messenger-Tchap-11326766.html&quot;&gt;https://www.heise.de/news/Datenleck-Cyberangriff-auf-franzoesischen-Regierungs-Messenger-Tchap-11326766.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fortinet schließt Befehlsschmuggel-Lücke in FortiSandbox und mehr&lt;/h3&gt;

Fortinet warnt vor einer kritischen Sicherheitslücke in FortiSandbox und weiteren Lecks in FortiPortal und FortiOS/FortiProxy.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Fortinet-schliesst-Befehlsschmuggel-Luecke-in-FortiSandbox-und-mehr-11326887.html&quot;&gt;https://www.heise.de/news/Fortinet-schliesst-Befehlsschmuggel-Luecke-in-FortiSandbox-und-mehr-11326887.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Phishing: Banken nutzen halbseidene Domains&lt;/h3&gt;

Namhafte Banken wie die Sparkassen warnen zwar vor Phishing, nutzen aber selbst Phishing-artige Domains. Es ginge sicher besser.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Phishing-Banken-nutzen-halbseidene-Domains-11327434.html&quot;&gt;https://www.heise.de/news/Phishing-Banken-nutzen-halbseidene-Domains-11327434.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;E-Mail-Fälschung bei Exchange Online: Ghost-Sender betrifft viele Unternehmen&lt;/h3&gt;

Nicht alle Unternehmenskunden von Microsofts Maildienst sind betroffen. Ein Prüfdienst schafft Klarheit und zeigt die möglichen Auswirkungen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Ghost-Sender-Exchange-Online-laesst-gefaelschte-E-Mails-anstandslos-durch-11327666.html&quot;&gt;https://www.heise.de/news/Ghost-Sender-Exchange-Online-laesst-gefaelschte-E-Mails-anstandslos-durch-11327666.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Who Runs the Ransomware Group -The Gentlemen?-&lt;/h3&gt;

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
&lt;p /&gt;
&lt;A HREF=&quot;https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/&quot;&gt;https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FinanzOnline-Phishing: &quot;Neuer Bescheid&quot; in der DataBox als Lockmittel&lt;/h3&gt;

Aktuell rollt wieder einmal eine Phishing-Welle im Namen von FinanzOnline. Darin dreht sich alles um einen vermeintlichen Bescheid, der in der DataBox von FinanzOnline wartet und eine Gutschrift verspricht. Dieser existiert natürlich nicht. Konkret abgesehen haben es die Kriminellen auf Logindaten ihrer Opfer.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/finanzonline-phishing-bescheid-datenbox/&quot;&gt;https://www.watchlist-internet.at/news/finanzonline-phishing-bescheid-datenbox/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Patch Tuesday Juni 2026 &amp; &quot;RoguePlanet&quot;&lt;/h3&gt;

Im Rahmen des diesmonatigen Patchdays hat Microsoft Sicherheitsupdates für rund 200 Schwachstellen veröffentlicht. Damit übertrifft dieser Patchday den bisherigen Rekord von 167 Lücken aus dem Oktober 2025 deutlich. Über 30 der behobenen Sicherheitslücken sind als &quot;Critical&quot; eingestuft. Besonders im Blick behalten sollten Administrator:innen drei Probleme, die bereits vor Verfügbarkeit eines Patches öffentlich bekannt waren. Alle drei werden von ..
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/aktuelles/2026/6/microsoft-patch-tuesday-juni-2026&quot;&gt;https://www.cert.at/de/aktuelles/2026/6/microsoft-patch-tuesday-juni-2026&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;More Evidence That Words Dont Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)&lt;/h3&gt;

Today, Ivanti published an advisory.-No way?- we hear you say. &quot;Yes way!&quot; a random dog screams back at you, across the street.Today-s rare advisory outlines two vulnerabilities in Ivanti-s Sentry product, appealing directly to our inner desire for sophisticated ..
&lt;p /&gt;
&lt;A HREF=&quot;https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/&quot;&gt;https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-10T18:27:47Z</dc:date></entry><entry><title>Tageszusammenfassung - 09.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-09062026"/><author><name>CERT.at</name></author><updated>2026-06-09T19:06:56Z</updated><published>2026-06-09T19:06:56Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 08-06-2026 18:00 - Dienstag 09-06-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;High-severity vulnerability in Linux caused by a single errant character&lt;/h3&gt;

The presence of a single mis-issued exclamation point in code implementing nf_tables introduced a use-after-free, a class of vulnerability that corrupts memory by placing malicious code at memory addresses that haven-t been properly freed of their previous contents. [..] The vulnerability was fixed in the kernel in February. Security firm FuzzingLabs demonstrated a proof of concept exploit in April. Exodus Intelligence, which discovered the bug, included its own PoC exploit in Monday-s post. It worked on Debian and Ubuntu.
&lt;p /&gt;
&lt;A HREF=&quot;https://arstechnica.com/security/2026/06/a-single-errant-character-in-the-linux-kernel-allows-attacker-to-gain-root/&quot;&gt;https://arstechnica.com/security/2026/06/a-single-errant-character-in-the-linux-kernel-allows-attacker-to-gain-root/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WhatsApp says it disrupted new NSO spyware phishing attacks&lt;/h3&gt;

WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. [..] The firm has been on the U.S. sanctioned entities list since November 2021, due to supplying to foreign governments software products that were used against people and organizations in the U.S.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/whatsapp-says-it-disrupted-new-nso-spyware-phishing-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/whatsapp-says-it-disrupted-new-nso-spyware-phishing-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;-Bestätigen Sie Ihre Reservierung!- - Betrugsklassiker im Namen von booking.com&lt;/h3&gt;

Nachdem Kriminelle im April 2026 Kontakt- und Reservierungsdaten von booking.com erbeutet hatten, setzt nun die dazugehörige Betrugswelle ein. Über WhatsApp sollen die Opfer zur -erneuten Bestätigung einer Reservierung- gedrängt werden. Reale Buchungsinfos wie Hotelname und An- bzw. Abreisedatum lassen die Nachricht vermeintlich seriös wirken. Abgesehen haben es die Betrüger:innen auf Geld und Zahlungsinformationen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/reservierung-betrugsklassiker-bookingcom/&quot;&gt;https://www.watchlist-internet.at/news/reservierung-betrugsklassiker-bookingcom/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;When -Hi, This Is IT- Comes Through Microsoft Teams&lt;/h3&gt;

Attackers are increasingly targeting collaboration platforms like Microsoft Teams. [..] If external chat is open, attackers will use it.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/microsoft-teams-phishing/&quot;&gt;https://unit42.paloaltonetworks.com/microsoft-teams-phishing/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft benachrichtigt einige Kunden über Downloads infizierter GitHub-Pakete&lt;/h3&gt;

Zum Wochenende hatte ich über eine Infektion von GitHub-Repositories mit Microsoft Tools berichtet. Diese waren mit einem Infostealer für AI-Tokens infiziert. Nun bestätigt, dass man eine kleine Anzahl Kunden benachrichtigt habe, die die kompromittierten Repositories mit den Tools heruntergeladen haben.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/06/09/microsoft-benachrichtigt-einige-kunden-ueber-downloads-infizierter-github-pakete/&quot;&gt;https://borncity.com/blog/2026/06/09/microsoft-benachrichtigt-einige-kunden-ueber-downloads-infizierter-github-pakete/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hidden in Plain Sight: PowerShell Visibility Most Defender XDR Analysts Miss&lt;/h3&gt;

Discover how an often-overlooked telemetry source in Microsoft Defender XDR can reveal PowerShell script activity that traditional process hunting misses.
&lt;p /&gt;
&lt;A HREF=&quot;https://detect.fyi/hidden-in-plain-sight-powershell-visibility-most-defender-xdr-analysts-miss-83944ddc56df?source=rssd5fd8f494f6a4&quot;&gt;https://detect.fyi/hidden-in-plain-sight-powershell-visibility-most-defender-xdr-analysts-miss-83944ddc56df?source=rssd5fd8f494f6a4&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels&lt;/h3&gt;

Socket Threat Research team identified a newer PyPI wave connected to the broader Mini Shai-Hulud, Miasma, and Hades supply chain attacks. This wave expands beyond the 37 malicious PyPI wheels covered in our weekend report and shows that the threat actors are iterating quickly across delivery mechanisms, package themes, and runtime triggers.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious?utm_medium=feed&quot;&gt;https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious?utm_medium=feed&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Ivanti: Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)&lt;/h3&gt;

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access ...
&lt;p /&gt;
&lt;A HREF=&quot;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US&quot;&gt;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ivanti: Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-6973 &amp; CVE-2026-10727)&lt;/h3&gt;

A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to inject arbitrary Apache directives, leading to remote code execution. ...
&lt;p /&gt;
&lt;A HREF=&quot;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-6973-CVE-2026-10727?language=en_US&quot;&gt;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-6973-CVE-2026-10727?language=en_US&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;TYPO3 Security Advisories 09.06.2026&lt;/h3&gt;

TYPO3 has published 14 new security advisories.
&lt;p /&gt;
&lt;A HREF=&quot;https://typo3.org/security&quot;&gt;https://typo3.org/security&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;XEN Security Advisories 09.06.2026&lt;/h3&gt;

Xenbits has published 4 new security advisories.
&lt;p /&gt;
&lt;A HREF=&quot;https://xenbits.xen.org/xsa/&quot;&gt;https://xenbits.xen.org/xsa/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SAP-Patchday: Kritische Lücken in SAP NetWeaver und weitere Schwachstellen&lt;/h3&gt;

Zum Juni-Patchday kümmert sich SAP um 15 neue Schwachstellen in mehreren Produkten. Gleich drei kritische betreffen NetWeaver.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/SAP-Patchday-Kritische-Luecken-in-SAP-NetWeaver-und-weitere-Schwachstellen-11323078.html&quot;&gt;https://www.heise.de/news/SAP-Patchday-Kritische-Luecken-in-SAP-NetWeaver-und-weitere-Schwachstellen-11323078.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Vulnerability Resolved in Veeam Backup &amp; Replication 12.3.2.4854&lt;/h3&gt;

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. CVE-2026-44963
&lt;p /&gt;
&lt;A HREF=&quot;https://www.veeam.com/kb4869&quot;&gt;https://www.veeam.com/kb4869&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1077163/&quot;&gt;https://lwn.net/Articles/1077163/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Waves Central: Zahlreiche Local Privilege Escalation Schwachstellen in Waves Audio Waves Central&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec-consult.com/de/vulnerability-lab/advisory/zahlreiche-local-privilege-escalation-schwachstellen-in-waves-audio-waves-central/&quot;&gt;https://sec-consult.com/de/vulnerability-lab/advisory/zahlreiche-local-privilege-escalation-schwachstellen-in-waves-audio-waves-central/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Google: Jetzt updaten! Chrome-Update stopft attackierte Lücke und 73 weitere&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11322503&quot;&gt;https://heise.de/-11322503&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-09T19:06:56Z</dc:date></entry><entry><title>Tageszusammenfassung - 08.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-08062026"/><author><name>CERT.at</name></author><updated>2026-06-08T18:35:10Z</updated><published>2026-06-08T18:35:10Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 05-06-2026 18:00 - Montag 08-06-2026 18:00
Handler:     Guenes Holler
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;C0XMO botnet spreads via DD-WRT router flaw, kills rival malware&lt;/h3&gt;

A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/&quot;&gt;https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Over 20,000 Instagram accounts stolen in Meta AI support hack&lt;/h3&gt;

Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/&quot;&gt;https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Angst vor Russland: Hacker entschuldigen sich bei attackierter Firma&lt;/h3&gt;

Ein Cyberakteur entpuppt sich als &quot;Ransomware-Trottel des Tages&quot;. Er hat ein Ziel attackiert, das ihm wirklich Probleme bereiten kann.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/angst-vor-russland-hacker-entschuldigen-sich-bei-attackierter-firma-2606-209426.html&quot;&gt;https://www.golem.de/news/angst-vor-russland-hacker-entschuldigen-sich-bei-attackierter-firma-2606-209426.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances&lt;/h3&gt;

A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html&quot;&gt;https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Google warnt: Angreifer geben sich als IT-Techniker aus und betreten Büros&lt;/h3&gt;

Die Google Threat Intelligence Group warnt vor der Gruppe UNC3753. Die Angreifer geben sich vor Ort als IT-Techniker aus, um Daten per USB-Stick zu stehlen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Google-warnt-Angreifer-geben-sich-als-IT-Techniker-aus-und-betreten-Bueros-11320590.html&quot;&gt;https://www.heise.de/news/Google-warnt-Angreifer-geben-sich-als-IT-Techniker-aus-und-betreten-Bueros-11320590.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Passwortmanager Dashlane: Angreifer kopieren fast 20 Passwort-Vaults&lt;/h3&gt;

Dashlane informiert darüber, dass Angreifer nach massiven Brute-Force-Attacken rund 20 Passwort-Vaults kopiert haben. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Passwortmanager-Dashlane-Angreifer-kopieren-fast-20-Passwort-Vaults-11321244.html&quot;&gt;https://www.heise.de/news/Passwortmanager-Dashlane-Angreifer-kopieren-fast-20-Passwort-Vaults-11321244.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Schweizer Rüstungsunternehmen RUAG zahlt Lösegeld an Cybergang&lt;/h3&gt;

Nachdem die Cybergang Akira bei der RUAG-Tochter Mecanex USA Daten abgezogen hat, hat RUAG ein Lösegeld gezahlt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Schweizer-Ruestungsunternehmen-RUAG-zahlt-Loesegeld-an-Cybergang-11321552.html&quot;&gt;https://www.heise.de/news/Schweizer-Ruestungsunternehmen-RUAG-zahlt-Loesegeld-an-Cybergang-11321552.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Recovery Scam: Fake-Agenturen schädigen Opfer erneut&lt;/h3&gt;

Sie versprechen Hilfe bei der Wiederbeschaffung von Vermögen, das durch eine Betrugsmasche gestohlen wurde. Die Website zur angeblichen Agentur sieht ansprechend aus, nutzt reale Impressumsdaten und übersteht damit erste Überprüfungen. Tatsächlich stecken hinter diesem Angebot Kriminelle, die frühere Opfer erneut bestehlen wollen. So funktioniert der Betrug nach dem Betrug.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/fake-agenturen-schaedigen-opfer/&quot;&gt;https://www.watchlist-internet.at/news/fake-agenturen-schaedigen-opfer/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5&lt;/h3&gt;

If you've ever received an out-of-the-blue message via LinkedIn from a recruiter offering some well-paid consultancy work, intelligence agencies have a message for you: be very careful.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bitdefender.com/en-us/blog/hotforsecurity/linkedin-recruiter-chinese-intelligence-fbi-mi5&quot;&gt;https://www.bitdefender.com/en-us/blog/hotforsecurity/linkedin-recruiter-chinese-intelligence-fbi-mi5&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Israelische Firma Bright Data missbraucht mit Backdoor in Apps Millionen Smart-TV&lt;/h3&gt;

Eine israelische Firma ist dabei aufgeflogen, dass sie Millionen Smart TV-Geräte in Zombi-Proxys verwandelt hat, um AI-Web-Scraping durchzuführen. Dazu wurden entsprechende Backdoors in Apps für Smart TV-Geräte eingebaut. Einige Anbieter wie Roku, Fire TV und Google TV haben diese Praxis untersagt. Aber Samsung- und LG-Smart TV-Geräte fungieren heimlich als Ausgangsknoten für KI-basiertes Web-Scraping, wie eine Untersuchung gezeigt hat.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/06/06/israelische-firma-bright-data-missbraucht-mit-backdoor-in-apps-millionen-smart-tv/&quot;&gt;https://borncity.com/blog/2026/06/06/israelische-firma-bright-data-missbraucht-mit-backdoor-in-apps-millionen-smart-tv/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams&lt;/h3&gt;

Cybersecurity researchers are warning businesses about Pink Extortion Group, a threat actor that uses voice phishing to bypass multi-factor authentication and steal files from cloud environments. 
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/&quot;&gt;https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Did Claude Increase Bugs in rsync?&lt;/h3&gt;

A simple distributional analysis of every rsync release with bug data. Nothing complicated, answers only one question: are the Claude-assisted releases unusually buggy?
&lt;p /&gt;
&lt;A HREF=&quot;https://alexispurslane.github.io/rsync-analysis/&quot;&gt;https://alexispurslane.github.io/rsync-analysis/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;How a USB-connected speaker can infect a PC without ever being touched&lt;/h3&gt;

Operating system makers take many steps to prevent their wares from accepting commands from remote devices. The safeguards, designed to thwart malicious attacks, typically require hackers to jump through all kinds of hoops to bypass the measures. But what if remote code execution were as simple as being within Bluetooth range of a speaker connected to the targeted device?
&lt;p /&gt;
&lt;A HREF=&quot;https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/&quot;&gt;https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Angriffe gegen Checkpoint VPN Lösungen - Hotfix verfügbar&lt;/h3&gt;

Checkpoint warnt vor beobachteten Angriffen gegen die Produkte Checkpoint Security Gateway und Checkpoint Spark Firewall.  Auswirkungen Die zugrunde liegende Sicherheitslücke CVE-2026-50751 erlaubt unbefugten Zugriff auf das VPN.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/warnungen/2026/6/angriffe-gegen-checkpoint-vpn-losungen-hotfix-verfugbar&quot;&gt;https://www.cert.at/de/warnungen/2026/6/angriffe-gegen-checkpoint-vpn-losungen-hotfix-verfugbar&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Critical UniFi OS bug lets hackers gain root without authentication&lt;/h3&gt;

Attackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication. The security issues are tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. They have been addressed in May and impact UniFi OS Server versions 5.0.6 and earlier.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/critical-unifi-os-bug-lets-hackers-gain-root-without-authentication/&quot;&gt;https://www.bleepingcomputer.com/news/security/critical-unifi-os-bug-lets-hackers-gain-root-without-authentication/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SolarWinds Serv-U: Angreifer missbrauchen DoS-Lücke in FTP-Server&lt;/h3&gt;

In SolarWinds-Serv-U-Servern können Angreifer eine Schwachstelle für Denial-of-Service-Angriffe missbrauchen. Laut CISA tun sie das bereits. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/SolarWinds-Serv-U-Angreifer-missbrauchen-DoS-Luecke-in-FTP-Server-11321084.html&quot;&gt;https://www.heise.de/news/SolarWinds-Serv-U-Angreifer-missbrauchen-DoS-Luecke-in-FTP-Server-11321084.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VMware: Mehrere Produkte mit Stored-Cross-Site-Scripting-Lücken&lt;/h3&gt;

Broadcom warnt vor mehreren Stored-Cross-Site-Scripting-Lücken in VMware Cloud Foundation und weiteren Produkten. Updates helfen. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/VMware-Mehrere-Produkte-mit-Stored-Cross-Site-Scripting-Luecken-11321673.html&quot;&gt;https://www.heise.de/news/VMware-Mehrere-Produkte-mit-Stored-Cross-Site-Scripting-Luecken-11321673.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Comodo Internet Security: DoS-Bug ohne Sicherheitsupdate&lt;/h3&gt;

Wer sich eine Internet Security Suite installiert, möchte den Rechner absichern. Im Fall von Comodo kommt eine Sicherheitslücke mit. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Comodo-Internet-Security-DoS-Bug-ohne-Sicherheitsupdate-11321732.html&quot;&gt;https://www.heise.de/news/Comodo-Internet-Security-DoS-Bug-ohne-Sicherheitsupdate-11321732.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Critical Everest Forms Pro flaw exploited to take over WordPress sites&lt;/h3&gt;

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. The security issue affects versions 1.9.12 and earlier of the plugin and can be leveraged without authentication to execute arbitrary code on the server.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/&quot;&gt;https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Kein Patch verfügbar: Bitlocker-Exploit Bitskrieg veröffentlicht&lt;/h3&gt;

Microsofts empfohlene Korrektur für den Bitlocker-Exploit Yellowkey ist offenbar unvollständig. Mit Bitskrieg soll sie sich umgehen lassen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/kein-patch-verfuegbar-bitlocker-exploit-bitskrieg-veroeffentlicht-2606-209491.html&quot;&gt;https://www.golem.de/news/kein-patch-verfuegbar-bitlocker-exploit-bitskrieg-veroeffentlicht-2606-209491.html&lt;/a&gt;

&lt;hr&gt;
&lt;h3&gt;LWN Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1076983/&quot;&gt;https://lwn.net/Articles/1076983/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-08T18:35:10Z</dc:date></entry><entry><title>Tageszusammenfassung - 05.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-05062026"/><author><name>CERT.at</name></author><updated>2026-06-05T18:44:16Z</updated><published>2026-06-05T18:44:16Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 03-06-2026 18:00 - Freitag 05-06-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Unauthenticated RCE as QSECOFR via IBM i Management Central&lt;/h3&gt;

Management Central is one of those services that has been running quietly on IBM i systems for over two decades. Many administrators don-t know it-s there, and its protocol security missed the scrutiny of researchers until now. The combination of a custom binary protocol, client-controlled authentication flags, and a derived usedForAuth field that can be trivially satisfied resulted in unauthenticated root-level command execution.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-via-ibm-i-management-central/&quot;&gt;https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-via-ibm-i-management-central/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New IronWorm malware hits 36 packages in npm supply-chain attack&lt;/h3&gt;

A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm. The malware targets 86 environment variables (key-value pairs) and 20 credential files that may contain OpenAI, AWS, Anthropic, and npm credentials, vault configuration files, SSH keys, and Exodus cryptocurrency wallet files.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Software supply chain attacks: check your dependencies&lt;/h3&gt;

This blog, aimed at cyber security professionals, exposes the insidious nature of recent attacks, underlining the growing threat from software supply chains, and how attackers are able to exploit them. We explain how organisations can check if they have been affected by such a supply chain attack, and recommend actions to take to mitigate compromise and prevent further spread.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies&quot;&gt;https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT&lt;/h3&gt;

Cybersecurity researchers have flagged a new malspam campaign that makes use of Googles DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT. [..] The attack begins when an unsuspecting user opens an HTML file that's attached to a phishing email. The file triggers a meta-refresh browser redirect to a Google DoubleClick Campaign Manager click-tracking URL, from where the user is steered to another redirector, which decodes the Base64-encoded email address and leads the victim to a landing page containing a &quot;Download PDF&quot; button.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html&quot;&gt;https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS&lt;/h3&gt;

Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework. [..] Attack chains specifically target users looking for such tools on search engines like Google, causing the bogus sites to be surfaced on top of the search results.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html&quot;&gt;https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;EU-Paket für digitale Souveränität: -Gefahr einer technologischen Entkopplung-&lt;/h3&gt;

Das neue Tech-Souveränitätspaket der EU erntet gemischte Reaktionen: Open-Source-Verfechter jubeln, doch US-Branchenverbände warnen vor schweren Marktstörungen.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11318218&quot;&gt;https://heise.de/-11318218&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Analyse zum Souveränitätspaket der EU: Krisenfest per Gesetz?&lt;/h3&gt;

Die EU-Kommission hat ein großes Paket vorgestellt, das den Staatenbund technologisch souveräner machen soll. Immerhin ein Anfang, analysiert Falk Steiner.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11318875&quot;&gt;https://heise.de/-11318875&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog&lt;/h3&gt;

A newly released federal audit now documents NIST-s long-running NVD backlog, with findings that are hard to square with two years of public assurances that the database was being brought back under control.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/federal-audit-finds-nist-wasted-funds-with-no-plan-to-clear-nvd-backlog&quot;&gt;https://socket.dev/blog/federal-audit-finds-nist-wasted-funds-with-no-plan-to-clear-nvd-backlog&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;A Post-Quantum Future for Lets Encrypt&lt;/h3&gt;

Let-s Encrypt is committed to a post-quantum-safe Web PKI. The path we-re planning to take is Merkle Tree Certificates (-MTCs-), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future.
&lt;p /&gt;
&lt;A HREF=&quot;https://letsencrypt.org/2026/06/03/pq-certs.html&quot;&gt;https://letsencrypt.org/2026/06/03/pq-certs.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The Interesting Case of WSL for Payload Staging&lt;/h3&gt;

Windows Subsystem for Linux (WSL) lets you run a Linux environment directly on Windows without a traditional virtual machine or dual-boot setup. [..] This is a case study in indirect command execution - a class of techniques where the process responsible for a malicious action is not the process that appears in telemetry.
&lt;p /&gt;
&lt;A HREF=&quot;https://detect.fyi/the-interesting-case-of-wsl-for-payload-staging-bfaa0f69329a?source=rssd5fd8f494f6a4&quot;&gt;https://detect.fyi/the-interesting-case-of-wsl-for-payload-staging-bfaa0f69329a?source=rssd5fd8f494f6a4&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;IT-Forscher zeigen anpassungsfähigen KI-Wurm&lt;/h3&gt;

IT-Forscher untersuchen, ob künstliche Intelligenz eine Bedrohung darstellt. Dabei haben sie eine neue Bedrohungsart entwickelt: Ein KI-Wurm, der maßgeschneiderte Angriffe auf jedes Ziel startet, dem er begegnet.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/IT-Forscher-zeigen-anpassungsfaehigen-KI-Wurm-11318083.html&quot;&gt;https://www.heise.de/news/IT-Forscher-zeigen-anpassungsfaehigen-KI-Wurm-11318083.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257&lt;/h3&gt;

We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/&quot;&gt;https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;

&lt;h3&gt;Drupal: Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-042&quot;&gt;https://www.drupal.org/sa-contrib-2026-042&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drupal: Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-041&quot;&gt;https://www.drupal.org/sa-contrib-2026-041&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drupal: TacJS - Moderately critical - Improper Access Control - SA-CONTRIB-2026-040&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-040&quot;&gt;https://www.drupal.org/sa-contrib-2026-040&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drupal: LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-039&quot;&gt;https://www.drupal.org/sa-contrib-2026-039&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Webex Meetings Cross-Site Scripting Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-jw3NeQzS&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-jw3NeQzS&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Finesse Remote File Inclusion Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-rfi-gwpkdc89&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-rfi-gwpkdc89&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1076364/&quot;&gt;https://lwn.net/Articles/1076364/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1076605/&quot;&gt;https://lwn.net/Articles/1076605/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-05T18:44:16Z</dc:date></entry><entry><title>Tageszusammenfassung - 03.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-03062026"/><author><name>CERT.at</name></author><updated>2026-06-03T19:11:38Z</updated><published>2026-06-03T19:11:38Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 02-06-2026 18:00 - Mittwoch 03-06-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Absicherung von Software: Anthropic öffnet -Project Glasswing- für Europa&lt;/h3&gt;

Anthropic will den Zugriff auf sein leistungsstärkstes KI-Modell Mythos deutlich ausweiten und Organisationen in mehr als 15 Staaten damit nach Sicherheitslücken in systemrelevanter Software suchen lassen. Das hat das KI-Unternehmen jetzt mitgeteilt, ohne das aber aufzuschlüsseln. [..] Anthropic hat Mythos Anfang April vorgestellt und erklärt, dass das Modell so gefährlich sei, dass es nur Firmen zur Verfügung gestellt wird, die an IT-Sicherheit arbeiten.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11316440&quot;&gt;https://heise.de/-11316440&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Trump gibt sich exklusiven Zugriff auf neue KI vor allen anderen&lt;/h3&gt;

Geheimes Benchmarking von KI, Zugriff für die US-Regierung vor allen anderen, staatliche Suche nach Software-Bugs. Das und mehr ordnet der US-Präsident an.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Trump-gibt-sich-exklusiven-Zugriff-auf-neue-KI-vor-allen-anderen-11316188.html&quot;&gt;https://www.heise.de/news/Trump-gibt-sich-exklusiven-Zugriff-auf-neue-KI-vor-allen-anderen-11316188.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Android bekommt Anrufererkennung gegen Betrugsanrufe&lt;/h3&gt;

Google baut einen neuen Mechanismus in Android ein, der betrügerische Anrufe mit gefälschten Kontakten unterbinden soll. Betrugsversuche mit gefälschten Caller-IDs (der übertragenen Anrufer-Rufnummer) soll das eindämmen.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11316362&quot;&gt;https://heise.de/-11316362&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Codex Discovered a Hidden HTTP/2 Bomb&lt;/h3&gt;

We-re publishing HTTP/2 Bomb, a remote denial-of-service exploit against most major web servers, including: nginx, Apache httpd, Microsoft IIS, Envoy, Cloudflare Pingora [..] The vulnerable behavior exists in each server's default HTTP/2 configuration. [..] A curious search on Shodan revealed 880,000+ websites supporting HTTP/2 and running one of these servers, though many sit behind a CDN, which is much harder to bring down. [..] A home computer on a 100Mbps connection can render a vulnerable server inaccessible within seconds. [..] We disclosed the issue to nginx in April. They responded by importing the max_headers directive from freenginx, shipping it in 1.29.8 the next day. At this point, we consider the attack public.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb&quot;&gt;https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Over 116,000 Mincraft systems infected in WeedHack malware campaign&lt;/h3&gt;

A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January. The malware is distributed through Minecraft-related malicious mods, clients, cheats, and utilities that are promoted over YouTube and SEO (search engine optimization) poisoning.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/over-116-000-mincraft-systems-infected-in-weedhack-malware-campaign/&quot;&gt;https://www.bleepingcomputer.com/news/security/over-116-000-mincraft-systems-infected-in-weedhack-malware-campaign/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Argamal: Malware hidden in hentai games&lt;/h3&gt;

The DLLs were spawned by different games written using various game engines and programming languages, including RenPy (Python) and RPG Maker MV (JavaScript), among others. However, they all had one thing in common: they were all hentai games.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/argamal-rat-distributed-with-hentai-games/119999/&quot;&gt;https://securelist.com/argamal-rat-distributed-with-hentai-games/119999/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Espionage Campaign Targeted Stock Exchange Executive for Five Months&lt;/h3&gt;

The attackers' focus throughout was on a single objective: long-term, incremental theft of the contents of a single Outlook mailbox, exfiltrated through Dropbox and OneDrive Personal in small batches over a period of five months to avoid raising suspicions or triggering alerts on the system. This was a tightly focused and highly targeted campaign, with five months being a significant dwell time for an attacker. It is notable to see the different techniques and approaches used by the attacker in order to stay under the radar and maintain persistent access. [..] The initial infection vector used by the attackers in this incident is unknown.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.security.com/threat-intelligence/stock-exchange-espionage&quot;&gt;https://www.security.com/threat-intelligence/stock-exchange-espionage&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Acer working to patch max severity zero-days in Wave 7 routers&lt;/h3&gt;

Acer is working to address two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers. [..] The first zero-day, a broken access control vulnerability tracked as CVE-2026-49200, can allow unauthenticated attackers to remotely access plaintext credentials stored in log archives. [..] The second one (CVE-2026-49201) stems from a hardcoded cryptographic key that lets remote attackers without privileges gain persistent backdoor access to the router. [..] While no security patches are available yet for these two flaws, Acer says it's working on fixes that should be released by the end of the month.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/&quot;&gt;https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes&lt;/h3&gt;

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a users NTLMv2 hash to the attacker. [..] As a result, a threat actor could leverage the captured hash to conduct relay attacks and gain deeper access into a network. Following responsible disclosure on April 15, 2026, Microsoft declined to address the issue, stating &quot;only Important and Critical severity cases meet our bar for servicing.&quot;
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/06/unpatched-windows-search-uri.html&quot;&gt;https://thehackernews.com/2026/06/unpatched-windows-search-uri.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GitHub-Drama 1: Sicherheitsforscher veröffentlicht 0-Day-Schwachstelle&lt;/h3&gt;

Ein weiterer Sicherheitsforscher hat die koordinierte Offenlegung von Schwachstellen beim Microsoft Security Resource Center (MSRC) übersprungen und eine kritische 1-Klick-GitHub-Schwachstelle öffentlich gemacht. Mit der Schwachstelle in VSCode lassen sich GitHub-Tokens stehlen, und der Entdecker hatte keine Lust mit dem MSRC zu diskutieren. [..] Der Sicherheitsforscher hat einen funktionierenden Proof-of-Concept veröffentlicht. [..] Er empfiehlt, die Daten der Website http://github[.]dev zu löschen, um das Risiko zu mindern, solange das Problem öffentlich bekannt ist.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/06/03/github-drama-1-sicherheitsforscher-veroeffentlicht-0-day-schwachstelle/&quot;&gt;https://borncity.com/blog/2026/06/03/github-drama-1-sicherheitsforscher-veroeffentlicht-0-day-schwachstelle/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1076117/&quot;&gt;https://lwn.net/Articles/1076117/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mozilla: Security Vulnerabilities fixed in Firefox 151.0.3&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.mozilla.org/en-US/security/advisories/mfsa2026-54/&quot;&gt;https://www.mozilla.org/en-US/security/advisories/mfsa2026-54/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Paloalto: CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities (Severity: LOW)&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://security.paloaltonetworks.com/CVE-2026-0249&quot;&gt;https://security.paloaltonetworks.com/CVE-2026-0249&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Solarwinds: WHD 2026.2 release notes&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2_release_notes.htm&quot;&gt;https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2_release_notes.htm&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-03T19:11:38Z</dc:date></entry><entry><title>Tageszusammenfassung - 02.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-02062026"/><author><name>CERT.at</name></author><updated>2026-06-02T18:14:06Z</updated><published>2026-06-02T18:14:06Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 01-06-2026 18:00 - Dienstag 02-06-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Passwortmanager: Hacker erbeuten Passwort-Tresore von Dashlane-Nutzern&lt;/h3&gt;

Infolge eines Brute-Force-Angriffs wurden einige Dashlane-Nutzer temporär gesperrt. Die Angreifer sollen zudem an Passwort-Tresore gelangt sein.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/brute-force-attacke-angreifer-erbeuten-passwort-tresore-von-dashlane-2606-209302.html&quot;&gt;https://www.golem.de/news/brute-force-attacke-angreifer-erbeuten-passwort-tresore-von-dashlane-2606-209302.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)&lt;/h3&gt;

This time, the SVG files are really simple and even don-t contain any graphical element but a simple piece of JavaScript that will redirect the victim's browser to the phishing page.
&lt;p /&gt;
&lt;A HREF=&quot;https://isc.sans.edu/diary/rss/33040&quot;&gt;https://isc.sans.edu/diary/rss/33040&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVSS: NIST schränkt Bewertung von IT-Sicherheitslücken ein&lt;/h3&gt;

Das US-amerikanische National Institute of Standards and Technology (NIST) wird die Bewertung von IT-Sicherheitslücken mit den bekannten CVSS-Schweregraden weitgehend einstellen. Das ist eine der Maßnahmen, mit denen NIST den wachsenden Rückstau seiner National Vulnerability Database (NVD) bekämpfen möchte. Wie das vereinbar ist mit der rechtlichen Verpflichtung, CVSS (Common Vulnerability Scoring System) zu berechnen, bleibt offen - aber wo kein Kläger, da kein Richter.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/CVSS-NIST-schraenkt-Bewertung-von-IT-Sicherheitsluecken-ein-11314492.html&quot;&gt;https://www.heise.de/news/CVSS-NIST-schraenkt-Bewertung-von-IT-Sicherheitsluecken-ein-11314492.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Red-Hat-Infostealer kommt auf mehr als 100.000 Downloads&lt;/h3&gt;

Ende Mai haben Cyberkriminelle in einer Lieferkettenattacke, die mittels eines Mini-Shai-Hulud-Klons erfolgte, bösartige Versionen von npm-Paketen verbreitet. Ziel der Malware, die sich selbst Miasma nennt, waren die Managed Cloud Services von Red Hat. Mittlerweile sind keine bösartigen Paketversionen mehr im Umlauf. Sicherheitsexperten raten dennoch dazu, die Credentials zu rotieren.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Mini-Shai-Hulud-Klon-Miasma-nimmt-Red-Hat-ins-Visier-11315039.html&quot;&gt;https://www.heise.de/news/Mini-Shai-Hulud-Klon-Miasma-nimmt-Red-Hat-ins-Visier-11315039.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake virus alerts are invading mobile games&lt;/h3&gt;

Sometimes it happens. You-re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere: -Your device is infected!- [..] Unfortunately, cybercriminals sometimes manage to buy advertising space and use it to defraud gamers.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/mobile/2026/06/fake-virus-alerts-are-invading-mobile-games&quot;&gt;https://www.malwarebytes.com/blog/mobile/2026/06/fake-virus-alerts-are-invading-mobile-games&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Vorsicht, Phishing: Spar-Gewinnspiel zu Bier-Paketen ist ein Fake!&lt;/h3&gt;

Der Sommer naht mit Riesenschritten und die thematisch passenden Betrugsmaschen schießen aus dem Boden wie Schwammerl. Eine Falle, die im Vorjahr für besonders viel Aufsehen gesorgt hat, feiert dabei ein Comeback: Es geht um ein Bier-Gewinnspiel! Die optische und inhaltliche Gestaltung hat sich im Vergleich zur 2025er-Variante zwar etwas geändert, die Abläufe sind allerdings dieselben geblieben. Ein kleines Update.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/phishing-spar-gewinnspiel-bier/&quot;&gt;https://www.watchlist-internet.at/news/phishing-spar-gewinnspiel-bier/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ASFINAG-Phishing: Über eine Fake-Mail an die Kreditkartendaten&lt;/h3&gt;

Erwischt beim Fahren ohne Vignette? Mit der Zahlung einer Ersatzmaut in Höhe von 12,36 Euro oder dem nachträglichen Kauf einer 10-Tages-Vignette ist die Angelegenheit aus der Welt geschafft? Was auf den ersten Blick aussieht wie eine echte Benachrichtigung der ASFINAG, ist in Wahrheit eine neue Phishing-Welle.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/asfinag-phishing-mail-kreditkartendaten/&quot;&gt;https://www.watchlist-internet.at/news/asfinag-phishing-mail-kreditkartendaten/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hacker stehlen Hunderte Instagram-Konten über Metas KI-Support&lt;/h3&gt;

Die Schatten eines ausgelagerten Instagram-Supports an eine KI. Hackern ist es gelungen, langjährige, hochkarätige Instagram-Konten zu kapern. Dazu haben Sie die Funktion zum Passwort-Reset aufgerufen und den KI-Support-Chatbot von Meta einfach gebeten, die mit dem Konto verknüpfte E-Mail-Adresse zu ändern.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/06/02/hacker-stehlen-hunderte-instagram-konten-ueber-ki-support/&quot;&gt;https://borncity.com/blog/2026/06/02/hacker-stehlen-hunderte-instagram-konten-ueber-ki-support/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ivanti EPMM -Sleeper Shells- not so sleepy?&lt;/h3&gt;

In late January 2026, an advisory covering two remote code execution vulnerabilities (CVE-2026-1281 &amp; CVE-2026-1340) in Ivanti Endpoint Manager Mobile (EPMM) was published. [..] In a recent incident that NVISO CSIRT handled, we came across a compromised Ivanti EPMM device, and the logs quickly revealed that the aforementioned vulnerabilities were used to compromise the device. From the log entries, we quickly identified what we believe is the same webshell Defused was reporting on.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.nviso.eu/2026/03/13/ivanti-epmm-sleeper-shells-not-so-sleepy/&quot;&gt;https://blog.nviso.eu/2026/03/13/ivanti-epmm-sleeper-shells-not-so-sleepy/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions&lt;/h3&gt;

GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/wordpress-malware-steam-profile-comments-instructions/&quot;&gt;https://hackread.com/wordpress-malware-steam-profile-comments-instructions/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;

&lt;h3&gt;LWN: Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1075966/&quot;&gt;https://lwn.net/Articles/1075966/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WebKitGTK and WPE WebKit Security Advisory WSA-2026-0003&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://webkitgtk.org/security/WSA-2026-0003.html&quot;&gt;https://webkitgtk.org/security/WSA-2026-0003.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zyxel security advisory for buffer overflow vulnerabilities in the UPnP function of certain 4G LTE/5G NR CPE and DSL/Ethernet CPE&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-buffer-overflow-vulnerabilities-in-the-upnp-function-of-certain-4g-lte-5g-nr-cpe-and-dsl-ethernet-cpe-06-02-2026&quot;&gt;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-buffer-overflow-vulnerabilities-in-the-upnp-function-of-certain-4g-lte-5g-nr-cpe-and-dsl-ethernet-cpe-06-02-2026&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Android: Patchday: 18 kritische Sicherheitslücken bedrohen Android 14, 15, 16&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11314546&quot;&gt;https://heise.de/-11314546&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Samsung: Juni-Patchday bei Samsung: Zahlreiche Sicherheitslücken gestopft&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11315093&quot;&gt;https://heise.de/-11315093&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-02T18:14:06Z</dc:date></entry><entry><title>Tageszusammenfassung - 01.06.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/6/tagesberichte-01062026"/><author><name>CERT.at</name></author><updated>2026-06-01T18:36:20Z</updated><published>2026-06-01T18:36:20Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 29-05-2026 18:00 - Montag 01-06-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Miasma: Supply Chain Attack Targeting RedHat npm Packages&lt;/h3&gt;

Detect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages&quot;&gt;https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;On the cyber-security implications of current LLMs&lt;/h3&gt;

The rapid progress in the capabilities of LLMs for cyber-security related tasks naturally leads to the question of what the right response should be. [..] So, here is a rough outline of how I structure the problem set in my mind. It-s not a complete treatment of all the points, just a scaffolding that needs to be fleshed out. Nevertheless, I think it could provide some value.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/en/blog/2026/6/on-the-cyber-security-implications-of-current-llms&quot;&gt;https://www.cert.at/en/blog/2026/6/on-the-cyber-security-implications-of-current-llms&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ChatGPT share links abused to host fake outage pages to deliver malware&lt;/h3&gt;

Threat actors are abusing ChatGPTs content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware/&quot;&gt;https://www.bleepingcomputer.com/news/security/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft fixes KB5089549 Windows security update install issues&lt;/h3&gt;

Microsoft has resolved a known issue causing installation failures and 0x800f0922 errors when deploying the May 2026 Windows 11 security update (KB5089549). [..] On Friday, the company said the issue has been resolved in the Windows 11 KB5089573 preview cumulative update, with the fix to be made available to all users who install the June Patch Tuesday updates later this month.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-kb5089549-windows-security-update-install-issues/&quot;&gt;https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-kb5089549-windows-security-update-install-issues/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit&lt;/h3&gt;

In May, Palo Alto Networks (PAN) disclosed and fixed the flaw, tracked as CVE-2026-0257, but it updated the advisory last week to note that there have been &quot;limited exploit attempts on unpatched PAN-OS devices without mitigations applied.&quot;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.darkreading.com/threat-intelligence/patch-palo-alto-auth-bypass-bug-exploit&quot;&gt;https://www.darkreading.com/threat-intelligence/patch-palo-alto-auth-bypass-bug-exploit&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Containers on fire: from container escapes to supply chain attacks&lt;/h3&gt;

We break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/container-attack-vectors/120010/&quot;&gt;https://securelist.com/container-attack-vectors/120010/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit&lt;/h3&gt;

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html&quot;&gt;https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Handy-Spione als Schnäppchen: Italiens boomende Spyware-Schattenindustrie&lt;/h3&gt;

Wenn von staatlicher Überwachungssoftware die Rede ist, fallen meist Namen wie Pegasus, Predator oder Paragon (Graphite)). Diese hochentwickelten Werkzeuge kosten Millionen und nutzen unbekannte Sicherheitslücken in Form von Zero-Day-Exploits, um Smartphones völlig ohne Zutun der Betroffenen zu infizieren. Doch diese High-End-Produkte bilden nur die Spitze des Eisbergs. Abseits des Rampenlichts hat sich in Europa ein paralleler, weitaus billigerer Markt etabliert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Handy-Spione-als-Schnaeppchen-Italiens-boomende-Spyware-Schattenindustrie-11312651.html&quot;&gt;https://www.heise.de/news/Handy-Spione-als-Schnaeppchen-Italiens-boomende-Spyware-Schattenindustrie-11312651.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Let-s talk about encrypted reasoning&lt;/h3&gt;

Last week I decided it-d be fun to set up an OpenClaw agent. [..] But configuring the agent to talk to Claude exposed me to something way more interesting: I got a cool error. The kind of error that cryptographers can-t resist [..] So TL;DR, while I was able to extract application-specific secrets that did exist, I wasn-t able to extract model prompts that don-t. [..] I think model providers should think hard about this reasoning data, and they should make sure it doesn-t leak things they don-t want it to.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.cryptographyengineering.com/2026/05/29/fooling-around-with-encrypted-reasoning-blobs/&quot;&gt;https://blog.cryptographyengineering.com/2026/05/29/fooling-around-with-encrypted-reasoning-blobs/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVE-2026-48710: A Maintainers Perspective&lt;/h3&gt;

Upgrade to Starlette 1.0.1 or later, which validates the Host header and rejects malformed values. Beyond that: don't base authorization on request.url.path. If you need the routed path, use request.scope[&quot;path&quot;], which is never reconstructed from the Host header. Better yet, don't make authorization decisions on path strings at all.
&lt;p /&gt;
&lt;A HREF=&quot;https://marcelotryle.com/blog/2026/05/28/cve-2026-48710-a-maintainers-perspective/&quot;&gt;https://marcelotryle.com/blog/2026/05/28/cve-2026-48710-a-maintainers-perspective/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;A census of the Starlette host-header auth bypass CVE-2026-48710&lt;/h3&gt;

CVE-2026-48710 is a Starlette host-header authentication bypass. Because FastAPI is built on Starlette, the affected population spans applications of every kind - AI and non-AI - and that broad impact is only starting to unfold.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.persistent-security.net/post/cve-2026-48710-bad-hosts-in-the-wild&quot;&gt;https://www.persistent-security.net/post/cve-2026-48710-bad-hosts-in-the-wild&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ivanti: Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614)&lt;/h3&gt;

An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
&lt;p /&gt;
&lt;A HREF=&quot;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US&quot;&gt;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;IT-Sicherheitslösung Check Point Security Gateway ist verwundbar&lt;/h3&gt;

Insgesamt haben die Entwickler vier Softwareschwachstellen geschlossen. Drei davon (CVE-2026-48131, CVE-2026-48132, CVE-2026-48133) sind mit dem Bedrohungsgrad -hoch- eingestuft. In zwei Fällen können Angreifer durch das Versenden von präparierten Datenpaketen VPN-Verbindungen terminieren. Wenn im Kontext der Browser-basierten Authentifizierung die Funktion Identity Awareness aktiv ist, können Angreifer ohne Authentifizierung interne Dateien von Security Gateway einsehen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/IT-Sicherheitsloesung-Check-Point-Security-Gateway-ist-verwundbar-11312987.html&quot;&gt;https://www.heise.de/news/IT-Sicherheitsloesung-Check-Point-Security-Gateway-ist-verwundbar-11312987.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1075733/&quot;&gt;https://lwn.net/Articles/1075733/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mozilla: Security Vulnerabilities fixed in Firefox for iOS 151.2&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.mozilla.org/en-US/security/advisories/mfsa2026-53/&quot;&gt;https://www.mozilla.org/en-US/security/advisories/mfsa2026-53/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-06-01T18:36:20Z</dc:date></entry><entry><title>Tageszusammenfassung - 29.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-29052026"/><author><name>CERT.at</name></author><updated>2026-05-29T18:37:36Z</updated><published>2026-05-29T18:37:36Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 28-05-2026 18:00 - Freitag 29-05-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer&lt;/h3&gt;

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. [..] The activity, observed by the cybersecurity company in May 2026, involves the exploitation of CVE-2026-35616 (CVSS score: 9.1), a critical pre-authentication API access bypass leading to privilege escalation. The issue was addressed by Fortinet in FortiClient EMS 7.4.7 and later.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/threat-actors-exploit-critical.html&quot;&gt;https://thehackernews.com/2026/05/threat-actors-exploit-critical.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Signal users targeted in backup-stealing phishing attacks&lt;/h3&gt;

A new phishing campaign is targeting Signal users by attempting to steal their backup recovery keys to access encrypted message archives. The attack is initiated by a text message pretending to come from Signal Support. [..] For now, the attacks appear to be targeted.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/news/2026/05/signal-users-targeted-in-backup-stealing-phishing-attacks&quot;&gt;https://www.malwarebytes.com/blog/news/2026/05/signal-users-targeted-in-backup-stealing-phishing-attacks&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Sechs Zero-Days in sechs Wochen offengelegt: Microsoft reagiert mit Drohung&lt;/h3&gt;

Nachweise von Sicherheitslücken in Microsoft Windows sind zuletzt mehrfach veröffentlicht worden, ohne dass es dafür ein Sicherheitsupdate gegeben hat. [..] In einem Blogpost ärgert sich das Microsoft Security Response Center (MSRC), dass es nicht vorab über die Sicherheitslücken informiert wurde. [..] Das Github-Konto des mutmaßlichen Entdeckers der gegenständlichen Sicherheitslücken (Pseudonym Nightmare Eclipse) hat Microsoft bereits gelöscht. [..] Der Konzern droht mit Klagen und der Polizei. [..] In dem selben mit -Nightmare Eclipse- betitelten Blog weist der Autor den Vorwurf, CVD-Regeln nicht befolgt zu haben, als -Diffamierung- von sich.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11310723&quot;&gt;https://heise.de/-11310723&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Chrome-Update schließt 151 Sicherheitslecks - davon 22 kritische&lt;/h3&gt;

Google hat am Mittwoch den Webbrowser Chrome in aktualisierter Fassung veröffentlicht. Erst in der Nacht zum Freitag haben die Entwickler jedoch Informationen über die damit geschlossenen Sicherheitslücken nachgeliefert: 151 Schwachstellen hat die neue Version weniger. Davon haben 22 die Einstufung als -kritisches- Risiko erhalten.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11310811&quot;&gt;https://heise.de/-11310811&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cybersicherheit: Kritische Infrastrukturen holen auf, doch -Risiko-Zone- wächst&lt;/h3&gt;

Ein Enisa-Bericht zeigt deutliche Fortschritte durch die NIS2-Richtlinie, warnt aber vor wachsenden digitalen Gefahren in den Sektoren Raumfahrt und Transport.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11312014&quot;&gt;https://heise.de/-11312014&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;RIPE NCC session fixation: poaching logins with an Atlas probe&lt;/h3&gt;

RIPE NCC-s single sign-on did not rotate session tokens on login, leaving 12000 Atlas probe hosts in a position to compromise other RIPE NCC users- logins. A single link click planted a session token in a target-s browser. [..] I reported this in April 2026, and it was fixed within three weeks. But the structural pattern that makes attacks like this possible, hosting third-party infrastructure under the same domain as the all-powerful SSO cookie, has not yet changed.
&lt;p /&gt;
&lt;A HREF=&quot;https://mxsasha.eu/posts/ripe-ncc-session-fixation/&quot;&gt;https://mxsasha.eu/posts/ripe-ncc-session-fixation/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Critical Security Patch Update Advisory - May 2026&lt;/h3&gt;

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle-s existing quarterly cumulative Critical Patch Updates (CPUs). These patches address vulnerabilities in Oracle code and in third party components included in Oracle products.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.oracle.com/security-alerts/cspumay2026.html&quot;&gt;https://www.oracle.com/security-alerts/cspumay2026.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CIFSwitch: a non-universal Linux local root vulnerability&lt;/h3&gt;

A distro-specific Linux LPE found by harnessing LLMs into better multihop knowledge composition. [..] The harnessed agents found an issue at the intersection of kernel-s CIFS and the userspace cifs-utils-provided helper. [..] A very non-exhaustive list of systems tested. [..] You can use the released PoC to validate the mitigations.
&lt;p /&gt;
&lt;A HREF=&quot;https://heyitsas.im/posts/cifswitch/&quot;&gt;https://heyitsas.im/posts/cifswitch/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover&lt;/h3&gt;

A critical vulnerability in the WP Maps Pro WordPress plugin allowed unauthenticated attackers to create administrator accounts and potentially perform a complete site takeover on affected websites.  The issue impacted all WP Maps Pro versions up to 6.1.0. [..] The vulnerability was submitted to the Wordfence Bug Bounty Program on March 24, 2026 [..] May 20, 2026 - WP Maps Pro 6.1.1 was released. [..] CVE-2026-8732
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/wp-maps-pro-vulnerability/&quot;&gt;https://thecyberexpress.com/wp-maps-pro-vulnerability/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VU#780781: Casdoor contains multiple authentication bypass and access management vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://kb.cert.org/vuls/id/780781&quot;&gt;https://kb.cert.org/vuls/id/780781&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1075310/&quot;&gt;https://lwn.net/Articles/1075310/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-29T18:37:36Z</dc:date></entry><entry><title>Tageszusammenfassung - 28.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-28052026"/><author><name>CERT.at</name></author><updated>2026-05-28T19:39:43Z</updated><published>2026-05-28T19:39:43Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 27-05-2026 18:00 - Donnerstag 28-05-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Update #2: Qilin-Ransomware nutzt Initial Access aus ZipLine-Kampagne - DACH-Recruiting-Domains im Fokus&lt;/h3&gt;

Update #2: 28. Mai 2026: Eine weitere neue Köderdomain wurde bekannt, die demselben Muster folgt: falkentalent[.]at
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/aktuelles/2026/5/zipline-qilin-raas-update&quot;&gt;https://www.cert.at/de/aktuelles/2026/5/zipline-qilin-raas-update&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GPU mining malware spreads via SEO poisoning, AI chatbots&lt;/h3&gt;

Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. -The compromise occurs through malicious download pages for utility software typically installed by owners of powerful systems, like CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear. [..] Microsoft researchers discovered the campaign and determined that the attack begins when users look for one of the aforementioned utilities and are presented with malicious links boosted in search rankings through SEO poisoning.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/gpu-mining-malware-spreads-via-seo-poisoning-ai-chatbots/&quot;&gt;https://www.bleepingcomputer.com/news/security/gpu-mining-malware-spreads-via-seo-poisoning-ai-chatbots/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Vibe-Coding-Verdacht: Datenpanne in NPM-Paket legt Malware-Operation offen&lt;/h3&gt;

Sicherheitsforscher von OX Security haben einen Malware-Angriff beobachtet, bei dem der Angreifer offenbar wenig Gespür für seine eigene operative Sicherheit hatte. Laut Blogbeitrag der Forscher versuchte der Angreifer, durch ein NPM-Paket einen Infostealer zu verbreiten. Das Paket enthielt jedoch sein Github-Token, so dass die Forscher die Malware-Aktivitäten ziemlich genau nachverfolgen konnten.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/vibe-coding-verdacht-datenpanne-in-npm-paket-legt-malware-operation-offen-2605-209123.html&quot;&gt;https://www.golem.de/news/vibe-coding-verdacht-datenpanne-in-npm-paket-legt-malware-operation-offen-2605-209123.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Seitenkanalangriff per Javascript: Spionage über SSD-Zugriffe einer Website&lt;/h3&gt;

Durch gezielte SSD-Zugriffe und Zeitmessungen können Angreifer über eine Website mit speziellem Javascript-Code heimlich Informationen darüber auslesen, welche Anwendungen auf den Systemen der Besucher laufen. [..] Im Hintergrund geöffnete Webseiten konnten die Forscher bei ihren Tests mit einer Wahrscheinlichkeit von 88,95 Prozent, andere ausgeführte Anwendungen sogar mit einer Wahrscheinlichkeit von 95,83 Prozent korrekt identifizieren.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/seitenkanalangriff-per-javascript-spionage-ueber-ssd-zugriffe-einer-website-2605-209137.html&quot;&gt;https://www.golem.de/news/seitenkanalangriff-per-javascript-spionage-ueber-ssd-zugriffe-einer-website-2605-209137.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years&lt;/h3&gt;

In late April 2026, a client reached out to us for incident response support after discovering a miner running on users- computers. We later discovered that the malware was being distributed via illegal movie and TV show streaming sites. The infection chain leveraged a fake update for a video player plugin. When the user attempted to watch a video, the player displayed a message saying the plugin version was outdated and asking to install an update to continue. [..] The archive contained a legitimate executable, HLS Installer.874.exe, alongside a malicious DLL.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/video-books-pirates-miners-rat/119943/&quot;&gt;https://securelist.com/video-books-pirates-miners-rat/119943/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Warnung vor gefälschten FIFA-Webseiten vor der Fußball-WM 2026&lt;/h3&gt;

In zwei Wochen startet die Fußball-WM. Kriminelle nutzen die Gunst der Stunde und fälschen die FIFA-Webseite etwa für Phishing. [..] Mehr als 300 Domains laufen mit der betrügerischen Infrastruktur im Hintergrund. Sie greifen das Ping-Identity-SSO-System der FIFA an, um Zugangsdaten abzugreifen. 140 weitere Domains gelten als verdächtig und 3800 sind noch geparkt und warten nur auf ihre Aktivierung. Insgesamt 2513 FIFA-Kontenzugangsdaten für die Domains fifa.com und fifa.org haben die IT-Forscher bereits im Darknet gefunden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Warnung-vor-gefaelschten-FIFA-Webseiten-vor-der-Fussball-WM-2026-11309777.html&quot;&gt;https://www.heise.de/news/Warnung-vor-gefaelschten-FIFA-Webseiten-vor-der-Fussball-WM-2026-11309777.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Gefälschte SMS im Namen der Österreichischen Pensionsversicherung&lt;/h3&gt;

Eine SMS der Pensionsversicherung fordert zur Aktualisierung des Pensionskontos auf. Vorsicht: Hinter dem Link steckt keine Behörde, sondern eine Phishing-Falle.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/gefaelschte-sms-im-namen-der-pensionsversicherung/&quot;&gt;https://www.watchlist-internet.at/news/gefaelschte-sms-im-namen-der-pensionsversicherung/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SharePoint Update für CVE-2026-45659 (26.5.2026)&lt;/h3&gt;

Microsoft hat zum 21. Mai 2026 einen Hinweis auf ein außerplanmäßiges Sicherheitsupdate für seine noch unterstützten SharePoint-Systeme freigegeben (oder zumindest dokumentiert, denn das Update kam bereits zum 12. Mai 2026 mit den regulären SharePoint-Updates). Die Information zum Update ist dann zum 26. Mai 2026 aktualisiert worden. Es handelt sich bei CVE-2026-45659 um eine Microsoft SharePoint Remote Code Execution-Schwachstelle.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/27/sharepoint-out-of-band-update-fuer-cve-2026-45659-26-5-2026/&quot;&gt;https://borncity.com/blog/2026/05/27/sharepoint-out-of-band-update-fuer-cve-2026-45659-26-5-2026/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA warnt vor Malware durch Supply-Chain-Attacken&lt;/h3&gt;

Die CISA warnt aktuell vor den jüngst beobachteten Lieferkettenangriffen auf TanStack, Daemon Tools sowie Nx Console, die Malware verteilt haben.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11309253&quot;&gt;https://heise.de/-11309253&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;New Gogs zero-day flaw lets hackers get remote code execution&lt;/h3&gt;

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. [..] This critical severity argument injection security flaw has yet to be assigned a CVE ID, affects the latest release versions (Gogs 0.14.2 and 0.15.0+dev), and can only be exploited by authenticated attackers without admin privileges.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-gogs-zero-day-flaw-lets-hackers-get-remote-code-execution/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-gogs-zero-day-flaw-lets-hackers-get-remote-code-execution/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038&lt;/h3&gt;

An attacker can supply a crafted payload and trigger PHP Object Injection. If a viable gadget chain exists in the site codebase or installed dependencies, this can result in arbitrary PHP code execution. CVE IDs: CVE-2026-9726
&lt;p /&gt;
&lt;A HREF=&quot;https://www.drupal.org/sa-contrib-2026-038&quot;&gt;https://www.drupal.org/sa-contrib-2026-038&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Notepad++: Lücken erlauben Einschleusen von Schadcode und Befehlen&lt;/h3&gt;

Ein weiteres Update steht für Notepad++ bereit. Es schließt drei Sicherheitslücken, von denen zwei als hohes Risiko eingestuft sind und Angreifern ermöglichen, etwa Befehle oder gar Schadcode einzuschmuggeln und auszuführen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Notepad-Luecken-erlauben-Einschleusen-von-Schadcode-und-Befehlen-11309111.html&quot;&gt;https://www.heise.de/news/Notepad-Luecken-erlauben-Einschleusen-von-Schadcode-und-Befehlen-11309111.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VMware Sicherheitsupdates für ESXi 8.0U3j &amp; VSA 8.0U3j&lt;/h3&gt;

VMware by Broadcom hat gerade Sicherheitsupdates für seine Produkte ESXi 8.0U3j sowie VSA 8.0U3J (vSphere Storage Appliance) veröffentlicht. Ergänzung: Es gab in Kommentaren Hinweise, dass Updates ohne Wartungsvertrag nicht installiert werden dürfen.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/28/vmware-sicherheitsupdates-fuer-esxi-8-0u3j-vsa-8-0u3j/&quot;&gt;https://borncity.com/blog/2026/05/28/vmware-sicherheitsupdates-fuer-esxi-8-0u3j-vsa-8-0u3j/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Veeam: Security Fixes and Improvements 2026-05-27&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.veeam.com/knowledge-base.html?type=security&quot;&gt;https://www.veeam.com/knowledge-base.html?type=security&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Joomla: [20260520] - Framework - Inadequate content filtering within the cleanAttributes filter code&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://developer.joomla.org/security-centre/1052-20260520-framework-inadequate-content-filtering-within-the-cleanattributes-filter-code.html&quot;&gt;https://developer.joomla.org/security-centre/1052-20260520-framework-inadequate-content-filtering-within-the-cleanattributes-filter-code.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1075060/&quot;&gt;https://lwn.net/Articles/1075060/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-28T19:39:43Z</dc:date></entry><entry><title>Tageszusammenfassung - 27.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-27052026"/><author><name>CERT.at</name></author><updated>2026-05-27T18:12:09Z</updated><published>2026-05-27T18:12:09Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 26-05-2026 18:00 - Mittwoch 27-05-2026 18:00
Handler:     Guenes Holler
Co-Handler:  Alexander Riepl


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Millions of AI agents imperiled by critical vulnerability in open source package&lt;/h3&gt;

&quot;BadHost&quot; was found in Starlette, a package with 325 million weekly downloads.
&lt;p /&gt;
&lt;A HREF=&quot;https://arstechnica.com/information-technology/2026/05/millions-of-ai-agents-imperiled-by-critical-vulnerability-in-open-source-package/&quot;&gt;https://arstechnica.com/information-technology/2026/05/millions-of-ai-agents-imperiled-by-critical-vulnerability-in-open-source-package/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;KnowledgeDeliver flaw exploited as a zero-day to install web shells&lt;/h3&gt;

Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/knowledgedeliver-flaw-exploited-as-a-zero-day-to-install-web-shells/&quot;&gt;https://www.bleepingcomputer.com/news/security/knowledgedeliver-flaw-exploited-as-a-zero-day-to-install-web-shells/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Messenger-App: Schwachstelle in Signal kann Datenlöschung verhindern&lt;/h3&gt;

Wegen einer Schwachstelle beim Logging von Löschanfragen könnten Signal-Nachrichten auch nach Jahren wiederherstellbar sein.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/messenger-app-schwachstelle-in-signal-kann-datenloeschung-verhindern-2605-209008.html&quot;&gt;https://www.golem.de/news/messenger-app-schwachstelle-in-signal-kann-datenloeschung-verhindern-2605-209008.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;(g+) F5 BIG-IP APM: Ein alter DoS-Patch kehrt als RCE zurück&lt;/h3&gt;

F5 stuft CVE-2025-53521 von DoS auf RCE hoch, Angreifer hatten Zugang zum Quellcode. Die dringendste Frage für Admins: Sind BIG-IP-APM-Instanzen direkt aus dem Internet erreichbar?
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/f5-big-ip-apm-ein-alter-dos-patch-kehrt-als-rce-zurueck-2605-209075.html&quot;&gt;https://www.golem.de/news/f5-big-ip-apm-ein-alter-dos-patch-kehrt-als-rce-zurueck-2605-209075.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries&lt;/h3&gt;

The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/muddywater-uses-dll-side-loading-in.html&quot;&gt;https://thehackernews.com/2026/05/muddywater-uses-dll-side-loading-in.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Gitea Vulnerability Exposes Private Container Images without Authentication&lt;/h3&gt;

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html&quot;&gt;https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure&lt;/h3&gt;

CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/glassworm-malware-takedown-disrupts.html&quot;&gt;https://thehackernews.com/2026/05/glassworm-malware-takedown-disrupts.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Umstrittene Befugnisse: BKA erhält Zugriff auf Angreifer-Infrastruktur&lt;/h3&gt;

Das Kabinett hat den Weg für neue Befugnisse freigemacht: Das Bundeskriminalamt soll künftig IT-Systeme von Angreifern stören oder zerstören dürfen. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Hackback-Erlaubnis-Kabinett-macht-Weg-frei-11308323.html&quot;&gt;https://www.heise.de/news/Hackback-Erlaubnis-Kabinett-macht-Weg-frei-11308323.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake-Anwaltskanzlei: Letzte außergerichtliche Zahlungsaufforderung als Druckmittel&lt;/h3&gt;

Ein angeblich telefonisch abgeschlossenes Abo bei einem Gewinnspielunternehmen. Ausstehende Zahlungen und eine letzte Möglichkeit, die Sache außergerichtlich zu klären. Mit dieser Geschichte wollen Kriminelle ans Geld ihrer Opfer. Die dazugehörige Nachricht vom (Fake-)Anwalt kommt per E-Mail - oder per Post.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/fake-anwaltskanzlei-zahlungsaufforderung/&quot;&gt;https://www.watchlist-internet.at/news/fake-anwaltskanzlei-zahlungsaufforderung/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts - no password required&lt;/h3&gt;

So, youve enabled multi-factor authentication. Youve taught your staff never to type their passwords into dodgy-looking login pages. Surely your Microsoft 365 accounts are safe now? Well, think again.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-kali365-phishing-kit-breaks-microsoft-365-accounts-no-password-required&quot;&gt;https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-kali365-phishing-kit-breaks-microsoft-365-accounts-no-password-required&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;BTMOB: A stealthy RAT burrowing deep into Android devices&lt;/h3&gt;

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
&lt;p /&gt;
&lt;A HREF=&quot;https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/&quot;&gt;https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning&lt;/h3&gt;

Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware and steal data. 
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/&quot;&gt;https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;OverlayPhantom Android Banking Trojan Targets 180+ Financial Apps Across 10 Countries&lt;/h3&gt;

A newly discovered Android banking trojan known as OverlayPhantom is raising concerns among cybersecurity researchers after evidence revealed that the malware is actively targeting banking, financial, and cryptocurrency users across multiple Western countries. 
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/overlayphantom-android-banking-trojan/&quot;&gt;https://thecyberexpress.com/overlayphantom-android-banking-trojan/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Trotz fehlender Patches: Russland setzt weiterhin massiv auf Microsoft Exchange&lt;/h3&gt;

Zahlreiche russische Unternehmen haben wohl noch Exchange und andere westliche Software im Einsatz. Patches bekommen sie dafür aber schon lange nicht mehr. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/trotz-fehlender-patches-russland-setzt-weiterhin-massiv-auf-microsoft-exchange-2605-209083.html&quot;&gt;https://www.golem.de/news/trotz-fehlender-patches-russland-setzt-weiterhin-massiv-auf-microsoft-exchange-2605-209083.html&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Ausnutzung wahrscheinlich: Kritische Nginx-Lücke gefährdet unzählige Webserver&lt;/h3&gt;

Erst vor wenigen Tagen hatten Forscher von Depthfirst eine Nginx Rift genannte Sicherheitslücke in der weit verbreiteten Webserver-Software Nginx aufgedeckt, mit der Angreifer anfällige Systeme temporär unerreichbar machen und manchmal sogar Schadcode zur Ausführung bringen können. Jetzt hat der Nginx-Entwickler F5 noch eine weitere Lücke gepatcht, die weitgehend über die gleichen Eigenschaften verfügt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/ausnutzung-wahrscheinlich-kritische-nginx-luecke-gefaehrdet-unzaehlige-webserver-2605-209060.html&quot;&gt;https://www.golem.de/news/ausnutzung-wahrscheinlich-kritische-nginx-luecke-gefaehrdet-unzaehlige-webserver-2605-209060.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;UniFi OS Server: Kritische Sicherheitslücken ermöglichen Angriffe&lt;/h3&gt;

In der zentralen Verwaltungsplattform und dem Betriebssystem für UniFi-Geräte UniFi OS Server klaffen mehrere Sicherheitslücken - teils mit Höchstwertung beim Risiko. Es stehen Updates zur Verfügung, die die Lücken schließen. Wer betroffene UniFi-Geräte einsetzt, sollte mit dem Installieren der Aktualisierungen nicht lange warten.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/UniFi-OS-Server-Kritische-Sicherheitsluecken-ermoeglichen-Angriffe-11307509.html&quot;&gt;https://www.heise.de/news/UniFi-OS-Server-Kritische-Sicherheitsluecken-ermoeglichen-Angriffe-11307509.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;7-Zip: Update schließt Codeschmuggel-Lücke&lt;/h3&gt;

Das populäre Packprogramm 7-Zip enthält eine Schwachstelle, die das Einschleusen von Schadcode ermöglicht. Ein Update steht bereit. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/7-Zip-Update-schliesst-Codeschmuggel-Luecke-11308241.html&quot;&gt;https://www.heise.de/news/7-Zip-Update-schliesst-Codeschmuggel-Luecke-11308241.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fehler in Docker Model Runner erlaubt Sandboxausbruch unter macOS&lt;/h3&gt;

Nutzen Angreifer eine Sicherheitslücke in Docker unter macOS erfolgreich aus, können sie aus der Sandbox ausbrechen und Schadcode im Hostsystem ausführen. Eine dagegen gerüstete Version steht zum Download bereit.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Fehler-in-Docker-Model-Runner-erlaubt-Sandboxausbruch-unter-macOS-11308267.html&quot;&gt;https://www.heise.de/news/Fehler-in-Docker-Model-Runner-erlaubt-Sandboxausbruch-unter-macOS-11308267.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LiteSpeed cPanel-Plugin: Angriffe auf Schwachstelle beobachtet&lt;/h3&gt;

Im LiteSpeed-Plugin für cPanel klafft eine Sicherheitslücke, die der Hersteller als kritisch einstuft. Die US-amerikanische IT-Sicherheitsbehörde CISA warnt, dass Angriffe darauf beobachtet wurden. Aktualisierte Software steht bereit.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11307435&quot;&gt;https://heise.de/-11307435&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://support.checkpoint.com/results/sk/sk184981&quot;&gt;https://support.checkpoint.com/results/sk/sk184981&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVE-2026-48132 - VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://support.checkpoint.com/results/sk/sk184982&quot;&gt;https://support.checkpoint.com/results/sk/sk184982&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVE-2026-48133 Identity Awareness Captive Portal - Unauthenticated Local File Inclusion&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://support.checkpoint.com/results/sk/sk184993&quot;&gt;https://support.checkpoint.com/results/sk/sk184993&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVE-2026-48134 - SQL injection issue in UserCheck Portal when DLP is active&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://support.checkpoint.com/results/sk/sk184983&quot;&gt;https://support.checkpoint.com/results/sk/sk184983&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://support.checkpoint.com/results/sk/sk184991&quot;&gt;https://support.checkpoint.com/results/sk/sk184991&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://support.checkpoint.com/results/sk/sk184992&quot;&gt;https://support.checkpoint.com/results/sk/sk184992&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1074840/&quot;&gt;https://lwn.net/Articles/1074840/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-27T18:12:09Z</dc:date></entry><entry><title>Tageszusammenfassung - 26.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-26052026"/><author><name>CERT.at</name></author><updated>2026-05-26T18:42:34Z</updated><published>2026-05-26T18:42:34Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 22-05-2026 18:00 - Dienstag 26-05-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Alexander Riepl


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Update #1: Qilin-Ransomware nutzt Initial Access aus ZipLine-Kampagne - DACH-Recruiting-Domains im Fokus&lt;/h3&gt;

Uns sind weitere Köderdomains bekannt geworden, die demselben Muster folgen: valenzsearch[.]at, haasrecruiting[.]at, bergersearch[.]at
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/aktuelles/2026/5/zipline-qilin-raas-update&quot;&gt;https://www.cert.at/de/aktuelles/2026/5/zipline-qilin-raas-update&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Anthropic to release Mythos-class models to the public&lt;/h3&gt;

Anthropic has revealed its intention to one day release models that match the performance of its Mythos bug-finding AI to the public, once it can make them safe.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/05/25/anthropic-to-release-mythos-class-models-to-the-public/5245596&quot;&gt;https://www.theregister.com/security/2026/05/25/anthropic-to-release-mythos-class-models-to-the-public/5245596&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Critical Ghost CMS Vulnerability Exploited to Hack 700+ Websites&lt;/h3&gt;

A critical Ghost CMS vulnerability identified as CVE-2026-26980 has been exploited in a widespread cyber campaign that compromised more than 700 websites, including platforms associated with major institutions such as Harvard University, University of Oxford, and DuckDuckGo. [..] The flaw received a CVSS severity score of 9.4, highlighting the serious risks posed by CVE-2026-26980. The vulnerability was reportedly discovered by Anthropic using its Claude AI system. [..] Investigators noted that a DLL file involved in the campaign carried a compilation timestamp dated February 16, 2026 [..] The malicious activity was first detected on May 7, 2026.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/cve-2026-26980-ghost-cms-vulnerability/&quot;&gt;https://thecyberexpress.com/cve-2026-26980-ghost-cms-vulnerability/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Github: Staged publishing and new install-time controls for NPM&lt;/h3&gt;

Staged publishing is now generally available on npm. Instead of a direct publish that immediately makes a package version available to consumers, the prebuilt tarball is uploaded to a stage queue where a maintainer must explicitly approve it before it becomes installable.
&lt;p /&gt;
&lt;A HREF=&quot;https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/&quot;&gt;https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects&lt;/h3&gt;

Socket researchers identified a coordinated supply chain campaign affecting eight packages on Packagist whose upstream repositories were modified to include the same malicious postinstall script. The script attempted to download a Linux binary from a GitHub Releases URL, save it to /tmp/.sshd, make it executable, and run it in the background.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos&quot;&gt;https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake software on GitHub and SourceForge distribute Deno RAT&lt;/h3&gt;

We found fake installers and plugins for ChatGPT, Claude, AutoTune, and other popular software that can give attackers full control over your device. [..] The infection chain is usually started via MSI files or PowerShell scripts downloaded from GitHub or SourceForge in most of the analyzed cases.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/threat-intel/2026/05/fake-software-on-github-and-sourceforge-distribute-deno-rat&quot;&gt;https://www.malwarebytes.com/blog/threat-intel/2026/05/fake-software-on-github-and-sourceforge-distribute-deno-rat&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Anruf, WhatsApp, QR-Code: Neue Phishing-Masche betrifft Erste Bank Kund:innen&lt;/h3&gt;

Kriminelle geben sich aktuell als Mitarbeitende der Erste Bank aus und fordern ihre Opfer per WhatsApp dazu auf, einen Aktivierungs-QR-Code für George zu übermitteln. Wer den Code weitergibt, ermöglicht den Tätern Zugriff auf das Konto.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/qr-code-erste-bank/&quot;&gt;https://www.watchlist-internet.at/news/qr-code-erste-bank/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Betrüger verschicken seit Monaten Scam-Mails von offizieller Microsoft-Adresse&lt;/h3&gt;

Betrüger können über eine offizielle E-Mailadresse von Microsoft Nachrichten verschicken. Über die selbe Adresse werden auch Codes für die Zwei-Faktor-Authentifzierung versendet. [..] Die genutzte Absenderadresse lautet &quot;msonlineservicesteam@microsoftonline.com&quot;.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.derstandard.at/story/3000000322088/betrueger-verschicken-seit-monaten-scam-mails-von-offizieller-microsoft-adresse&quot;&gt;https://www.derstandard.at/story/3000000322088/betrueger-verschicken-seit-monaten-scam-mails-von-offizieller-microsoft-adresse&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;DBIR 2026: Sicherheitslücken als häufigstes Einfallstor für Angriffe&lt;/h3&gt;

Obwohl der Bericht (DBIR 2026) noch auf Daten aus dem Jahr 2025 basiert und somit vor den jüngsten Fortschritten bei KI-Spitzenmodellen entstanden ist, sind die Trends eindeutig: KI verändert die Cybersicherheitsbranche grundlegend. [..] Fast ein Drittel (31 %) aller Sicherheitsverletzungen beginnt mit der Ausnutzung von Schwachstellen.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/25/dbir-2026-sicherheitsluecken-sind-das-haeufigste-einfallstor-fuer-angriffe/&quot;&gt;https://borncity.com/blog/2026/05/25/dbir-2026-sicherheitsluecken-sind-das-haeufigste-einfallstor-fuer-angriffe/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services&lt;/h3&gt;

While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground.
&lt;p /&gt;
&lt;A HREF=&quot;https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/&quot;&gt;https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Six Signals for Threat Attribution&lt;/h3&gt;

Credible threat attribution weighs six signals together. Each signal has a disciplined methodology behind it, with citations and stress tests to back the conclusions.
&lt;p /&gt;
&lt;A HREF=&quot;https://zeltser.com/six-signals-for-threat-attribution&quot;&gt;https://zeltser.com/six-signals-for-threat-attribution&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Noroboto: Lying fonts and mitigation in Rust&lt;/h3&gt;

The &quot;noroboto.ttf&quot; &quot;lexploit&quot; is straightforward: create a new malicious font definition which is embedded in a document according to the specification and lies about the Unicode representation of its glyphs.
&lt;p /&gt;
&lt;A HREF=&quot;https://tritium.legal/blog/noroboto&quot;&gt;https://tritium.legal/blog/noroboto&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Detection Logic Bugs, Developing Context to Bypass MiniPlasma Rules&lt;/h3&gt;

Recently, because of Nightmare-eclipse-s Green Plasma and MiniPlasma variants, it-s been a busy week. There are tons of community detection rules out there now. But as someone who practices Adversarial Detection Engineering, that is, hunting for bugs in detection logic, you know a small tweaks can bypass detection.
&lt;p /&gt;
&lt;A HREF=&quot;https://detect.fyi/detection-logic-bugs-developing-context-to-bypass-miniplasma-rules-903f1d7c68e8?source=rssd5fd8f494f6a4&quot;&gt;https://detect.fyi/detection-logic-bugs-developing-context-to-bypass-miniplasma-rules-903f1d7c68e8?source=rssd5fd8f494f6a4&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Remove SPNs and Fix Kerberoasting&lt;/h3&gt;

Remediate Kerberoasting vulnerabilities by removing SPNs for accounts that dont need them.
&lt;p /&gt;
&lt;A HREF=&quot;https://projectblack.io/blog/remove-spn-fix-kerberoasting/&quot;&gt;https://projectblack.io/blog/remove-spn-fix-kerberoasting/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NISG 2026: Der praktische 6-Monats-Fahrplan für österreichische Unternehmen&lt;/h3&gt;

Der 1. Oktober 2026 ist kein weiches Zieldatum. Ab diesem Tag gilt das Netz- und Informationssystemsicherheitsgesetz NISG 2026 in Österreich vollumfänglich [..] Dieser Fahrplan zeigt konkret, was in den nächsten 6 Monaten zu tun ist: So, dass ein IT-Verantwortlicher oder eine Geschäftsführerin morgen damit beginnen kann.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zettasecure.com//post//nisg-2026-fahrplan-oesterreich&quot;&gt;https://www.zettasecure.com//post//nisg-2026-fahrplan-oesterreich&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Roundcube: Security updates 1.6.16 and 1.7.1 released&lt;/h3&gt;

We just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.
&lt;p /&gt;
&lt;A HREF=&quot;https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1&quot;&gt;https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Debian SE Linux and PinTheft&lt;/h3&gt;

PinTheft is a Linux local privilege escalation exploit for an RDS zerocopy double-free that can be turned into a page-cache overwrite through io_uring fixed buffers. [..] We duped on this bug with some other teams and a patch is available so we are releasing our PoC.
&lt;p /&gt;
&lt;A HREF=&quot;https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/&quot;&gt;https://etbe.coker.com.au/2026/05/24/debian-selinux-pintheft/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Splunk: SVD-2026-0504: Denial of Service through coldToFrozen.sh Script in Splunk Enterprise&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0504&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0504&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1074443/&quot;&gt;https://lwn.net/Articles/1074443/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Synology-SA-26:10 Synology Chat Server&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.synology.com/en-global/support/security/Synology_SA_26_10&quot;&gt;https://www.synology.com/en-global/support/security/Synology_SA_26_10&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;MISP 2.5.38 - UI and security update&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.misp-project.org/2026/05/26/misp.2.5.38.released.html/&quot;&gt;https://www.misp-project.org/2026/05/26/misp.2.5.38.released.html/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zyxel security advisory for missing authorization vulnerability in GS1200v3 series switches&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-missing-authorization-vulnerability-in-gs1200v3-series-switches-05-26-2026&quot;&gt;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-missing-authorization-vulnerability-in-gs1200v3-series-switches-05-26-2026&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-26T18:42:34Z</dc:date></entry><entry><title>Tageszusammenfassung - 22.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-22052026"/><author><name>CERT.at</name></author><updated>2026-05-22T19:02:00Z</updated><published>2026-05-22T19:02:00Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 21-05-2026 18:00 - Freitag 22-05-2026 18:00
Handler:     Guenes Holler
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Qilin-Ransomware nutzt Initial Access aus ZipLine-Kampagne - DACH-Recruiting-Domains im Fokus&lt;/h3&gt;

Wir haben Hinweise darauf, dass die Ransomware-Gruppe Qilin Initial Access von Akteur:innen der ZipLine-Phishing-Kampagne erwirbt und für eigene Verschlüsselungs- und Erpressungsoperationen weiterverwendet. In Österreich liegen uns bereits bestätigte Fälle vor. [..] Im DACH-Raum sehen wir aktuell vor allem Köderdomains mit Recruiting-Bezug.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/aktuelles/2026/5/zipline-qilin-raas&quot;&gt;https://www.cert.at/de/aktuelles/2026/5/zipline-qilin-raas&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;A hacker group is poisoning open source code at an unprecedented scale&lt;/h3&gt;

GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks. [..] Amid an epidemic of supply chain attacks like the ones TeamPCP has unleashed, Socket-s Burckhardt says open-source users will need to take trust-but-verify measures, like analyzing updates for malware before rolling them out across a network, as well as the kind of -cool-down- period that Read recommends before downloading and running code.
&lt;p /&gt;
&lt;A HREF=&quot;https://arstechnica.com/information-technology/2026/05/a-hacker-group-is-poisoning-open-source-code-at-an-unprecedented-scale/&quot;&gt;https://arstechnica.com/information-technology/2026/05/a-hacker-group-is-poisoning-open-source-code-at-an-unprecedented-scale/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Megalodon: Mass GitHub Repo Backdooring via CI Workflows&lt;/h3&gt;

On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. [..] 5,700+ commits in six hours, 5,561 repositories, one payload: replace a GitHub Actions workflow with a dormant secret exfiltration backdoor. The workflow_dispatch trigger design means these backdoors sit silent until activated, creating no visible CI runs.
&lt;p /&gt;
&lt;A HREF=&quot;https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows&quot;&gt;https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Drupal: Critical SQL injection flaw now targeted in attacks&lt;/h3&gt;

Drupal is warning that hackers are attempting to exploit a &quot;highly critical&quot; SQL injection vulnerability announced earlier this week.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/drupal-critical-sql-injection-flaw-now-targeted-in-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/drupal-critical-sql-injection-flaw-now-targeted-in-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Google API keys keep working after you delete them long enough to be exploited&lt;/h3&gt;

When you delete a Google API key, it says it-s immediately deleted. Our testing says ~23 minutes. During that window, an attacker with a leaked key keeps access to your data and enabled APIs (including Gemini). You have no way to revoke it faster or confirm when it stops working. Google closed our report as -won-t fix-.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.aikido.dev/blog/google-api-keys-deletion&quot;&gt;https://www.aikido.dev/blog/google-api-keys-deletion&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Paved With Intent: ROADtools and Nation-State Tactics in the Cloud&lt;/h3&gt;

Open-source framework ROADtools is being misused by threat actors for cloud intrusions. [..] ROADtools is an open-source framework written in Python and built for red-teaming and research. It primarily targets the identity and authentication layers of Azure, and focuses on how accounts, applications and tokens operate in tenants.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/&quot;&gt;https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA to allow researchers to report vulnerabilities to exploited bugs catalog&lt;/h3&gt;

The Cybersecurity and Infrastructure Security Agency (CISA) announced the creation of a nomination form on Thursday that they said enables -researchers, vendors, and industry partners- to report bugs that need to be added to the Known Exploited Vulnerabilities catalog.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/cisa-to-allow-researchers-to-report-vulnerabilities-kev&quot;&gt;https://therecord.media/cisa-to-allow-researchers-to-report-vulnerabilities-kev&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Ubiquiti patches three max severity UniFi OS vulnerabilities&lt;/h3&gt;

Ubiquiti has released security updates to patch three maximum severity vulnerabilities in Unify OS that can be exploited by remote attackers without privileges. [..]
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/&quot;&gt;https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Trend Micro Apex One und Langflow: Warnung vor Angriffen&lt;/h3&gt;

Die unter Beschuss stehende Schwachstelle in Trend Micros Apex One schließen die Updates aus dem Mai, die der Hersteller am Donnerstag dieser Woche veröffentlicht hat. [..] In Langflow handelt es sich um eine verkettete Schwachstelle, die die Übernahme von Konten und das Ausführen von Schadcode aus dem Netz ermöglicht.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Schwachstellen-in-Trend-Micro-Apex-One-und-Langflow-unter-Beschuss-11303311.html&quot;&gt;https://www.heise.de/news/Schwachstellen-in-Trend-Micro-Apex-One-und-Langflow-unter-Beschuss-11303311.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Notepad++: Update bessert Schwachstelle im Installer aus&lt;/h3&gt;

Notepad++ schließt in der neuen Version 8.9.6 eine Sicherheitslücke im Installer. Die Risikobewertung ist noch nicht eindeutig, ein aufgeführter CVE-Eintrag noch nicht veröffentlicht.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Notepad-Update-bessert-Schwachstelle-im-Installer-aus-11303525.html&quot;&gt;https://www.heise.de/news/Notepad-Update-bessert-Schwachstelle-im-Installer-aus-11303525.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FatGid - FreeBSD 14.x kernel LPE&lt;/h3&gt;

A kernel stack buffer overflow exists in the setcred(2) system call introduced in FreeBSD 14.x. The overflow occurs before any privilege check, allowing any unprivileged local user to trigger arbitrary behaviour ranging from a kernel panic to full local privilege escalation. [..] The FreeBSD Security Team published FreeBSD-SA-26:18.setcred on 2026-05-21 with the assigned identifier CVE-2026-45250. Patches landed across all supported branches on 2026-05-20.
&lt;p /&gt;
&lt;A HREF=&quot;https://fatgid.io/&quot;&gt;https://fatgid.io/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1074040/&quot;&gt;https://lwn.net/Articles/1074040/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Tenable: [R1] Sensor Proxy Version 1.4.0 Fixes Multiple Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.tenable.com/security/tns-2026-15&quot;&gt;https://www.tenable.com/security/tns-2026-15&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Openwall: CVE-2026-47243: Kata Containers guest-root to host-root escape via virtiofs&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.openwall.com/lists/oss-security/2026/05/21/14&quot;&gt;https://www.openwall.com/lists/oss-security/2026/05/21/14&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-22T19:02:00Z</dc:date></entry><entry><title>Tageszusammenfassung - 21.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-21052026"/><author><name>CERT.at</name></author><updated>2026-05-21T18:48:12Z</updated><published>2026-05-21T18:48:12Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 20-05-2026 18:00 - Donnerstag 21-05-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Hackers bypass SonicWall VPN MFA due to incomplete patching&lt;/h3&gt;

Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. [..] SonicWall warned in a security advisory for CVE-2024-12802 that installing the firmware update alone on Gen6 devices does not fully mitigate the vulnerability, and a manual reconfiguration of the LDAP server is required. Failing to do so leaves open the possibility of bypassing MFA protection.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching/&quot;&gt;https://www.bleepingcomputer.com/news/security/hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400&lt;/h3&gt;

Between May 9 and May 18, 2026, GreyNoise observed a significant new spike in scanning of SonicWall SonicOS management interfaces. The May 12 peak - approximately 597,000 sessions - was the largest single-day total recorded on the SonicWall SonicOS API Scanner tag in the past 90 days, roughly 46× the typical daily volume for this tag in the 30 days before the elevation.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400&quot;&gt;https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Google publishes exploit code threatening millions of Chromium users&lt;/h3&gt;

Google on Wednesday published exploit code for an unfixed vulnerability in its Chromium browser codebase [..] The proof-of-concept code exploits the Browser Fetch programming interface, a standard that allows long videos and other large files to be downloaded in the background. An attacker can use the exploit to create a connection for monitoring some aspects of a user-s browser usage and as a proxy for viewing sites and launching denial-of-service attacks. [..] The unfixed vulnerability can be exploited by any website a user visits. [..] Users of Chromium browsers should be suspicious of download dropdowns that appear for no reason.
&lt;p /&gt;
&lt;A HREF=&quot;https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/&quot;&gt;https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach&lt;/h3&gt;

Users of the Myspace93 parody web art site be warned: the dataset spilled after a reported breach in 2021 included the plaintext usernames and passwords of more than 46,000 registered users. [..] In addition to the clear-as-day passwords and usernames, HIBP said email addresses and IP addresses were also among the exposed data.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/05/21/46k-plaintext-passwords-pwned-in-myspace93-breach/5244024&quot;&gt;https://www.theregister.com/security/2026/05/21/46k-plaintext-passwords-pwned-in-myspace93-breach/5244024&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The npm Threat Landscape: Attack Surface and Mitigations (Updated May 20)&lt;/h3&gt;

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. 
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/&quot;&gt;https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Webworm: New burrowing techniques&lt;/h3&gt;

ESET researchers analyzed the 2025 activity of Webworm, a China-aligned APT group that started out targeting organizations in Asia, but has recently shifted its focus to Europe.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/&quot;&gt;https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Europe dismantles VPN service used by cybercriminals to hide ransomware attacks&lt;/h3&gt;

The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way for criminals to evade law enforcement.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/europe-dismantles-first-vpn&quot;&gt;https://therecord.media/europe-dismantles-first-vpn&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft warnt vor Defender 0-Days und patcht&lt;/h3&gt;

Microsoft hat zum 19. Mai 2026 zwei 0-Day-Schwachstellen CVE-2026-41091 und CVE-2026-45498 im Defender durch Update der Defender Antimalware Platform geschlossen. Die Schwachstellen betrafen die Defender Antimalware Platform Version 4.18.26030.3011 und älter.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/21/microsoft-warnt-vor-defender-0-days-und-patcht/&quot;&gt;https://borncity.com/blog/2026/05/21/microsoft-warnt-vor-defender-0-days-und-patcht/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740&lt;/h3&gt;

For this post, we're going to look at the last of the four unpatchable Kubernetes CVEs, CVE-2021-25740, which relates to how Kubernetes ingress or LoadBalancer features can be abused to bypass network security controls in a cluster.
&lt;p /&gt;
&lt;A HREF=&quot;https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2021-25740/&quot;&gt;https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2021-25740/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Sicherheitspatches Atlassian: Bamboo, Confluence &amp; Co. sind verwundbar&lt;/h3&gt;

Angreifer können an mehreren Softwareschwachstellen unter anderem in Atlassian Bamboo Data Center and Server, Confluence Data Center and Server und Jira Data Center and Server ansetzen und betroffene Systeme im schlimmsten Fall vollständig kompromittieren. Sicherheitsupdates sind verfügbar.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Sicherheitspatches-Atlassian-Bamboo-Confluence-Co-sind-verwundbar-11301596.html&quot;&gt;https://www.heise.de/news/Sicherheitspatches-Atlassian-Bamboo-Confluence-Co-sind-verwundbar-11301596.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Grafikkartentreiber von Nvidia unter Linux und Windows angreifbar&lt;/h3&gt;

Nutzen Angreifer Schwachstellen im Grafikkartentreiber von Nvidia erfolgreich aus, können sie Dienste abstürzen lassen, unbefugt auf Informationen zugreifen oder sogar Schadcode ausführen. Dagegen stehen abgesicherte Versionen für Linux und Windows zum Download bereit. Weiterhin haben die Entwickler Lücken in der vGPU-Software geschlossen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Grafikkartentreiber-von-Nvidia-unter-Linux-und-Windows-angreifbar-11301854.html&quot;&gt;https://www.heise.de/news/Grafikkartentreiber-von-Nvidia-unter-Linux-und-Windows-angreifbar-11301854.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Kritische Sicherheitslücke in Drupal Core - Updates verfügbar&lt;/h3&gt;

In Drupal Core existiert eine SQL-Injection-Schwachstelle in der Datenbank-Abstraktions-API. Speziell gestaltete Anfragen können zu beliebigen SQL-Injections führen. Die Schwachstelle ist ausschließlich für Drupal-Installationen relevant, die PostgreSQL als Datenbank einsetzen, und kann ohne Authentifizierung durch anonyme Benutzer:innen ausgenutzt werden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/warnungen/2026/5/kritische-sicherheitslucke-in-drupal-core-updates-verfugbar&quot;&gt;https://www.cert.at/de/warnungen/2026/5/kritische-sicherheitslucke-in-drupal-core-updates-verfugbar&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Secure Workload Unauthorized API Access Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Splunk: SVD-2026-0515: Third-Party Package Updates in Splunk User Behavior Analytics - May 2026&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://advisory.splunk.com//advisories/SVD-2026-0515&quot;&gt;https://advisory.splunk.com//advisories/SVD-2026-0515&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1073860/&quot;&gt;https://lwn.net/Articles/1073860/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-21T18:48:12Z</dc:date></entry><entry><title>Tageszusammenfassung - 20.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-20052026"/><author><name>CERT.at</name></author><updated>2026-05-20T19:14:43Z</updated><published>2026-05-20T19:14:43Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 19-05-2026 18:00 - Mittwoch 20-05-2026 18:00
Handler:     Guenes Holler
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Datenklau: Hacker wollen 4.000 private Github-Repos geplündert haben&lt;/h3&gt;

Die Cybergang TeamPCP setzt Github unter Druck. Sie will an Daten aus Tausenden privaten Code-Repos gelangt sein und stellt diese nun zum Verkauf.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/datenklau-hacker-wollen-4-000-private-github-repos-gepluendert-haben-2605-208851.html&quot;&gt;https://www.golem.de/news/datenklau-hacker-wollen-4-000-private-github-repos-gepluendert-haben-2605-208851.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft shares mitigation for YellowKey Windows zero-day&lt;/h3&gt;

Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/&quot;&gt;https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Stealer Spoofs Google, Microsoft &amp; Apple, Then Backdoors macOS&lt;/h3&gt;

The SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.darkreading.com/threat-intelligence/stealer-spoofs-google-microsoft-apple-backdoors-macos&quot;&gt;https://www.darkreading.com/threat-intelligence/stealer-spoofs-google-microsoft-apple-backdoors-macos&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)&lt;/h3&gt;

We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/exiftool-compromise-mac/119866/&quot;&gt;https://securelist.com/exiftool-compromise-mac/119866/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps&lt;/h3&gt;

Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.The activity, per HUMANs Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control (C2) domains, turning the infrastructure into a pipeline for multi-stage fraud.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/trapdoor-android-ad-fraud-scheme-hit.html&quot;&gt;https://thehackernews.com/2026/05/trapdoor-android-ad-fraud-scheme-hit.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware&lt;/h3&gt;

Thousands of US victims, including 12+ machines owned and operated by Redmond.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/05/19/microsoft-disrupts-alleged-malware-signing-operation-used-by-ransomware-gangs/5243013&quot;&gt;https://www.theregister.com/security/2026/05/19/microsoft-disrupts-alleged-malware-signing-operation-used-by-ransomware-gangs/5243013&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Neue Phishing-Masche: Gutschrift nach &quot;Fehler&quot; von booking.com als Köder&lt;/h3&gt;

Kriminelle versenden via WhatsApp Nachrichten, in denen sie sich als Gästebetreuung eines Hotels ausgeben und eine Rückbuchung versprechen. Angeblich sei aufgrund eines technischen Fehlers bei booking.com ein falscher Betrag eingezogen worden. Besonders problematisch: Die Eckdaten stimmen mit einer echten Buchung überein! Wer der aufgebauten Falle folgt, liefert den Drahtziehern seine Logindaten fürs Onlinebanking.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/phishing-gutschrift-booking/&quot;&gt;https://www.watchlist-internet.at/news/phishing-gutschrift-booking/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Tracking TamperedChef Clusters via Certificate and Code Reuse&lt;/h3&gt;

Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/&quot;&gt;https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Huawei zero-day attack behind last year-s crash of Luxembourgs entire telecoms network&lt;/h3&gt;

There is no evidence that the incident has recurred, but the flaw remains unexplained and has not been publicly acknowledged by the company.
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/huawei-zero-day-behind-last-year-luxembourg-telecom-outage&quot;&gt;https://therecord.media/huawei-zero-day-behind-last-year-luxembourg-telecom-outage&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;How OLTs may have exposed entire ISP networks&lt;/h3&gt;

This is the fifteenth article I have written over the past three years at Quarkslab, and without a doubt, it has been the most thrilling and fun to put together. The hidden world of ISP (Internet Service Provider) network security might sound complex, but what I am about to reveal could shake up how you see network defenses. In this post, I dive deep into how vulnerabilities in critical devices can lead to the complete takeover of service provider networks.
&lt;p /&gt;
&lt;A HREF=&quot;http://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html&quot;&gt;http://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;durabletask: TeamPCPs Latest PyPi Compromise&lt;/h3&gt;

Discover the latest on malicious versions of the pypi package durabletask, matching TeamPCP tactics.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack&quot;&gt;https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor&lt;/h3&gt;

Sockets Threat Research Team identified a malicious Go module published as github.com/shopsprint/decimal, a typosquat of the widely used github.com/shopspring/decimal arbitrary precision arithmetic library. The typosquatted module has been present on the Go ecosystem since 2017-11-08 and was weaponized on 2023-08-19 when version v1.3.3 added a malicious init() function that opens a DNS TXT record command and control channel to a threat actor controlled subdomain on a free dynamic DNS provider.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/popular-go-decimal-library-typosquat-dns-backdoor?utm_medium=feed&quot;&gt;https://socket.dev/blog/popular-go-decimal-library-typosquat-dns-backdoor?utm_medium=feed&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Max-severity flaw in ChromaDB for AI apps allows server hijacking&lt;/h3&gt;

A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/&quot;&gt;https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Node.js: Vier kritische Sicherheitslücken mit Höchstwertung in vm2 geschlossen&lt;/h3&gt;

Angreifer können abermals aus der Node.js-Sandbox vm2 ausbrechen und Schadcode im Hostsystem ausführen. Sicherheitsupdates schaffen Abhilfe.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Node-js-Vier-kritische-Sicherheitsluecken-mit-Hoechstwertung-in-vm2-geschlossen-11300256.html&quot;&gt;https://www.heise.de/news/Node-js-Vier-kritische-Sicherheitsluecken-mit-Hoechstwertung-in-vm2-geschlossen-11300256.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hunderte bösartige npm-Pakete im AntV-Ökosystem entdeckt&lt;/h3&gt;

In einer neuen Mini-Shai-Hulud-Lieferkettenattacke haben Bedrohungsakteure am 19. Mai mehr als 600 bösartige Versionen von npm-Paketen verbreitet. Hauptziel der Attacke war das Datenvisualisierungs-Ökosystem AntV. Die infizierten Versionen sind mittlerweile entfernt.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11300242&quot;&gt;https://heise.de/-11300242&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1073713/&quot;&gt;https://lwn.net/Articles/1073713/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;MISP 2.5.38 - UI and security update&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://github.com/MISP/MISP/releases/tag/v2.5.38&quot;&gt;https://github.com/MISP/MISP/releases/tag/v2.5.38&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-20T19:14:43Z</dc:date></entry><entry><title>Tageszusammenfassung - 19.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-19052026"/><author><name>CERT.at</name></author><updated>2026-05-19T19:01:29Z</updated><published>2026-05-19T19:01:29Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 18-05-2026 18:00 - Dienstag 19-05-2026 18:00
Handler:     Guenes Holler
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Vorankündigung: Kritische Sicherheitslücke in Drupal Core - Patch-Verfügbarkeit am 20. Mai 2026&lt;/h3&gt;

Drupal hat eine Vorankündigung (Pre-Announcement) zu einer als kritisch eingestuften Sicherheitslücke in Drupal Core veröffentlicht. Für alle unterstützten Versionszweige wird am 20. Mai 2026 zwischen 19:00 und 23:00 CEST eine Sicherheitsaktualisierung bereitgestellt. Zum Zeitpunkt dieser Vorankündigung sind noch keine Details zur Schwachstelle und kein Patch verfügbar.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/aktuelles/2026/5/drupal-critical-preannounce&quot;&gt;https://www.cert.at/de/aktuelles/2026/5/drupal-critical-preannounce&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials&lt;/h3&gt;

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/github-actions-supply-chain-attack.html&quot;&gt;https://thehackernews.com/2026/05/github-actions-supply-chain-attack.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer&lt;/h3&gt;

Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has more than 2.2 million installations.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/compromised-nx-console-18950-targeted.html&quot;&gt;https://thehackernews.com/2026/05/compromised-nx-console-18950-targeted.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability&lt;/h3&gt;

Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE).
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html&quot;&gt;https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cyberangriff Grafana: Erpresser kopieren Sourcecode und drohen mit Leak&lt;/h3&gt;

Grafana Labs ist Opfer einer Cyberattacke geworden. Dabei hatten Angreifer Zugriff auf die Codebasis von Grafana. Darunter fallen alle zu einem Projekt gehörenden Quelltext- und Konfigurationsdateien. Also offensichtlich mehr, als die Open-Source-Anwendung auf GitHub ohnehin öffentlich preisgibt. [..] Die Entwickler versichern, dass nach jetzigem Kenntnisstand keine Kundendaten oder persönliche Daten von Mitarbeitern von dem Vorfall betroffen sind.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Cyberattacke-Angreifer-kopieren-Sourcecode-von-Grafana-11298389.html&quot;&gt;https://www.heise.de/news/Cyberattacke-Angreifer-kopieren-Sourcecode-von-Grafana-11298389.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA Admin Leaked AWS GovCloud Keys on Github&lt;/h3&gt;

Until this past weekend, a contractor for the Cybersecurity &amp; Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.
&lt;p /&gt;
&lt;A HREF=&quot;https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/&quot;&gt;https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;32-jähriger SMS-Betrüger in Wien festgenommen&lt;/h3&gt;

Ermittlern des Landeskriminalamts Wien ist ein Schlag gegen mutmaßliche Cyberkriminelle gelungen, die über sogenannte &quot;SMS Blaster&quot; millionenfach betrügerische Phishing-SMS versendet haben sollen. Seit dem 6. April sollen die Phishing-SMS insbesondere bei größeren Veranstaltungen verschickt worden sein. Am 14. Mai wurde ein Verdächtiger ausgeforscht und von Cobra-Beamten festgenommen. [..] Bei den eingesetzten Geräten handelt es sich um sogenannte &quot;SMS Blaster&quot;. Das Gerät imitiert Mobilfunkzellen oder nutzt Mobilfunknetze automatisiert. Damit können tausende Nachrichten gleichzeitig an Mobiltelefone in der Umgebung gesendet werden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.derstandard.at/story/3000000321362/32-jaehriger-sms-betrueger-in-wien-festgenommen&quot;&gt;https://www.derstandard.at/story/3000000321362/32-jaehriger-sms-betrueger-in-wien-festgenommen&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Details Storm-2949 Cloud Attack on Azure and Microsoft 365&lt;/h3&gt;

Microsoft Threat Intelligence has disclosed details of a cyberattack carried out by a threat actor tracked as Storm-2949, which escalated from a targeted identity compromise into a large-scale breach of cloud infrastructure and sensitive enterprise systems. The campaign focused heavily on data theft from Microsoft 365 services, Azure-hosted production environments, and cloud storage resources, demonstrating how compromised identities can become gateways to an organization-s entire cloud ecosystem.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/microsoft-storm-2949-azure-m365-cloud-breach/&quot;&gt;https://thecyberexpress.com/microsoft-storm-2949-azure-m365-cloud-breach/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;When Filenames Become Attack Surfaces: Weaponizing NASAs CFITSIO Extended Filename Syntax&lt;/h3&gt;

This research was recently presented at BSides Luxembourg 2026. This blogpost documents our findings presented during the talk. [..] We-ll focus on perfectly documented features, useful during file processing, but chained together to achieve some unexpected offensive primitives.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.doyensec.com/2026/05/19/cfitsio-weaponized-filenames.html&quot;&gt;https://blog.doyensec.com/2026/05/19/cfitsio-weaponized-filenames.html&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access&lt;/h3&gt;

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. [..] One significant hurdle that an attacker must overcome to achieve remote code execution is that syslogd re-reads the configuration only upon receiving the SIGHUP (aka &quot;signal hang up&quot;) signal.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/seppmail-secure-e-mail-gateway.html&quot;&gt;https://thehackernews.com/2026/05/seppmail-secure-e-mail-gateway.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Linux kernel flaw opens root-only files to unprivileged users&lt;/h3&gt;

Despite its official designation, a demo exploit on GitHub calls it ssh-keysign-pwn. It is not quite as catchy a name as Copy Fail, or Dirty Frag, or indeed Fragnesia, but we feel it is safe to say it hasn't been a good month. [..] The good news is that it's already been fixed [..] This time, the culprit is CVE-2026-46333, a local kernel vulnerability that lets an unprivileged user read files they should not be able to access, including those normally available only to root. An attacker who already has login access to an affected machine could therefore potentially grab SSH keys, password files, or other confidential credentials.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/security/2026/05/18/linux-kernel-flaw-opens-root-only-files-to-unprivileged-users/5241950&quot;&gt;https://www.theregister.com/security/2026/05/18/linux-kernel-flaw-opens-root-only-files-to-unprivileged-users/5241950&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;TYPO3 Security Advisories 19.05.2026&lt;/h3&gt;

TYPO3 has release security advisories for ceselector, tt_address, ke_search, news, crawler and sf_register.
&lt;p /&gt;
&lt;A HREF=&quot;https://typo3.org/security&quot;&gt;https://typo3.org/security&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mozilla Foundation Security Advisories for Firefox 19.05.2026&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.mozilla.org/en-US/security/advisories/&quot;&gt;https://www.mozilla.org/en-US/security/advisories/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1073542/&quot;&gt;https://lwn.net/Articles/1073542/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;DFIR-IRIS advisories&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://github.com/sbaresearch/advisories/commit/3b38de4446b06c28191ae872bb51bae12360b7ae&quot;&gt;https://github.com/sbaresearch/advisories/commit/3b38de4446b06c28191ae872bb51bae12360b7ae&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-19T19:01:29Z</dc:date></entry><entry><title>Tageszusammenfassung - 18.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-18052026"/><author><name>CERT.at</name></author><updated>2026-05-18T19:00:25Z</updated><published>2026-05-18T19:00:25Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 15-05-2026 18:00 - Montag 18-05-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing&lt;/h3&gt;

The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/&quot;&gt;https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Recent Kernel exploits, attack surface reduction, example IPSEC&lt;/h3&gt;

Multiple of the recent kernel exploits have affected the &quot;esp&quot; Linux Kernel module. ESP is, as far as I understand, part of IPSEC, and I think it's fair to say that IPSEC is not widely used these days.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.openwall.com/lists/oss-security/2026/05/16/3&quot;&gt;https://www.openwall.com/lists/oss-security/2026/05/16/3&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE&lt;/h3&gt;

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the vulnerability was introduced in 2008.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html&quot;&gt;https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Edge: Keine Klartext-Passwörter mehr im Browserprozess&lt;/h3&gt;

Microsofts Edge hatte alle Passwörter aus dem Passwort-Manager beim Start geladen und im Klartext vorgehalten. Jetzt aber nicht mehr.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Microsoft-Edge-Keine-Klartext-Passwoerter-mehr-im-Browserprozess-11296765.html&quot;&gt;https://www.heise.de/news/Microsoft-Edge-Keine-Klartext-Passwoerter-mehr-im-Browserprozess-11296765.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft rejects critical Azure vulnerability report, no CVE issued&lt;/h3&gt;

A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and that &quot;no product changes were made,&quot; despite the researcher documenting a silent fix.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/microsoft-rejects-critical-azure-vulnerability-report-no-cve-issued/&quot;&gt;https://www.bleepingcomputer.com/news/security/microsoft-rejects-critical-azure-vulnerability-report-no-cve-issued/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake-Mail: Angebliche PayPal-Zahlung führt in Phishing-Falle&lt;/h3&gt;

Derzeit sind betrügerische E-Mails im Umlauf, die angeblich von PayPal stammen und eine hohe Zahlung melden. Wer erschrickt und unüberlegt klickt, landet auf einer Fake-Website!
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/angebliche-paypal-zahlung-klicks/&quot;&gt;https://www.watchlist-internet.at/news/angebliche-paypal-zahlung-klicks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4&lt;/h3&gt;

Hackers are hiding XWorm malware in PyInstaller files to bypass Windows security, steal data and remotely control devices through ads.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4/&quot;&gt;https://hackread.com/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Welcome to BlackFile: Inside a Vishing Extortion Operation&lt;/h3&gt;

Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the &quot;BlackFile&quot; brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise.
&lt;p /&gt;
&lt;A HREF=&quot;https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/&quot;&gt;https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Forscher eskaliert: Gefährlicher Zero-Day-Exploit für Windows geleakt&lt;/h3&gt;

Der Miniplasma genannte Exploit nutzt eine Windows-Lücke aus, die eigentlich schon seit 2020 gepatcht sein sollte. Das ist offenkundig nicht der Fall. [..] Der unter dem Namen Chaotic Eclipse bekannte Sicherheitsforscher, der zuletzt mehrere ungepatchte Lücken in Windows aufgedeckt hatte, hat dafür einen neuen Exploit veröffentlicht. Angreifer sollen damit unter Windows Systemrechte erlangen können. [..] Chaotic Eclipse hat ihn nach eigenen Angaben unter Windows 11 und Windows Server 2025 getestet. In beiden Fällen soll er trotz aktuellen Patch-Standes funktionieren und eine Shell mit Systemrechten starten. Der Forscher geht davon aus, dass alle Windows-Versionen betroffen sind.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/forscher-eskaliert-gefaehrlicher-zero-day-exploit-fuer-windows-geleakt-2605-208755.html&quot;&gt;https://www.golem.de/news/forscher-eskaliert-gefaehrlicher-zero-day-exploit-fuer-windows-geleakt-2605-208755.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Exchange: Zero-Day-Lücke wird angegriffen&lt;/h3&gt;

In der Schwachstellenbeschreibung erklärt Microsoft, dass es sich um unzureichende Filterung von Eingaben bei der Generierung von Webseiten handelt, eine Cross-Site-Scripting-Lücke. Dadurch können nicht authentifizierte Angreifer aus dem Netz Spoofing-Angriffe ausführen (CVE-2026-42897, CVSS 8.1, Risiko -hoch-). Den Schweregrad stuft Microsoft jedoch als -kritisch- ein. Ein Blog-Beitrag von Microsofts Exchange-Team erklärt das sowie die Gegenmaßnahmen etwas ausführlicher.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Microsoft-Exchange-Zero-Day-Luecke-wird-angegriffen-11295799.html&quot;&gt;https://www.heise.de/news/Microsoft-Exchange-Zero-Day-Luecke-wird-angegriffen-11295799.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Authenticator: Kritische Sicherheitslücke ermöglicht Token-Diebstahl&lt;/h3&gt;

Microsoft warnt vor einer Sicherheitslücke im Authenticator. Angreifer können Sign-in-Token abgreifen und damit Zugriff erlangen. [..] Zum Missbrauch der Lücke müssen Angreifer ein Opfer dazu bringen, mit einer legitim erscheinenden, bösartigen Anfrage zu interagieren. [..] Aktualisierte Versionen des Authenticators von Microsoft stehen in den jeweiligen App-Stores bereit.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Microsoft-Authenticator-Kritische-Sicherheitsluecke-ermoeglicht-Token-Diebstahl-11296717.html&quot;&gt;https://www.heise.de/news/Microsoft-Authenticator-Kritische-Sicherheitsluecke-ermoeglicht-Token-Diebstahl-11296717.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;PostgreSQL: Updates stopfen hochriskante Sicherheitslecks&lt;/h3&gt;

Die Entwickler von PostgreSQL schreiben in einer Versionsankündigung, dass die neu verfügbaren Fassungen 18.4, 17.10, 16.14, 15.18 und 14.23 insgesamt elf Schwachstellen ausbessern.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/PostgreSQL-Updates-stopfen-hochriskante-Sicherheitslecks-11297485.html&quot;&gt;https://www.heise.de/news/PostgreSQL-Updates-stopfen-hochriskante-Sicherheitslecks-11297485.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1073356/&quot;&gt;https://lwn.net/Articles/1073356/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-18T19:00:25Z</dc:date></entry><entry><title>Tageszusammenfassung - 15.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-15052026"/><author><name>CERT.at</name></author><updated>2026-05-15T18:24:10Z</updated><published>2026-05-15T18:24:10Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 13-05-2026 18:00 - Freitag 15-05-2026 18:00
Handler:     Guenes Holler
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;West Pharmaceutical says hackers stole data, encrypted systems&lt;/h3&gt;

West Pharmaceutical Services disclosed that it was the target of a cyberattack that resulted in data exfiltration and system encryption.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/west-pharmaceutical-says-hackers-stole-data-encrypted-systems/&quot;&gt;https://www.bleepingcomputer.com/news/security/west-pharmaceutical-says-hackers-stole-data-encrypted-systems/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;KongTuke hackers now use Microsoft Teams for corporate breaches&lt;/h3&gt;

Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/&quot;&gt;https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution&lt;/h3&gt;

Stolen browser sessions and authentication tokens are becoming more valuable than stolen passwords. Flare explains how the REMUS infostealer evolved around session theft and operational scalability.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution/&quot;&gt;https://www.bleepingcomputer.com/news/security/inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;SOHO router attack by APT28&lt;/h3&gt;

Few weeks ago, one particular large scale cyber-attack hit the mainstream news everywhere. Russian cyber actor APT28 attacked SOHO routers and managed to compromise some credentials through that. The attack itself was carried in multiple phases and was quite interesting.
&lt;p /&gt;
&lt;A HREF=&quot;https://en.blog.nic.cz/2026/05/14/soho-router-attack-by-apt28/&quot;&gt;https://en.blog.nic.cz/2026/05/14/soho-router-attack-by-apt28/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Kimsuky targets organizations with PebbleDash-based tools&lt;/h3&gt;

Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/kimsuky-appleseed-pebbledash-campaigns/119785/&quot;&gt;https://securelist.com/kimsuky-appleseed-pebbledash-campaigns/119785/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;How AI Hallucinations Are Creating Real Security Risks&lt;/h3&gt;

AI hallucinations are introducing serious security risks into critical infrastructure decision-making by exploiting human trust through highly confident yet incorrect outputs.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/how-ai-hallucinations-are-creating-real.html&quot;&gt;https://thehackernews.com/2026/05/how-ai-hallucinations-are-creating-real.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure&lt;/h3&gt;

Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of its public disclosure.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/praisonai-cve-2026-44338-auth-bypass.html&quot;&gt;https://thehackernews.com/2026/05/praisonai-cve-2026-44338-auth-bypass.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FrostyNeighbor: Fresh mischief and digital shenanigans&lt;/h3&gt;

ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group-s continual cyberespionage operations.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/&quot;&gt;https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Device Code Phishing via Fake File-Sharing Invitation&lt;/h3&gt;

Truesec has observed a phishing attempt where a customer received an email claiming that a sender wanted to share a document. The message prompted the recipient to click -Open-, which redirected the user to a website designed to appear legitimate.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.truesec.com/hub/blog/device-code-phishing-via-fake-file-sharing-invitation&quot;&gt;https://www.truesec.com/hub/blog/device-code-phishing-via-fake-file-sharing-invitation&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage&lt;/h3&gt;

A new Darktrace report reveals how Chinese hackers use fake Apple and Yahoo sites and the FDMTP malware framework to spy on organisations. 
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/chinatwill-typhoon-fake-apple-yahoo-sites-espionage/&quot;&gt;https://hackread.com/chinatwill-typhoon-fake-apple-yahoo-sites-espionage/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit&lt;/h3&gt;

Bitdefender Labs reveals how the China-linked FamousSparrow hacking group targeted an Azerbaijani energy firm using ProxyNotShell, Deed RAT, and Terndoor malware across three persistent waves.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/famoussparrow-oil-gas-ms-exchange-server-exploit/&quot;&gt;https://hackread.com/famoussparrow-oil-gas-ms-exchange-server-exploit/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions&lt;/h3&gt;

Hackers are exploiting Outlook calendar invites and device code phishing to steal M365 session tokens, bypass MFA and breach enterprise accounts. 
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/&quot;&gt;https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Anatomy of a WooCommerce Skimmer: A Technical Deep-Dive&lt;/h3&gt;

One malicious change to a trusted JavaScript file can turn your checkout page into a silent credit-card skimmer, siphoning customer data off to criminals while the website looks secure and continues to work as normal. That creates serious organisational risk: PCI exposure, regulatory consequences, reputational damage, and a breach that remains invisible until long after the damage is done.
&lt;p /&gt;
&lt;A HREF=&quot;https://scotthelme.ghost.io/anatomy-of-a-woocommerce-skimmer-a-technical-deep-dive/&quot;&gt;https://scotthelme.ghost.io/anatomy-of-a-woocommerce-skimmer-a-technical-deep-dive/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Backdoored Cemu release linked to TanStack and Mistral supply chain campaign&lt;/h3&gt;

We investigate how a coordinated supply chain campaign that compromised npm and PyPI packages also backdoored the official Cemu Nintendo Wii U emulator GitHub release, reaching nearly 20,000 Linux users.
&lt;p /&gt;
&lt;A HREF=&quot;https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/&quot;&gt;https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Backdoored node-ipc npm releases steal developer credentials through DNS queries&lt;/h3&gt;

An analysis of backdoored node-ipc npm releases that add an obfuscated credential collection and DNS exfiltration payload to the CommonJS entrypoint.
&lt;p /&gt;
&lt;A HREF=&quot;https://securitylabs.datadoghq.com/articles/node-ipc-npm-malware-analysis/&quot;&gt;https://securitylabs.datadoghq.com/articles/node-ipc-npm-malware-analysis/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New critical Exim mailer flaw allows remote code execution&lt;/h3&gt;

A critical vulnerability affecting certain configurations of the Exim open-source mail transfer agent could be exploited by an unauthenticated remote attacker to execute arbitrary code.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Fragnesia: Schon wieder gefährliche Root-Lücke im Linux-Kernel&lt;/h3&gt;

Dirty Frag und Copy Fail beschäftigen bereits unzählige Linux-Admins. Die nächste Root-Lücke ist bereits identifiziert - und die Patches sind spät dran.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/fragnesia-schon-wieder-gefaehrliche-root-luecke-im-linux-kernel-2605-208702.html&quot;&gt;https://www.golem.de/news/fragnesia-schon-wieder-gefaehrliche-root-luecke-im-linux-kernel-2605-208702.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Webserver gefährdet: 18 Jahre alte Sicherheitslücke in Nginx entdeckt&lt;/h3&gt;

Nginx-Webserver sollen sich durch eine seit 2008 präsente Lücke zum Absturz bringen lassen. Manchmal ist wohl auch eine Schadcodeausführung möglich.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/webserver-gefaehrdet-18-jahre-alte-sicherheitsluecke-in-nginx-entdeckt-2605-208713.html&quot;&gt;https://www.golem.de/news/webserver-gefaehrdet-18-jahre-alte-sicherheitsluecke-in-nginx-entdeckt-2605-208713.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Update stopft 79 Sicherheitslücken in Google Chrome&lt;/h3&gt;

Das wöchentliche Chrome-Update schließt insgesamt 79 Sicherheitslücken. Davon gelten 14 als kritisch. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Update-stopft-79-Sicherheitsluecken-in-Google-Chrome-11294547.html&quot;&gt;https://www.heise.de/news/Update-stopft-79-Sicherheitsluecken-in-Google-Chrome-11294547.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Jetzt patchen! Angreifer attackieren Cisco Catalyst SD-WAN Controller&lt;/h3&gt;

Angreifer nutzen derzeit eine kritische Sicherheitslücke in Cisco Catalyst SD-WAN Controller aus. Sicherheitsupdates sind verfügbar. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11294491&quot;&gt;https://heise.de/-11294491&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ivanti EPM: Sicherheitslücken ermöglichen SQL-Iinjection und Rechteausweitung&lt;/h3&gt;

Ivanti warnt vor drei Sicherheitslücken im Endpoint Manager (EPM). Sie ermöglichen SQL-Injection oder Rechteausweitung. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11294605&quot;&gt;https://heise.de/-11294605&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VMware Fusion: Angreifer können sich root-Rechte verschaffen&lt;/h3&gt;

Nutzen Angreifer eine Schwachstelle in VMware Fusion erfolgreich aus, können sie sich unter bestimmten Bedingungen Root-Nutzerrechte verschaffen. Nun haben die Entwickler die Lücke geschlossen.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11294685&quot;&gt;https://heise.de/-11294685&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;F5 BIG-IP: Quartalssicherheitsupdate schließt zahlreiche Lücken&lt;/h3&gt;

Der Netzwerkausrüster F5 hat unter anderem für verschiedene BIG-IP-Produkte wichtige Sicherheitsupdates veröffentlicht.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11294929&quot;&gt;https://heise.de/-11294929&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zero-Click-Lücke in Outlook: Angreifer können Systeme per E-Mail kompromittieren&lt;/h3&gt;

Das bloße Senden einer E-Mail reicht aus, um über Microsoft Outlook Schadcode zur Ausführung zu bringen. Ein Klick auf einen Link ist nicht nötig. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/zero-click-luecke-in-outlook-angreifer-koennen-systeme-per-e-mail-kompromittieren-2605-208693.html&quot;&gt;https://www.golem.de/news/zero-click-luecke-in-outlook-angreifer-koennen-systeme-per-e-mail-kompromittieren-2605-208693.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mdash: Microsofts KI findet vier kritische Lücken in Windows&lt;/h3&gt;

Microsofts Projekt MDash soll beim Finden von Sicherheitslücken sogar noch besser sein als Anthropics Claude Mythos.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/mdash-microsofts-ki-findet-vier-kritische-luecken-in-windows-2605-208701.html&quot;&gt;https://www.golem.de/news/mdash-microsofts-ki-findet-vier-kritische-luecken-in-windows-2605-208701.html&lt;/a&gt;

&lt;hr&gt;&lt;h3&gt;telnetd 2.7 Buffer Overflow&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://cxsecurity.com/issue/WLB-2026050010&quot;&gt;https://cxsecurity.com/issue/WLB-2026050010&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;WPS Office improper access restriction to its named pipe&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://jvn.jp/en/jp/JVN14434132/&quot;&gt;https://jvn.jp/en/jp/JVN14434132/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Catalyst SD-WAN Manager Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-dos-7Egqyc&quot;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-dos-7Egqyc&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;[R1] Tenable Network Monitor 6.5.4 Fixes Multiple Vulnerabilities&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.tenable.com/security/tns-2026-14&quot;&gt;https://www.tenable.com/security/tns-2026-14&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1072838/&quot;&gt;https://lwn.net/Articles/1072838/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1073059/&quot;&gt;https://lwn.net/Articles/1073059/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-15T18:24:10Z</dc:date></entry><entry><title>Tageszusammenfassung - 13.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-13052026"/><author><name>CERT.at</name></author><updated>2026-05-13T18:20:23Z</updated><published>2026-05-13T18:20:23Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 12-05-2026 18:00 - Mittwoch 13-05-2026 18:00
Handler:     Guenes Holler
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation&lt;/h3&gt;

A threat actor with affiliations to China has been linked to a &quot;multi-wave intrusion&quot; targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of its targeting.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/azerbaijani-energy-firm-hit-by-repeated.html&quot;&gt;https://thehackernews.com/2026/05/azerbaijani-energy-firm-hit-by-repeated.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Angriff umgeht BitLocker mittels Windows Recovery Environment&lt;/h3&gt;

BitLocker soll vertrauliche Daten auch vor physischen Angriffen schützen. Die Windows Recovery Environment hebelt den Schutz aus. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Angriff-umgeht-BitLocker-mittels-Windows-Recovery-Environment-11292642.html&quot;&gt;https://www.heise.de/news/Angriff-umgeht-BitLocker-mittels-Windows-Recovery-Environment-11292642.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Datenpanne bei Best Western Hotels: Hacker konnten monatelang Buchungsdaten abgreifen&lt;/h3&gt;

Angreifer konnten sich wohl rund ein halbes Jahr lang ungestört im System von Best Western Hotels umsehen und Daten der Hotelgäste ausleiten.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/best-western-hotels-hacker-konnten-monatelang-auf-buchungsdaten-zugreifen-2605-208637.html&quot;&gt;https://www.golem.de/news/best-western-hotels-hacker-konnten-monatelang-auf-buchungsdaten-zugreifen-2605-208637.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded&lt;/h3&gt;

RubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a &quot;major malicious attack.&quot;
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/rubygems-suspends-new-signups-after.html&quot;&gt;https://thehackernews.com/2026/05/rubygems-suspends-new-signups-after.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Thus Spoke-The Gentlemen&lt;/h3&gt;

The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025. Its operators advertise the service across multiple underground forums, promoting their ransomware platform and inviting penetration testers and other technically skilled actors to join as affiliates.
&lt;p /&gt;
&lt;A HREF=&quot;https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/&quot;&gt;https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection&lt;/h3&gt;

Of course I took a peek at the Claude Code source.
&lt;p /&gt;
&lt;A HREF=&quot;https://0day.click/recipe/2026-05-12-cc-rce/&quot;&gt;https://0day.click/recipe/2026-05-12-cc-rce/&lt;/a&gt;

&lt;hr&gt;

&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Patchday Microsoft: Kritische DNS-Client-Lücke bedroht Windows&lt;/h3&gt;

Microsoft hat wichtige Sicherheitsupdates für unter anderem Azure, Edge, Office und Windows veröffentlicht. Viele Lücken wurden mit KI-Agenten entdeckt. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Patchday-Microsoft-Kritische-DNS-Client-Luecke-bedroht-Windows-11292506.html&quot;&gt;https://www.heise.de/news/Patchday-Microsoft-Kritische-DNS-Client-Luecke-bedroht-Windows-11292506.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Patchday: Adobe schließt mehr als 50 Lücken in After Effects &amp; Co.&lt;/h3&gt;

Wichtige Sicherheitsupdates reparieren diverse Adobe-Anwendungen. Bislang gibt es keine Berichte zu laufenden Attacken. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11292536&quot;&gt;https://heise.de/-11292536&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fortinet stopft elf Sicherheitslücken in mehreren Produkten&lt;/h3&gt;

Fortinet hat zum -Patch-Dienstag- elf Sicherheitsflicken konzertiert veröffentlicht. Zwei der Lecks gelten als kritisch. 
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11292861&quot;&gt;https://heise.de/-11292861&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in Avada Builder WordPress Plugin&lt;/h3&gt;

On March 21st, 2026, we received a submission for an Arbitrary File Read and an SQL Injection vulnerability in Avada Builder, a WordPress plugin with an estimated 1,000,000 active installations.The post 1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in Avada Builder WordPress Plugin appeared first on Wordfence.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/&quot;&gt;https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution&lt;/h3&gt;

Exim has released security updates to address a severe security issue affecting certain configurations that could enable memory corruption and potential code execution.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html&quot;&gt;https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html&lt;/a&gt;

&lt;hr&gt;
&lt;h3&gt;LWN Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1072596/&quot;&gt;https://lwn.net/Articles/1072596/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NCSC-2026-0147 [1.00] [M/H] Kwetsbaarheden verholpen in Siemens-producten&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0147&quot;&gt;https://advisories.ncsc.nl/advisory?id=NCSC-2026-0147&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FortiGuard Labs: Improper access control on API endpoints&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-128&quot;&gt;https://fortiguard.fortinet.com/psirt/FG-IR-26-128&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FortiGuard Labs: Incorrect global authorization&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-136&quot;&gt;https://fortiguard.fortinet.com/psirt/FG-IR-26-136&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FortiGuard Labs: Out-of-bounds access in CAPWAP daemon&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-123&quot;&gt;https://fortiguard.fortinet.com/psirt/FG-IR-26-123&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-13T18:20:23Z</dc:date></entry><entry><title>Tageszusammenfassung - 12.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-12052026"/><author><name>CERT.at</name></author><updated>2026-05-12T19:24:28Z</updated><published>2026-05-12T19:24:28Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 11-05-2026 18:00 - Dienstag 12-05-2026 18:00
Handler:     Felician Fuchs
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;New GhostLock tool abuses Windows API to block file access&lt;/h3&gt;

A security researcher has released a proof-of-concept tool named GhostLock that demonstrates how a legitimate Windows file API can be abused in attacks to block access to files stored locally or on SMB network shares.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-ghostlock-tool-abuses-windows-api-to-block-file-access/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-ghostlock-tool-abuses-windows-api-to-block-file-access/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cyberangriff trifft Fahrzeughersteller: Kundendaten von Skoda kompromittiert&lt;/h3&gt;

Ein unbekannter Angreifer hat ein von Skoda genutztes Shopsystem infiltriert und konnte auf Kundendaten zugreifen. Auch Zugangsdaten sind betroffen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/cyberangriff-trifft-fahrzeughersteller-kundendaten-von-skoda-kompromittiert-2605-208556.html&quot;&gt;https://www.golem.de/news/cyberangriff-trifft-fahrzeughersteller-kundendaten-von-skoda-kompromittiert-2605-208556.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation&lt;/h3&gt;

Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and exploit generation.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html&quot;&gt;https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor&lt;/h3&gt;

A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environments.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/cpanel-cve-2026-41940-under-active.html&quot;&gt;https://thehackernews.com/2026/05/cpanel-cve-2026-41940-under-active.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Prüfportal für Gutscheinkarten? Wie ein kurzer Check das Guthaben absaugt&lt;/h3&gt;

Wer im Zuge eines Online-Privatverkaufs dazu gedrängt wird, für die Zahlung gekaufte Gutscheinkarten auf einem dubiosen Portal zu überprüfen, sollte den Deal sofort abblasen. Hier wird nämlich nichts geprüft, die Plattform ist lediglich ein praktischer Weg für Kriminelle, an das Guthaben auf den Karten zu gelangen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/pruefportal-fuer-gutscheinkarten/&quot;&gt;https://www.watchlist-internet.at/news/pruefportal-fuer-gutscheinkarten/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign&lt;/h3&gt;

Iran-linked threat actor abused signed Fortemedia and SentinelOne binaries for DLL sideloading and exfiltrated data through a public file-transfer service.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.security.com/threat-intelligence/iran-seedworm-electronics&quot;&gt;https://www.security.com/threat-intelligence/iran-seedworm-electronics&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA&lt;/h3&gt;

SAP has released the May 2026 security updates addressing 15 vulnerabilities across multiple products, including two critical flaws in the Commerce Cloud enterprise-grade e-commerce platform and the S/4HANA ERP suite.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/sap-fixes-critical-vulnerabilities-in-commerce-cloud-and-s-4hana/&quot;&gt;https://www.bleepingcomputer.com/news/security/sap-fixes-critical-vulnerabilities-in-commerce-cloud-and-s-4hana/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation&lt;/h3&gt;

dnsmasq is affected by multiple memory safety and input validation vulnerabilities, including heap buffer overflows, heap corruption, and code execution flaws. Collectively, these vulnerabilities enable attackers to poison cached DNS records, bypass security controls, crash the dnsmasq process, or under certain conditions, achieve local privilege escalation. dnsmasq has released version 2.92rel2 to fix the vulnerabilities.
&lt;p /&gt;
&lt;A HREF=&quot;https://kb.cert.org/vuls/id/471747&quot;&gt;https://kb.cert.org/vuls/id/471747&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Anonymisierendes Linux Tails: Notfallupdate 7.7.3 fixt DirtyFrag-Lücke&lt;/h3&gt;

Das anonymisierende Linux Tails ist als nächstes Notfallupdate in Version 7.7.3 erschienen. Es schließt die DirtyFrag-Lücke.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Anonymisierendes-Linux-Tails-Notfallupdate-7-7-3-fixt-DirtyFrag-Luecke-11290621.html&quot;&gt;https://www.heise.de/news/Anonymisierendes-Linux-Tails-Notfallupdate-7-7-3-fixt-DirtyFrag-Luecke-11290621.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Node.js: Abermals Ausbruch aus vm2-Sandbox möglich&lt;/h3&gt;

Eine kritische Sicherheitslücke in der Node.js-Sandbox vm2 kann Schadcode passieren lassen. Ein Sicherheitspatch steht zum Download bereit.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Node-js-Abermals-Ausbruch-aus-vm2-Sandbox-moeglich-11290901.html&quot;&gt;https://www.heise.de/news/Node-js-Abermals-Ausbruch-aus-vm2-Sandbox-moeglich-11290901.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;OpenSearch-Client für Node.js ist auch kompromittiert - Teil 2&lt;/h3&gt;

Die Hiobsbotschaften reißen heute nicht ab. Im Beitrag Neuer Shai-Hulud Lieferkettenangriff auf npm tanstack-Pakete; CheckMarx Jenkins-Paket infiziert hatte ich über zwei Lieferkettenangriffe der letzten beiden Stunden berichtet. Der Mini Shai Hulud-Lieferkettenangriff auf npm tanstack-Pakete hat sich ausgeweitet und  der OpenSearch-Client für Node.js ist auch kompromittiert.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/12/opensearch-client-fuer-node-js-ist-auch-kompromittiert-teil-2/&quot;&gt;https://borncity.com/blog/2026/05/12/opensearch-client-fuer-node-js-ist-auch-kompromittiert-teil-2/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;May 2026 Security Update&lt;/h3&gt;

Ivanti is disclosing vulnerabilities in Ivanti Secure Access Client, Xtraction, Virtual Traffic Manager and Endpoint Manager (EPM).
&lt;p /&gt;
&lt;A HREF=&quot;https://www.ivanti.com/blog/may-2026-security-update&quot;&gt;https://www.ivanti.com/blog/may-2026-security-update&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Postmortem: TanStack npm supply-chain compromise&lt;/h3&gt;

On 2026-05-11 between 19:20 and 19:26 UTC, an attacker published 84 malicious versions across 42 @tanstack/* npm packages by combining: the pull_request_target &quot;Pwn Request&quot; pattern, GitHub Actions cache poisoning across the fork-base trust boundary, and runtime memory extraction of an OIDC token from the GitHub Actions runner process. No npm tokens were stolen and the npm publish workflow itself was not compromised.
&lt;p /&gt;
&lt;A HREF=&quot;https://tanstack.com/blog/npm-supply-chain-compromise-postmortem&quot;&gt;https://tanstack.com/blog/npm-supply-chain-compromise-postmortem&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Pi-hole-Update schließt dnsmasq-Sicherheitslücken&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Pi-hole-Update-schliesst-dnsmasq-Sicherheitsluecken-11291003.html&quot;&gt;https://www.heise.de/news/Pi-hole-Update-schliesst-dnsmasq-Sicherheitsluecken-11291003.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1072498/&quot;&gt;https://lwn.net/Articles/1072498/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Firefox 150.0.3 korrigiert Passwort-Druck-Bug&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/12/firefox-150-0-3-korrigiert-passwort-druck-bug/&quot;&gt;https://borncity.com/blog/2026/05/12/firefox-150-0-3-korrigiert-passwort-druck-bug/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-12T19:24:28Z</dc:date></entry><entry><title>Tageszusammenfassung - 11.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-11052026"/><author><name>CERT.at</name></author><updated>2026-05-11T19:30:47Z</updated><published>2026-05-11T19:30:47Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Freitag 08-05-2026 18:00 - Montag 11-05-2026 18:00
Handler:     Felician Fuchs
Co-Handler:  Alexander Riepl


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Hackers abuse Google ads, Claude.ai chats to push Mac malware&lt;/h3&gt;

Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for &quot;Claude mac download&quot; may come across sponsored search results that list claude.ai as the target website, but lead to instructions that install malware on their Mac.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/&quot;&gt;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Messenger: So will Signal Phishing-Angriffe erschweren&lt;/h3&gt;

Nachdem die Messenger-App Signal Ziel einer Phishing-Attacke unter anderem auf Politiker geworden ist, sollen solche Angriffe erschwert werden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/messenger-so-will-signal-phishing-angriffe-erschweren-2605-208511.html&quot;&gt;https://www.golem.de/news/messenger-so-will-signal-phishing-angriffe-erschweren-2605-208511.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads&lt;/h3&gt;

A malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html&quot;&gt;https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged&lt;/h3&gt;

Cybercrooks ruin engineers weekends with Saturday attack. Checkmarx-s software engineers are still working to remove a malicious version of the code security outfit's Jenkins plugin after detecting an unauthorized upload over the weekend.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.theregister.com/devops/2026/05/11/checkmarx-tackles-another-teampcp-intrusion-as-jenkins-plugin-sabotaged/5237780&quot;&gt;https://www.theregister.com/devops/2026/05/11/checkmarx-tackles-another-teampcp-intrusion-as-jenkins-plugin-sabotaged/5237780&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Yarbo responds to robot flaws that could mow down their owners&lt;/h3&gt;

A researcher found a host of vulnerabilities in Yarbo garden robots that could expose Wi-Fi passwords, hijack cameras, and run over their owners on command.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/news/2026/05/yarbo-responds-to-robot-flaws-that-could-mow-down-their-owners&quot;&gt;https://www.malwarebytes.com/blog/news/2026/05/yarbo-responds-to-robot-flaws-that-could-mow-down-their-owners&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;E-Mail zur Erneuerung der ID Austria App ist fake&lt;/h3&gt;

Aktuell ist eine betrügerische E-Mail im Umlauf, die Nutzer:innen zu einem angeblich notwendigen Update der ID-Austria-App auffordert. Das Ziel: Zugang zu privaten Daten und Accounts zu erlangen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/erneuerung-der-id-austria-app-fake/&quot;&gt;https://www.watchlist-internet.at/news/erneuerung-der-id-austria-app-fake/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware&lt;/h3&gt;

In April, we observed an intrusion linked to the Atos-reported campaign where an EtherRAT was installed via a malicious MSI masquerading as a Sysinternals tool. Later in the intrusion, we observed the deployment of a new malware framework named TukTuk, first reported by Evangelos G, which, according to their analysis, is AI-generated.
&lt;p /&gt;
&lt;A HREF=&quot;https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/&quot;&gt;https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Vulnerability Garden: A growing list of named vulnerabilities, attack techniques and exploits&lt;/h3&gt;

A growing list of 966 named vulnerabilities, attack techniques and exploits.
&lt;p /&gt;
&lt;A HREF=&quot;https://vulnerability.garden/&quot;&gt;https://vulnerability.garden/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;the 90 day disclosure policy is dead&lt;/h3&gt;

The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines to near-zero. I have seen it first hand, and so has everyone else paying attention.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/&quot;&gt;https://blog.himanshuanand.com/2026/05/the-90-day-disclosure-policy-is-dead/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Hunting ClickFix Win + X Variants&lt;/h3&gt;

It has been just over a year since my post on ClickFix, where I explored the technique in depth. Since then, defenders have adopted countermeasures that detect ClickFix execution through the Windows Run prompt shortcut (Win + R), or have disabled that vector entirely through the Windows registry. This post focuses on variants that leverage the Windows Power User Menu (Win + X) and user-driven Terminal launches to paste and execute commands.
&lt;p /&gt;
&lt;A HREF=&quot;https://detect.fyi/hunting-clickfix-win-x-variants-ff06e4c62bd9&quot;&gt;https://detect.fyi/hunting-clickfix-win-x-variants-ff06e4c62bd9&lt;/a&gt;

&lt;hr&gt;


&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Per DHCP-Antwort zum Root: KI findet 21 Jahre alte Schadcode-Lücke in FreeBSD&lt;/h3&gt;

Auf unzähligen FreeBSD-basierten Systemen lässt sich über einen bösartigen DHCP-Server im Netzwerk Schadcode einschleusen und als Root ausführen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/per-dhcp-antwort-zum-root-ki-findet-21-jahre-alte-schadcode-luecke-in-freebsd-2605-208535.html&quot;&gt;https://www.golem.de/news/per-dhcp-antwort-zum-root-ki-findet-21-jahre-alte-schadcode-luecke-in-freebsd-2605-208535.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak&lt;/h3&gt;

Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process memory. The out-of-bounds read flaw, which likely impacts over 300,000 servers globally, is tracked as CVE-2026-7482 (CVSS score: 9.1). It has been codenamed Bleeding Llama by Cyera.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html&quot;&gt;https://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;JDownloader verteilte Malware-Downloads&lt;/h3&gt;

Die Webseite des recht populären Downloader-Tools JDownloader wurde kompromittiert. Sie hat dadurch falsche Installationspakete ausgeliefert, die mit Malware verseucht sind. Inzwischen haben die Betreiber die Webseite bereinigt. Auch bei den Daemon Tools gab es solch einen Vorfall; inzwischen haben auch dort die Inhaber reagiert und stellen nun saubere Installer bereit.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/JDownloader-verteilte-Malware-Downloads-11288832.html&quot;&gt;https://www.heise.de/news/JDownloader-verteilte-Malware-Downloads-11288832.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Sicherheitspatch: Abermals Sicherheitslücken in cPanel und WHM geschlossen&lt;/h3&gt;

Angreifer können cPanel und WebHost Manager unter anderem mit Schadcode attackieren. Sicherheitspatches sind verfügbar.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Sicherheitspatch-Abermals-Sicherheitsluecken-in-cPanel-und-WHM-geschlossen-11288962.html&quot;&gt;https://www.heise.de/news/Sicherheitspatch-Abermals-Sicherheitsluecken-in-cPanel-und-WHM-geschlossen-11288962.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Schadcode-Lücke bedroht IBM App Connect Enterprise und IBM Integration Bus&lt;/h3&gt;

Angreifer können IBM App Connect Enterprise und IBM Integration Bus for z/OS attackieren. Updates lösen das Sicherheitsproblem.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11289112&quot;&gt;https://heise.de/-11289112&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1072301/&quot;&gt;https://lwn.net/Articles/1072301/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-11T19:30:47Z</dc:date></entry><entry><title>Tageszusammenfassung - 08.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-08052026"/><author><name>CERT.at</name></author><updated>2026-05-08T18:23:48Z</updated><published>2026-05-08T18:23:48Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 07-05-2026 18:00 - Freitag 08-05-2026 18:00
Handler:     Felician Fuchs
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;New PCPJack worm steals credentials, cleans TeamPCP infections&lt;/h3&gt;

A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP's access to the systems. Among the targeted services are Docker, Kubernetes, Redis, MongoDB, RayML, and vulnerable web applications. In many cases, the threat actor moves laterally on the network. [..] To mitigate this risk, the researchers recommend enforcing multi-factor authentication (MFA), using IMDSv2 in AWS, ensuring proper authentication for Docker and Kubernetes services, following least-privilege principles, and avoiding storing secrets in plaintext.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/new-pcpjack-worm-steals-credentials-cleans-teampcp-infections/&quot;&gt;https://www.bleepingcomputer.com/news/security/new-pcpjack-worm-steals-credentials-cleans-teampcp-infections/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Ende-zu-Ende-Verschlüsselung: Instagram deaktiviert Privatsphärenschutz&lt;/h3&gt;

Es flog etwas unter dem Radar, doch ab dem heutigen Freitag wird es Ernst: Instagram verwässert den Privatsphärenschutz des sozialen Netzwerks. Die Opt-in-Option zur Ende-zu-Ende-Verschlüsselung (End-to-End-Encryption, E2EE) schaltet Meta für Direktnachrichten global ab. [..] Als Erklärung dazu, warum die Ende-zu-Ende-Verschlüsselung nun nicht mehr möglich sein soll, liefert ein aktualisierter Facebook-Blog-Beitrag eine Antwort: Demnach haben nur sehr wenige Menschen die Möglichkeit der Aktivierung der Ende-zu-Ende-Verschlüsselung in Direktnachrichten genutzt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Ende-zu-Ende-Verschluesselung-Instagram-deaktiviert-Privatsphaerenschutz-11287210.html&quot;&gt;https://www.heise.de/news/Ende-zu-Ende-Verschluesselung-Instagram-deaktiviert-Privatsphaerenschutz-11287210.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ShinyHunters escalates Canvas attacks with school login defacements&lt;/h3&gt;

According to new reporting, ShinyHunters has now hit Instructure again, this time moving from quiet data theft to very visible extortion. Using another vulnerability in Instructure-s systems, the attackers were able to modify Canvas login portals for hundreds of educational institutions, defacing both web logins and the Canvas app with an on-screen ransom message.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.malwarebytes.com/blog/news/2026/05/shinyhunters-escalates-canvas-attacks-with-school-login-defacements&quot;&gt;https://www.malwarebytes.com/blog/news/2026/05/shinyhunters-escalates-canvas-attacks-with-school-login-defacements&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data&lt;/h3&gt;

Cybersecurity researchers from LayerX have found a major security flaw in the Claude for Chrome browser extension that could allow hackers to take full control of the AI assistant. They have named this vulnerability ClaudeBleed, and their research shows that even a basic extension with no special permissions can hijack Claude to steal private files and send emails without the user-s knowledge or consent. [..] After being notified by LayerX, Anthropic released a patch on 6 May in version 1.0.70. This update added new pop-up windows to ask for user permission. However, the LayerX team quickly found a way around them, discovering that by forcing the extension into a privileged mode, aka Act without asking mode, they could skip the permission screens entirely.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/claudebleed-vulnerability-hackers-claude-chrome-extension/&quot;&gt;https://hackread.com/claudebleed-vulnerability-hackers-claude-chrome-extension/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Kubernetes security fundamentals: Secrets&lt;/h3&gt;

In this post, we'll be exploring secrets management in Kubernetes. Securely handling secrets is essential for any cluster operator, and there are several important nuances to keep in mind.
&lt;p /&gt;
&lt;A HREF=&quot;https://securitylabs.datadoghq.com/articles/kubernetes-security-fundamentals-part-8/&quot;&gt;https://securitylabs.datadoghq.com/articles/kubernetes-security-fundamentals-part-8/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Behind the Scenes Hardening Firefox with Claude Mythos Preview&lt;/h3&gt;

Two weeks ago we announced that we had identified and fixed an unprecedented number of latent security bugs in Firefox with the help of Claude Mythos Preview and other AI models. In this post, we-ll go into more detail about how we approached this work, what we found, and advice for other projects on making good use of emerging capabilities to harden themselves against attack.
&lt;p /&gt;
&lt;A HREF=&quot;https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/&quot;&gt;https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Stop MITM on the first SSH connection, on any VPS or cloud provider&lt;/h3&gt;

This little script stops attacks on the first SSH connection to a new VM, even on providers (like Hetzner Cloud) that don't offer a proprietary solution; we only need cloud-init, which is widely supported.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.joachimschipper.nl/Stop%20MITM%20on%20the%20first%20SSH%20connection%2C%20on%20any%20VPS%20or%20cloud%20provider.html&quot;&gt;https://www.joachimschipper.nl/Stop%20MITM%20on%20the%20first%20SSH%20connection%2C%20on%20any%20VPS%20or%20cloud%20provider.html&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Lokale Privilegieneskalation im Linux-Kernel (&quot;Dirty Frag&quot; und &quot;Copy Fail 2&quot;) - PoCs verfügbar, kein Patch&lt;/h3&gt;

Am 7. Mai 2026 wurden zwei neue Schwachstellen im Linux-Kernel öffentlich gemacht, die unter den Namen -Dirty Frag- und -Copy Fail 2: Electric Boogaloo- bekannt sind. Beide Schwachstellen ermöglichen lokalen, nicht privilegierten Benutzer:innen eine Eskalation auf root. [..] Es handelt sich um deterministische Logikfehler ohne Race-Condition; bei einem Fehlschlag tritt keine Kernel-Panik auf, die Erfolgswahrscheinlichkeit wird als hoch beschrieben. [..] Bestehende Gegenmaßnahmen gegen -Copy Fail- (CVE-2026-31431), insbesondere das Sperren des Moduls algif_aead, schützen NICHT gegen -Dirty Frag- oder -Copy Fail 2-. [..] Betroffen sind die meisten aktuellen Linux-Distributionen mit aktiviertem Page-Cache-Pfad in esp4/esp6 bzw. rxrpc. [..] Zum Zeitpunkt der Veröffentlichung dieser Warnung liegen für die meisten Distributionen noch keine vollständig gepatchten Kernel vor.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/warnungen/2026/5/linux-lpe-dirty-frag-copy-fail-2&quot;&gt;https://www.cert.at/de/warnungen/2026/5/linux-lpe-dirty-frag-copy-fail-2&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Friday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1071859/&quot;&gt;https://lwn.net/Articles/1071859/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-08T18:23:48Z</dc:date></entry><entry><title>Tageszusammenfassung - 07.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-07052026"/><author><name>CERT.at</name></author><updated>2026-05-07T18:52:26Z</updated><published>2026-05-07T18:52:26Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 06-05-2026 18:00 - Donnerstag 07-05-2026 18:00
Handler:     Felician Fuchs
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Hackers abuse Google ads for GoDaddy ManageWP login phishing&lt;/h3&gt;

A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddys platform for managing fleets of WordPress websites.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-for-godaddy-managewp-login-phishing/&quot;&gt;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-for-godaddy-managewp-login-phishing/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake Claude AI website delivers new Beagle Windows malware&lt;/h3&gt;

A fake version for the Claude AI website offers a malicious Claude-Pro Relay download that pushes a previously undocumented backdoor for Windows named Beagle.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/fake-claude-ai-website-delivers-new-beagle-windows-malware/&quot;&gt;https://www.bleepingcomputer.com/news/security/fake-claude-ai-website-delivers-new-beagle-windows-malware/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;When DNSSEC goes wrong: how we responded to the .de TLD outage&lt;/h3&gt;

On May 5, 2026, DENIC published broken DNSSEC signatures for the .de TLD, making millions of domains unreachable. Heres what 1.1.1.1 saw, how serve stale cushioned the impact, and how we restored resolution.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.cloudflare.com/de-tld-outage-dnssec/&quot;&gt;https://blog.cloudflare.com/de-tld-outage-dnssec/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;How Cloudflare responded to the -Copy Fail- Linux vulnerability&lt;/h3&gt;

When a critical Linux kernel privilege escalation was publicly disclosed, Cloudflares security and engineering teams detected, investigated, and mitigated the threat across our global fleet, confirming zero customer impact and no malicious exploitation.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.cloudflare.com/copy-fail-linux-vulnerability-mitigation/&quot;&gt;https://blog.cloudflare.com/copy-fail-linux-vulnerability-mitigation/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks&lt;/h3&gt;

Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying out distributed denial-of-service (DDoS) attacks.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/mirai-based-xlabsv1-botnet-exploits-adb.html&quot;&gt;https://thehackernews.com/2026/05/mirai-based-xlabsv1-botnet-exploits-adb.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Insolvenzmasse: Kriminelle imitieren neben Anwaltskanzleien nun auch Autohändler, Großhändler und Wirtschaftsprüfer&lt;/h3&gt;

Die Masche bleibt gleich, aber die Deckmäntel ändern sich. Wurde früher ausschließlich die Identität von Anwaltskanzleien missbraucht, um über Vorschussbetrug an das Geld von Opfern zu gelangen, haben die Kriminellen nun ihr Portfolio erweitert. Sie geben sich mittlerweile auch als eine Vielzahl anderer Unternehmen und Agenturen aus. Ein Update.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/insolvenzmasse-autohaendler-grosshaendler-wirtschaftspruefer/&quot;&gt;https://www.watchlist-internet.at/news/insolvenzmasse-autohaendler-grosshaendler-wirtschaftspruefer/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;World Password Day 2026: Why -Strong Passwords- Can-t Save You from AI, Infostealers, and the Telegram Underground&lt;/h3&gt;

As we recognize World Password Day in 2026, the traditional advice to -use a complex password with numbers and symbols- feels hopelessly outdated. Today, a 16-character password is useless if an infostealer malware extracts it directly from a browser cache, or if an employee willingly pastes it into an unmanaged AI chatbot. Welcome to the real World Password Day 2026.
&lt;p /&gt;
&lt;A HREF=&quot;https://blog.checkpoint.com/security/world-password-day-2026-why-strong-passwords-cant-save-you-from-ai-infostealers-and-the-telegram-underground/&quot;&gt;https://blog.checkpoint.com/security/world-password-day-2026-why-strong-passwords-cant-save-you-from-ai-infostealers-and-the-telegram-underground/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Polish intelligence warns hackers attacked water treatment control systems&lt;/h3&gt;

The agency did not publicly attribute the incidents to a specific group or country but said Poland faced intensified hostile cyber activity in 2024 and 2025, -with particular emphasis on the special services of the Russian Federation.-
&lt;p /&gt;
&lt;A HREF=&quot;https://therecord.media/polish-intelligence-warns-hackers-attacked-water-treatment&quot;&gt;https://therecord.media/polish-intelligence-warns-hackers-attacked-water-treatment&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Warnung vor IONOS/1&amp;1 Rechnungs-Phishing&lt;/h3&gt;

Ich stelle mal eine kurze Warnung hier im Blog ein, weil mir bereits zum zweiten Monat eine Phishing-Mail von 1&amp;1 in meinem Postfach zugestellt wurde, die Rechnungs-Phishing bei IONOS versucht.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/07/warnung-vor-ionos-11-rechnungs-phishing/&quot;&gt;https://borncity.com/blog/2026/05/07/warnung-vor-ionos-11-rechnungs-phishing/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Best OSINT Tools for Investigations and Threat Intelligence in 2026&lt;/h3&gt;

Explore the best OSINT tools for your digital investigations, threat intelligence, reconnaissance, and tracking online activity in 2026.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/best-osint-tools-investigate-threat-intelligence-2026/&quot;&gt;https://hackread.com/best-osint-tools-investigate-threat-intelligence-2026/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Plastic Flowers to Protect the Hive&lt;/h3&gt;

Agentic development has fundamentally changed the software ecosystem. Modern coding agents are trained and prompted to seek out tools that will help with their assigned coding tasks. They will install those tools into their user-s environment, with little to no oversight on what the installed package actually does, relying on name pattern matching more than any other signal.
&lt;p /&gt;
&lt;A HREF=&quot;https://phildini.dev/slopsquatting-for-good&quot;&gt;https://phildini.dev/slopsquatting-for-good&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Operation Epic Fury Exposes Critical OT Security Gaps in U.S. Oil and Gas Sector&lt;/h3&gt;

The cybersecurity posture of the U.S. oil and gas sector has come under renewed scrutiny following Operation Epic Fury, with a new independent survey revealing a disconnect between operator confidence and actual operational technology (OT) security capabilities.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/operation-epic-fury-ot-security-detection-gaps/&quot;&gt;https://thecyberexpress.com/operation-epic-fury-ot-security-detection-gaps/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ClickFix Campaign Evolves with Targeting of MacOS Users&lt;/h3&gt;

ClickFix started as a Windows problem. It is no longer one. Microsofts Defender Security Research Team published a detailed analysis documenting an active ClickFix campaign that is targeting macOS users since at least January 2026. The primary goal is delivering infostealers by convincing users to paste malicious commands into their own Terminal, framed as routine system maintenance.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/clickfix-campaign-evolves-targets-macos-users/&quot;&gt;https://thecyberexpress.com/clickfix-campaign-evolves-targets-macos-users/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Cisco: Codeschmuggel-Leck in Unity Connection und weitere Lücken&lt;/h3&gt;

Cisco hat fast zwei Handvoll Sicherheitsupdates veröffentlicht. Sie schließen mehrere hochriskante Lücken etwa in Unity Connection.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Cisco-Codeschmuggel-Leck-in-Unity-Connection-und-weitere-Luecken-11285115.html&quot;&gt;https://www.heise.de/news/Cisco-Codeschmuggel-Leck-in-Unity-Connection-und-weitere-Luecken-11285115.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;May 2026 EPMM Security Update&lt;/h3&gt;

Ivanti has released updates for Ivanti Endpoint Manager Mobile (EPMM) which addresses five high severity vulnerabilities.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.ivanti.com/blog/may-2026-epmm-security-update&quot;&gt;https://www.ivanti.com/blog/may-2026-epmm-security-update&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Node.js 25: Ausbrüche aus JavaScript-Sandbox vm2 vorstellbar&lt;/h3&gt;

Die Sandbox-Komponente vm2 der Open-Source-JavaScript-Laufzeitumgebung Node.js ist mit bestimmten Einstellungen verwundbar.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11285063&quot;&gt;https://heise.de/-11285063&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Salesforce Marketing Cloud Vulnerabilities Expose Cross-Tenant Subscriber Data Risks&lt;/h3&gt;

A recently disclosed set of vulnerabilities in Salesforce Marketing Cloud, widely known as SFMC, has drawn attention to the security risks tied to centralized marketing infrastructure. The flaws, which affected components tied to AMPScript, CloudPages, and email-rendering workflows, could have enabled attackers to access subscriber information, enumerate marketing emails, and potentially affect organizations across multiple tenants.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/salesforce-sfmc-ampscript-vulnerability/&quot;&gt;https://thecyberexpress.com/salesforce-sfmc-ampscript-vulnerability/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Authenticated Arbitrary File Upload Vulnerability Patched in Slider Revolution 7 WordPress Plugin&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wordfence.com/blog/2026/05/authenticated-arbitrary-file-upload-vulnerability-patched-in-slider-revolution-7-wordpress-plugin/&quot;&gt;https://www.wordfence.com/blog/2026/05/authenticated-arbitrary-file-upload-vulnerability-patched-in-slider-revolution-7-wordpress-plugin/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1071700/&quot;&gt;https://lwn.net/Articles/1071700/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-07T18:52:26Z</dc:date></entry><entry><title>Tageszusammenfassung - 06.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-06052026"/><author><name>CERT.at</name></author><updated>2026-05-06T18:33:48Z</updated><published>2026-05-06T18:33:48Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 05-05-2026 18:00 - Mittwoch 06-05-2026 18:00
Handler:     Felician Fuchs
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;MuddyWater hackers use Chaos ransomware as a decoy in attacks&lt;/h3&gt;

The MuddyWater Iranian hackers disguised their operations as a Chaos ransomware attack, relying on Microsoft Teams social engineering to gain access and establish persistence.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/muddywater-hackers-use-chaos-ransomware-as-a-decoy-in-attacks/&quot;&gt;https://www.bleepingcomputer.com/news/security/muddywater-hackers-use-chaos-ransomware-as-a-decoy-in-attacks/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;OceanLotus suspected of using PyPI to deliver ZiChatBot malware&lt;/h3&gt;

Kaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot. We attribute this activity to OceanLotus APT.
&lt;p /&gt;
&lt;A HREF=&quot;https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/&quot;&gt;https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader&lt;/h3&gt;

OpenClaw, previously known as Clawdbot, Moltbot, and Molty, is an open-source framework designed for autonomous AI agents that execute complex tasks requiring high-privilege local system access. While intended for automation, its modular &quot;skill&quot; architecture has been weaponized as a significant attack vector.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader&quot;&gt;https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Behörde für abgesicherte Ausweise geknackt: 15-Jähriger verhaftet&lt;/h3&gt;

Millionen Datensätze aus französischen -abgesicherten Ausweisen- gerieten in falsche Hände. Kein fremder Geheimdienst, sondern ein Bursche ist verdächtig.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Behoerde-fuer-abgesicherte-Ausweise-geknackt-15-Jaehriger-verhaftet-11283198.html&quot;&gt;https://www.heise.de/news/Behoerde-fuer-abgesicherte-Ausweise-geknackt-15-Jaehriger-verhaftet-11283198.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;-Pressure Cooker-: Europols geheime Datenverarbeitung ohne Aufsicht&lt;/h3&gt;

Interne, per Infofreiheit erlangte Warnungen belegen, dass das EU-Polizeiamt lange operative Netzwerke ohne IT-Kontrolle und richtige Protokollierung betrieb.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Pressure-Cooker-Europols-geheime-Datenverarbeitung-ohne-Aufsicht-11283466.html&quot;&gt;https://www.heise.de/news/Pressure-Cooker-Europols-geheime-Datenverarbeitung-ohne-Aufsicht-11283466.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FSFE warnt: NHS sollte quelloffenen Code nicht depublizieren&lt;/h3&gt;

Die Free Software Foundation Europe warnt vor dem Umstellen der NHS-Code-Repositories auf Privat aus Angst vor KI-Schwachstellensuche.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/FSFE-warnt-NHS-sollte-quelloffenen-Code-nicht-depublizieren-11283406.html&quot;&gt;https://www.heise.de/news/FSFE-warnt-NHS-sollte-quelloffenen-Code-nicht-depublizieren-11283406.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;IPFire: Neue DNS Firewall soll URL-Filter und Pi-hole ablösen&lt;/h3&gt;

Die Firewall-Distribution IPFire bringt mit Core Update 201 eine DNS Firewall mit, die unerwünschte Domains schon bei der Namensauflösung blockiert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/IPFire-Neue-DNS-Firewall-soll-URL-Filter-und-Pi-hole-abloesen-11283482.html&quot;&gt;https://www.heise.de/news/IPFire-Neue-DNS-Firewall-soll-URL-Filter-und-Pi-hole-abloesen-11283482.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Discounter-Falle: Gefälschte Suchergebnisse führen in Lidl-Fake-Shop&lt;/h3&gt;

Wer sich online auf die Suche nach günstigen Haushaltsgeräten, Fahrrädern, Werkzeugen oder anderen beliebten Artikeln macht, landet häufig in einem Fake-Shop. Als -gesponserte Suchergebnisse- getarnte Werbeanzeigen führen direkt in die Falle, die optisch dem Web-Auftritt des bekannten Discounters Lidl nachempfunden ist.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/lidl-fake-shop/&quot;&gt;https://www.watchlist-internet.at/news/lidl-fake-shop/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Paramiko Security Audit&lt;/h3&gt;

Paramiko is a pure-Python implementation of SSHv2 that provides both client- and server-side functionality. It serves as the foundation for the high-level SSH library Fabric and is widely regarded as one of the most popular SSH solutions in the Python ecosystem. The Cryptography library, for its part, offers Python developers access to a broad range of cryptographic algorithms and primitives. It is a widely adopted Python/Rust library with more than 25,000 known dependencies.
&lt;p /&gt;
&lt;A HREF=&quot;http://blog.quarkslab.com/paramiko-security-audit.html&quot;&gt;http://blog.quarkslab.com/paramiko-security-audit.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The Jenkins Threat Landscape&lt;/h3&gt;

What usage patterns, plugin adoption, and configuration choices reveal about the Jenkins attack surface.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wiz.io/blog/jenkins-threat-risk-insights&quot;&gt;https://www.wiz.io/blog/jenkins-threat-risk-insights&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New Infostealer Dubbed -Pheno- Hijacks Windows- Phone Link App to Steal MFA OTPs&lt;/h3&gt;

Attackers have found a way to intercept SMS-based one-time passwords from a victims mobile device without deploying a single line of malware on the phone itself. Instead, they go through the Windows PC the phone is already connected to.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/new-infostealer-pheno-steals-mfa-otps/&quot;&gt;https://thecyberexpress.com/new-infostealer-pheno-steals-mfa-otps/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE&lt;/h3&gt;

The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE). The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been described as a case of &quot;double free and possible RCE&quot; in the HTTP/2 protocol handling.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html&quot;&gt;https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;PAN-OS-Lücke wird angegriffen, Updates erst in Wochen geplant&lt;/h3&gt;

Palo Alto Networks warnt vor einer bereits angegriffenen kritischen Sicherheitslücke in PAN-OS. Updates kommen frühestens Mitte Mai.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/PAN-OS-Luecke-wird-angegriffen-Updates-erst-in-Wochen-geplant-11283352.html&quot;&gt;https://www.heise.de/news/PAN-OS-Luecke-wird-angegriffen-Updates-erst-in-Wochen-geplant-11283352.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;An exploitable integer overflow in Lix (CVE-2026-44028)&lt;/h3&gt;

Security researchers have found a security issue in Lix. This issue has been assigned CVE-2026-44028.
&lt;p /&gt;
&lt;A HREF=&quot;https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/&quot;&gt;https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wordfence.com/blog/2026/05/attackers-actively-exploiting-critical-vulnerability-in-breeze-cache-plugin/&quot;&gt;https://www.wordfence.com/blog/2026/05/attackers-actively-exploiting-critical-vulnerability-in-breeze-cache-plugin/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1071466/&quot;&gt;https://lwn.net/Articles/1071466/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-06T18:33:48Z</dc:date></entry><entry><title>Tageszusammenfassung - 05.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-05052026"/><author><name>CERT.at</name></author><updated>2026-05-05T18:25:49Z</updated><published>2026-05-05T18:25:49Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 04-05-2026 18:00 - Dienstag 05-05-2026 18:00
Handler:     Felician Fuchs
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Trellix discloses data breach after source code repository hack&lt;/h3&gt;

Cybersecurity firm Trellix disclosed a data breach after attackers gained access to &quot;a portion&quot; of its source code repository.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/&quot;&gt;https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Amazon SES increasingly abused in phishing to evade detection&lt;/h3&gt;

The Amazon Simple Email Service (SES) is being increasingly abused to send convincing phishing emails that can bypass standard security filters and render reputation-based blocks ineffective.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/&quot;&gt;https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Weaver E-cology critical bug exploited in attacks since March&lt;/h3&gt;

Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/weaver-e-cology-critical-bug-exploited-in-attacks-since-march/&quot;&gt;https://www.bleepingcomputer.com/news/security/weaver-e-cology-critical-bug-exploited-in-attacks-since-march/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs&lt;/h3&gt;

A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/&quot;&gt;https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Webbrowser: Klartext-Passwörter im Speicher von Microsoft Edge entdeckt&lt;/h3&gt;

Der in Edge integrierte Passwortmanager ist offenbar keine sichere Wahl. Passwörter landen beim Start im Prozessspeicher und lassen sich auslesen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/webbrowser-klartext-passwoerter-permanent-im-speicher-von-microsoft-edge-2605-208315.html&quot;&gt;https://www.golem.de/news/webbrowser-klartext-passwoerter-permanent-im-speicher-von-microsoft-edge-2605-208315.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools&lt;/h3&gt;

An active phishing campaign has been observed targeting multiple vectors since at least April 2025 with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html&quot;&gt;https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries&lt;/h3&gt;

Microsoft has disclosed details of a large-scale credential theft campaign that has leveraged a combination of code of conduct-themed lures and legitimate email services to direct users to attacker-controlled domains and steal authentication tokens.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/microsoft-details-phishing-campaign.html&quot;&gt;https://thehackernews.com/2026/05/microsoft-details-phishing-campaign.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Vimeo-Datenleck: 119.000 E-Mail-Adressen betroffen&lt;/h3&gt;

Die Cybergang ShinyHunters hat Daten von Vimeo bei Anodot gestohlen und ins Darknet gestellt. Nun hat Have-I-Been-Pwned sie aufgenommen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Vimeo-Datenleck-119-000-E-Mail-Adressen-betroffen-11281379.html&quot;&gt;https://www.heise.de/news/Vimeo-Datenleck-119-000-E-Mail-Adressen-betroffen-11281379.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Datenschutzvorfall bei Verlag Delius Klasing&lt;/h3&gt;

Der Verlag Delius Klasing räumt in einer E-Mail an Kunden einen IT-Vorfall ein. Personenbezogene Kundendaten wurden offengelegt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Datenschutzvorfall-bei-Verlag-Delius-Klasing-11281800.html&quot;&gt;https://www.heise.de/news/Datenschutzvorfall-bei-Verlag-Delius-Klasing-11281800.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Quasar Linux (QLNX) - A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities&lt;/h3&gt;

TrendAI- Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.html&quot;&gt;https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA Unveils New Initiative to Fortify America-s Critical Infrastructure&lt;/h3&gt;

Today, the Cybersecurity and Infrastructure Security Agency (CISA) released guidance to help critical infrastructure (CI) entities across all sectors prepare to operate through a crisis or conflict, continuing vital service delivery even as their systems are under attack. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cisa.gov/news-events/news/cisa-unveils-new-initiative-fortify-americas-critical-infrastructure&quot;&gt;https://www.cisa.gov/news-events/news/cisa-unveils-new-initiative-fortify-americas-critical-infrastructure&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Patchday: Kritische Schadcode-Lücke bedroht Android 14, 15 und 16&lt;/h3&gt;

Schadcode kann durch ein fehlerhaftes Debugging-Modul auf Androidgeräte schlüpfen. Nun hat Google die kritische Schwachstelle geschlossen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Patchday-Kritische-Schadcode-Luecke-bedroht-Android-14-15-und-16-11281884.html&quot;&gt;https://www.heise.de/news/Patchday-Kritische-Schadcode-Luecke-bedroht-Android-14-15-und-16-11281884.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Daemon Tools Lite: Infizierte Installer durch Supply-Chain-Attacke&lt;/h3&gt;

Offiziell signierte Daemon-Tools-Installer von der Herstellerseite bringen Malware mit. Offenbar durch einen Lieferkettenangriff.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Daemon-Tools-Lite-Infizierte-Installer-durch-Supply-Chain-Attacke-11282006.html&quot;&gt;https://www.heise.de/news/Daemon-Tools-Lite-Infizierte-Installer-durch-Supply-Chain-Attacke-11282006.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass&lt;/h3&gt;

Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/progress-patches-critical-moveit.html&quot;&gt;https://thehackernews.com/2026/05/progress-patches-critical-moveit.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1071324/&quot;&gt;https://lwn.net/Articles/1071324/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-05T18:25:49Z</dc:date></entry><entry><title>Tageszusammenfassung - 04.05.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/5/tagesberichte-04052026"/><author><name>CERT.at</name></author><updated>2026-05-04T19:10:28Z</updated><published>2026-05-04T19:10:28Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Donnerstag 30-04-2026 18:00 - Montag 04-05-2026 18:00
Handler:     Felician Fuchs
Co-Handler:  n/a


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;ConsentFix v3 attacks target Azure with automated OAuth abuse&lt;/h3&gt;

A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums, building on the previous technique by adding automation and scaling potential.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/consentfix-v3-attacks-target-azure-with-automated-oauth-abuse/&quot;&gt;https://www.bleepingcomputer.com/news/security/consentfix-v3-attacks-target-azure-with-automated-oauth-abuse/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks&lt;/h3&gt;

A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service providers (MSPs) and hosting providers in the Philippines, Laos, Canada, South Africa, and the U.S., by exploiting the recently disclosed vulnerability in cPanel.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/05/critical-cpanel-vulnerability.html&quot;&gt;https://thehackernews.com/2026/05/critical-cpanel-vulnerability.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Trellix: Angreifer erlangten Zugriff auf Quellcode&lt;/h3&gt;

Trellix, das aus FireEye und McAfee hervorging, hat einen IT-Vorfall gemeldet. Angreifer haben Zugriff auf Quellcode erlangt.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Trellix-Angreifer-erlangten-Zugriff-auf-Quellcode-11280743.html&quot;&gt;https://www.heise.de/news/Trellix-Angreifer-erlangten-Zugriff-auf-Quellcode-11280743.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Vorfall bei DigiCert: Malware-Autoren klauten Zertifikate&lt;/h3&gt;

Die Zertifizierungsstelle DigiCert hat im April mehrere Zertifikate zur Signierung von Programmen (-Code Signing Certificate-) an Malware-Autoren ausgegeben. Diese hatten zuvor Kundendienstmitarbeiter bei DigiCert mit Schadsoftware angegriffen und deren Rechner übernommen. Weil verschiedene Schutzmaßnahmen versagten, erlangten die Kriminellen Zugriff auf ein geschütztes Kundenportal - inklusive aller notwendigen Informationen, um die Zertifikate abzurufen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Nach-Malware-Angriff-Kriminelle-nutzten-Codesigning-Zertifikate-von-DigiCert-11280757.html&quot;&gt;https://www.heise.de/news/Nach-Malware-Angriff-Kriminelle-nutzten-Codesigning-Zertifikate-von-DigiCert-11280757.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Build a Decoy MCP Server to Catch AI Agent Attackers&lt;/h3&gt;

Your AI agents MCP config can be a target for an attacker who reaches your machine. A decoy MCP server entry pointing at a Cloudflare Worker can reveal the attackers presence and their intent.
&lt;p /&gt;
&lt;A HREF=&quot;https://zeltser.com/decoy-mcp-server-honeypot&quot;&gt;https://zeltser.com/decoy-mcp-server-honeypot&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ESC-Tickets im Netz: Drittanbieter wie ticombo.com bergen ein hohes Risiko!&lt;/h3&gt;

Für den ausverkauften Eurovision Song Contest tauchen immer wieder Ticketangebote bei Drittanbietern auf. Wir erklären, warum man besser die Finger davon lassen sollte.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/esc-tickets-plattformen-wie-ticombocom-riskant/&quot;&gt;https://www.watchlist-internet.at/news/esc-tickets-plattformen-wie-ticombocom-riskant/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;That AI Extension Helping You Write Emails? It-s Reading Them First&lt;/h3&gt;

Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser.
&lt;p /&gt;
&lt;A HREF=&quot;https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/&quot;&gt;https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;EV-Zertifikate von Lenovo &amp; Co. durch GoldenEyeDog missbraucht&lt;/h3&gt;

Hersteller wie Lenovo, Kingston, Shuttle Inc. und Palit Microsystems sind von einem Zertifikatsproblem betroffen. Eine chinesische Hackergruppe namens GoldenEyeDog (APT-Q-27) war in der Lage, EV-Zertifikate im Namen der oben genannten Organisationen auszustellen und für kriminelle Zwecke zu missbrauchen.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/05/03/ev-zertifikate-von-lenovo-co-durch-goldeneyedog-missbraucht/&quot;&gt;https://borncity.com/blog/2026/05/03/ev-zertifikate-von-lenovo-co-durch-goldeneyedog-missbraucht/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Careful Adoption of Agentic AI Services&lt;/h3&gt;

CISA, in collaboration with the Australian Signals Directorate-s Australian Cyber Security Centre (ASD-s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services&quot;&gt;https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;The Life-Dinner Principle in Detection&lt;/h3&gt;

Cybersecurity has its own folk saying. You have heard it at conferences, on panels, in vendor decks, and in LinkedIn posts from CISOs who are -humbled- to announce something: -The attacker only has to be right once. The defender has to be right every time.-
&lt;p /&gt;
&lt;A HREF=&quot;https://detect.fyi/the-life-dinner-principle-in-detection-822169d9da2c&quot;&gt;https://detect.fyi/the-life-dinner-principle-in-detection-822169d9da2c&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Evaluating our Threat Hunting Detection Rules (+ KQL Query Evaluation)&lt;/h3&gt;

I really enjoy creating detection rules - they give me better visibility into current threats, help me stay proactive, and bring many other advantages. On the other hand, it-s a double-edged sword.
&lt;p /&gt;
&lt;A HREF=&quot;https://detect.fyi/evaluating-our-threat-hunting-detection-rules-kql-query-evaluation-5e8b6a77f2a2?source=rssd5fd8f494f6a4&quot;&gt;https://detect.fyi/evaluating-our-threat-hunting-detection-rules-kql-query-evaluation-5e8b6a77f2a2?source=rssd5fd8f494f6a4&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Practical Package Security: The Unofficial Guide&lt;/h3&gt;

Get actionable best practices to shrink your attack surface, protect execution environments, control package ingestion, and catch compromises early.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.wiz.io/blog/practical-package-security-the-unofficial-guide&quot;&gt;https://www.wiz.io/blog/practical-package-security-the-unofficial-guide&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise&lt;/h3&gt;

Socket found a malicious Intercom PHP package on Packagist using Composer plugin execution to steal credentials and spread across ecosystems.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise&quot;&gt;https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables&lt;/h3&gt;

The Socket Research Team has detected an active supply-chain attack targeting the unscoped tanstack package on npm, a brand-squatted impersonation of the legitimate @tanstack/* organization.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/tanstack-brandsquat-compromise&quot;&gt;https://socket.dev/blog/tanstack-brandsquat-compromise&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface&lt;/h3&gt;

Organisations worldwide are being urged to prepare for a vulnerability patch wave, as security experts warn that advances in artificial intelligence (AI) could rapidly expose long-standing weaknesses across software systems. The warning comes from National Cyber Security Centre (NCSC), which says businesses must act now to strengthen their environments before a surge of critical updates arrives.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/ncsc-vulnerability-patch-wave/&quot;&gt;https://thecyberexpress.com/ncsc-vulnerability-patch-wave/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;FBI Warns of Surge in Cyber-Enabled Cargo Theft Targeting Logistics Firms&lt;/h3&gt;

The Federal Bureau of Investigation (FBI) has issued a public warning over a sharp rise in cyber-enabled cargo theft, as threat actors increasingly use digital tactics to impersonate legitimate businesses, hijack freight, and steal high-value shipments. According to the FBI, cybercriminals are targeting transportation and logistics companies involved in shipping, receiving, and insuring cargo.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/cyber-enabled-cargo-theft-fbi-issues-alert/&quot;&gt;https://thecyberexpress.com/cyber-enabled-cargo-theft-fbi-issues-alert/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Copy Fail Update #1: Kritische Linux-Kernel-Schwachstelle ermöglicht lokale Root-Rechte&lt;/h3&gt;

04.05.2026 Wir haben den Hinweis erhalten, dass ein Workaround existiert, der auf Systemen greift, bei denen der betroffene Code in einem Kernel-Modul enthalten ist (wie unter anderem Debian-basierte Systeme wie Ubuntu). Dabei wird das Laden des Moduls verhindert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/warnungen/2026/4/copy-fail-kritische-linux-kernel-schwachstelle-ermoglicht-lokale-root-rechte&quot;&gt;https://www.cert.at/de/warnungen/2026/4/copy-fail-kritische-linux-kernel-schwachstelle-ermoglicht-lokale-root-rechte&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Progress warns of critical MOVEit Automation auth bypass flaw&lt;/h3&gt;

Progress Software warned customers to patch a critical authentication bypass vulnerability in its MOVEit Automation enterprise-grade managed file transfer (MFT) application.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/moveit-automation-customers-warned-to-patch-critical-auth-bypass-flaw/&quot;&gt;https://www.bleepingcomputer.com/news/security/moveit-automation-customers-warned-to-patch-critical-auth-bypass-flaw/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Netzwerkanalysetool Wireshark: Zahlreiche Sicherheitslücken geschlossen&lt;/h3&gt;

In zwei aktuellen Versionen von Wireshark haben die Entwickler mehrere Schwachstellen geschlossen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Netzwerkanalysetool-Wireshark-Zahlreiche-Sicherheitsluecken-geschlossen-11280168.html&quot;&gt;https://www.heise.de/news/Netzwerkanalysetool-Wireshark-Zahlreiche-Sicherheitsluecken-geschlossen-11280168.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Tails 7.7.1: Notfallupdate für anonymisierendes Linux stopft Firefox-Lecks&lt;/h3&gt;

Das anonymisierende Linux Tails schließt in Version 7.7.1 unter anderem Firefox-Sicherheitslücken im Tor-Browser.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Tails-7-7-1-Notfallupdate-fuer-anonymisierendes-Linux-stopft-Firefox-Lecks-11280198.html&quot;&gt;https://www.heise.de/news/Tails-7-7-1-Notfallupdate-fuer-anonymisierendes-Linux-stopft-Firefox-Lecks-11280198.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Bösartige npm-Pakete: SAP-Software kompromittiert&lt;/h3&gt;

Mehrere npm-Pakete von SAP waren einer Supply-Chain-Attacke ausgesetzt. Dahinter steckt die Hackergruppe TeamPCP, sagen Sicherheitsforscher.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Boesartige-npm-Pakete-SAP-Software-kompromittiert-11280683.html&quot;&gt;https://www.heise.de/news/Boesartige-npm-Pakete-SAP-Software-kompromittiert-11280683.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN Security updates for Monday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1071167/&quot;&gt;https://lwn.net/Articles/1071167/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-05-04T19:10:28Z</dc:date></entry><entry><title>Tageszusammenfassung - 30.04.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/4/tagesberichte-30042026"/><author><name>CERT.at</name></author><updated>2026-04-30T19:46:15Z</updated><published>2026-04-30T19:46:15Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Mittwoch 29-04-2026 18:00 - Donnerstag 30-04-2026 18:00
Handler:     Michael Schlagenhaufer
Co-Handler:  Guenes Holler


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Popular WordPress redirect plugin hid dormant backdoor for years&lt;/h3&gt;

The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users sites.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/popular-wordpress-redirect-plugin-hid-dormant-backdoor-for-years/&quot;&gt;https://www.bleepingcomputer.com/news/security/popular-wordpress-redirect-plugin-hid-dormant-backdoor-for-years/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;RDP Security: CPS Threats Spark Need for Secure Remote Access&lt;/h3&gt;

1.8 million RDP and 1.6 million VNC servers are exposed on the internet. [..] 18% of exposed RDP servers run end-of-life Windows versions; an additional 42% run Windows 10, which reached end of support last October. [..] 19,000+ RDP servers remain vulnerable to BlueKeep (CVE-2019-0708) - a critical remote code execution flaw. Nearly 60,000 VNC servers have authentication disabled - 670+ of those have direct access to OT/ICS control panels. [..] Hacktivist groups are sharing custom tools to scan for vulnerable VNC servers and selling access to compromised assets.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.forescout.com/blog/rdp-security-cps-threats-spark-need-for-secure-remote-access/&quot;&gt;https://www.forescout.com/blog/rdp-security-cps-threats-spark-need-for-secure-remote-access/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution&lt;/h3&gt;

Google has addressed a maximum severity security flaw in Gemini CLI -- the &quot;@google/gemini-cli&quot; npm package and the &quot;google-github-actions/run-gemini-cli&quot; GitHub Actions workflow -- that could have allowed attackers to execute arbitrary commands on host systems. [..] The update addresses the problem by requiring folders to be explicitly trusted before configuration files can be accessed. To that end, users are being urged to review their workflows and adopt one of two approaches.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/04/google-fixes-cvss-10-gemini-cli-ci-rce.html&quot;&gt;https://thehackernews.com/2026/04/google-fixes-cvss-10-gemini-cli-ci-rce.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Aktive Ausnutzung einer schwerwiegenden Sicherheitslücke in cPanel und WHM&lt;/h3&gt;

Der Hersteller cPanel hat kürzlich Sicherheitsupdates zur Behebung einer kritischen Schwachstelle (CVE-2026-41940) in den Produkten cPanel &amp; WHM sowie WP Squared veröffentlicht. Laut Berichten von watchTowr wird diese Schwachstelle bereits aktiv durch Angreifer:innen ausgenutzt, um Hosting-Infrastrukturen zu kompromittieren. Es gibt Hinweise darauf, dass gezielte Zero-Day-Angriffe bereits seit Ende Februar 2026 stattfinden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/aktuelles/2026/4/aktive-ausnutzung-einer-schwerwiegenden-sicherheitslucke-in-cpanel-und-whm&quot;&gt;https://www.cert.at/de/aktuelles/2026/4/aktive-ausnutzung-einer-schwerwiegenden-sicherheitslucke-in-cpanel-und-whm&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks&lt;/h3&gt;

Bluekit Phishing Kit is a new PhaaS tool that targets major platforms, using AiTM techniques to steal session data and bypass MFA protections. [..] According to Varonis- experts, when a victim enters their details on a fake Bluekit page, the kit doesn-t just grab the password; it also steals session cookies and local storage data.
&lt;p /&gt;
&lt;A HREF=&quot;https://hackread.com/bluekit-phishing-kit-targets-platforms-mfa-bypass-attack/&quot;&gt;https://hackread.com/bluekit-phishing-kit-targets-platforms-mfa-bypass-attack/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Adapting Zero Trust Principles to Operational Technology&lt;/h3&gt;

This guidance supports OT owners and operators in addressing the unique challenges of transitioning to a ZT architecture, considering technology gaps from legacy infrastructure, operational constraints, and safety requirements. It focuses on establishing comprehensive asset visibility, proactively addressing supply chain risks, and implementing robust identity and access management while stressing the importance of layered security measures-including network segmentation, secure communication protocols, and vulnerability management.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology&quot;&gt;https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables&lt;/h3&gt;

The Socket Research Team has detected an active supply-chain attack targeting the unscoped tanstack package on npm, a brand-squatted impersonation of the legitimate @tanstack/* organization. Beginning today, the package's maintainer (sh20raj) began pushing malicious versions that silently steal environment variable files, including .env, .env.local, and .env.production, from developers' machines at install time, exfiltrating them to an attacker-controlled endpoint. Versions 2.0.4 through 2.0.7 are confirmed malicious.
&lt;p /&gt;
&lt;A HREF=&quot;https://socket.dev/blog/tanstack-brandsquat-compromise?utm_medium=feed&quot;&gt;https://socket.dev/blog/tanstack-brandsquat-compromise?utm_medium=feed&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;SonicWall SonicOS: Sicherheitslücke erlaubt Management-Interface-Zugriff&lt;/h3&gt;

SonicWall warnt vor drei Sicherheitslücken in SonicOS. [..] Am schwersten wiegt eine Schwachstelle, die die Entwickler als schwache Authentifizierung einstufen. Dadurch können Angreifer unbefugt auf bestimmte, nicht genannte Management-Interface-Funktionen zugreifen - unter ebenfalls nicht genannten Umständen (CVE-2026-0204, CVSS 8.0, Risiko -hoch-).
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/SonicWall-SonicOS-Sicherheitsluecke-erlaubt-Management-Interface-Zugriff-11277522.html&quot;&gt;https://www.heise.de/news/SonicWall-SonicOS-Sicherheitsluecke-erlaubt-Management-Interface-Zugriff-11277522.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;ProFTPD: Codeschmuggel durch mod_sql möglich&lt;/h3&gt;

Laut der Schwachstellenbeschreibung ist mod_sql von ProFTPD vor der Version 1.3.10rc1 von der Sicherheitslücke betroffen. Durch den übertragenen Nutzernamen können bösartige Akteure aus dem Netz ohne vorherige Anmeldung beliebige SQL-Befehle und Schadcode einschleusen. Das gelingt in Szenarien, die USER-Anfragen mit Erweiterungen wie -%U- loggen und in denen das SQL-Backend Befehle zulässt, beispielsweise -COPY TO PROGRAM- (CVE-2026-42167, CVSS 8.1, Risiko -hoch-). [..] Admins sollten daher prüfen, ob sie das mod_sql etwa für Logging in Datenbanken überhaupt einsetzen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/ProFTPD-Codeschmuggel-durch-mod-sql-moeglich-11277942.html&quot;&gt;https://www.heise.de/news/ProFTPD-Codeschmuggel-durch-mod-sql-moeglich-11277942.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Copy Fail: Kritische Linux-Kernel-Schwachstelle ermöglicht lokale Root-Rechte&lt;/h3&gt;

Die Schwachstelle steckt im Linux-Kernel und beruht auf einem simplen, aber schweren Logikfehler. Benutzer:innen können dadurch mit wenig Daten gezielt in eigentlich geschützte Speicherbereiche schreiben. Das reicht aus, um interne Strukturen zu verändern und sich höhere Rechte zu verschaffen. Der Vorgang funktioniert zuverlässig und ohne typische Hürden wie Race Conditions oder spezielle Systemabhängigkeiten.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.cert.at/de/warnungen/2026/4/copy-fail-kritische-linux-kernel-schwachstelle-ermoglicht-lokale-root-rechte&quot;&gt;https://www.cert.at/de/warnungen/2026/4/copy-fail-kritische-linux-kernel-schwachstelle-ermoglicht-lokale-root-rechte&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Thursday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1070640/&quot;&gt;https://lwn.net/Articles/1070640/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-04-30T19:46:15Z</dc:date></entry><entry><title>Tageszusammenfassung - 29.04.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/4/tagesberichte-29042026"/><author><name>CERT.at</name></author><updated>2026-04-29T18:46:53Z</updated><published>2026-04-29T18:46:53Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Dienstag 28-04-2026 18:00 - Mittwoch 29-04-2026 18:00
Handler:     Guenes Holler
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Per Git-Push-Befehl: Angreifer hätten Millionen von Github-Repos kapern können&lt;/h3&gt;

Sicherheitsforscher von Wiz haben eine extrem gefährliche Sicherheitslücke in der internen Git-Infrastruktur von Github entdeckt. Laut Blogbeitrag der Forscher hätten Angreifer durch einen einfachen Git-Push-Befehl Schadcode auf die Backend-Server von Github schleusen und damit tief in die Infrastruktur eindringen können. Auch Github Enterprise Server ist betroffen. [..] Auf Github.com soll die Lücke innerhalb weniger Stunden nach Meldung der Forscher gepatcht worden sein. [..] Wer einen eigenen Github-Enterprise-Server betreibt, muss den Patch hingegen selbst einspielen, sofern noch nicht geschehen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/per-git-push-befehl-angreifer-haetten-millionen-von-github-repos-kapern-koennen-2604-208133.html&quot;&gt;https://www.golem.de/news/per-git-push-befehl-angreifer-haetten-millionen-von-github-repos-kapern-koennen-2604-208133.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Nach Cyberangriff: Hacker erpressen Vimeo mit Nutzerdaten&lt;/h3&gt;

Der berüchtigte Cyberakteur Shinyhunters ist offenbar bei einem Cyberangriff auf einen Dienstleister an Daten der beliebten Videoplattform und Youtube-Alternative Vimeo gelangt. Betroffen sind laut Mitteilung des Betreibers sowohl Nutzer- als auch Kundendaten. [..] Ursache des Datenabflusses war den Angaben zufolge ein Sicherheitsvorfall bei dem KI-Analyseanbieter Anodot. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/cyberangriff-trifft-videoplattform-hacker-erbeuten-nutzerdaten-von-vimeo-2604-208149.html&quot;&gt;https://www.golem.de/news/cyberangriff-trifft-videoplattform-hacker-erbeuten-nutzerdaten-von-vimeo-2604-208149.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure&lt;/h3&gt;

In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has come under active exploitation in the wild within 36 hours of the bug becoming public knowledge. The vulnerability, tracked as CVE-2026-42208 (CVSS score: 9.3), is an SQL injection that could be exploited to modify the underlying LiteLLM proxy database. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example, POST /chat/completions) and reach this query through the proxy's error-handling path.
&lt;p /&gt;
&lt;A HREF=&quot;https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html&quot;&gt;https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;30 ClawHub skills secretly turn AI agents into a crypto swarm&lt;/h3&gt;

Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm - without any malware or user consent.
&lt;p /&gt;
&lt;A HREF=&quot;https://go.theregister.com/feed/www.theregister.com/2026/04/29/30_clawhub_skills_mine_crypto/&quot;&gt;https://go.theregister.com/feed/www.theregister.com/2026/04/29/30_clawhub_skills_mine_crypto/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;CISA flags data-theft bug in NSA-built OT networking tool&lt;/h3&gt;

The Cybersecurity and Infrastructure Security Agency (CISA) is warning anyone who uses GrassMarlin, a tool developed by the National Security Agency (NSA), about a new vulnerability that attackers can use to snoop on sensitive information. [..] GrassMarlin went EOL in 2017, so there are no fixes in the works.
&lt;p /&gt;
&lt;A HREF=&quot;https://go.theregister.com/feed/www.theregister.com/2026/04/29/cisa_flags_datatheft_bug_in/&quot;&gt;https://go.theregister.com/feed/www.theregister.com/2026/04/29/cisa_flags_datatheft_bug_in/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer&lt;/h3&gt;

A new npm supply-chain compromise is targeting the SAP developer ecosystem. [..] The pattern is familiar but also a bit different: a trusted package receives a new preinstall hook, the hook runs a new setup.mjs file, and that loader downloads the Bun JavaScript runtime to execute a large obfuscated payload named execution.js. The payload is an 11.7 MB credential stealer and propagation framework.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.aikido.dev/blog/mini-shai-hulud-has-appeared&quot;&gt;https://www.aikido.dev/blog/mini-shai-hulud-has-appeared&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Fake-Krypto-Casino: Wenn Promis einen Registrierungs-Bonus versprechen&lt;/h3&gt;

Mithilfe übernommener Social-Media-Profile oder geschickt platzierter Werbeanzeigen locken Kriminelle ihre Opfer in angebliche Krypto-Casinos. Durch die Einzahlung von 200 Euro werde ein Registrierungsbonus von 2.500 Euro freigeschaltet. Vor einer Beanspruchung der Gewinne müssen allerdings erst diverse Gebühren und Steuern beglichen werden.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.watchlist-internet.at/news/fake-krypto-casino/&quot;&gt;https://www.watchlist-internet.at/news/fake-krypto-casino/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;RIPE NCC RPKI exploit chain&lt;/h3&gt;

One click on a malicious, but not suspicious, link. That is all it could take for a network operator to get disconnected from the internet, through a chain of vulnerabilities I discovered. From that single click, I could fully control their routing authorisations in a RIPE NCC portal, telling the rest of the internet not to accept their routes. I could also hijack all their RIPE Database objects, locking the legitimate owners out until RIPE NCC staff manually restore them. This attack chain comes down to surprising entry points, risky architectural decisions, and components that don-t look security-critical until they are.
&lt;p /&gt;
&lt;A HREF=&quot;https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/&quot;&gt;https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;IT-Sicherheitsplattform: Anreifer können Wazuh kompromittieren&lt;/h3&gt;

Wie aus dem Sicherheitsbereich der GitHub-Website von Wazuh hervorgeht, ist eine Schwachstelle (CVE-2026-30893) mit dem Bedrohungsgrad -kritisch- eingestuft. Im Zuge einer Path-Traversal-Attacke können Angreifer unbefugt auf eigentlich geschützte Pfade zugreifen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/IT-Sicherheitsplattform-Anreifer-koennen-Wazuh-kompromittieren-11276206.html&quot;&gt;https://www.heise.de/news/IT-Sicherheitsplattform-Anreifer-koennen-Wazuh-kompromittieren-11276206.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Schwachstelle in cPanel und WHM (28. April 2026)&lt;/h3&gt;

Zum 28. April 2026 wurden gravierende Schwachstellen in der Software bekannt. Diese erlauben einen unautorisierte Anmeldung an der cPanel oder WHM Oberfläche.
&lt;p /&gt;
&lt;A HREF=&quot;https://borncity.com/blog/2026/04/29/schwachstelle-in-cpanel-und-whm/&quot;&gt;https://borncity.com/blog/2026/04/29/schwachstelle-in-cpanel-und-whm/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Abermals kritische Sicherheitslücke in Nginx UI geschlossen&lt;/h3&gt;

Eine Schwachstelle (CVE-2026-42238) gilt als -kritisch-. Weil bei jeder Neuinstallation und jedem Neustart die Backup-Restore-Points für zehn Minuten ohne Authentifizierung ansprechbar sind, können entfernte Angreifer manipulierte Backups hochladen. Dabei können sie die Konfigurationsdatei app.ini mit eigenen Befehlen überschreiben und die volle Kontrolle über Instanzen erlangen. Durch das erfolgreiche Ausnutzen einer weiteren Lücke (CVE-2026-42221 -hoch-) können Angreifer im Zuge der Ersteinrichtung Admin-Accounts kapern. Das soll ohne Authentifizierung möglich sein.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11276012&quot;&gt;https://heise.de/-11276012&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Wednesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1070428/&quot;&gt;https://lwn.net/Articles/1070428/&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-04-29T18:46:53Z</dc:date></entry><entry><title>Tageszusammenfassung - 28.04.2026</title><link rel="alternate" href="https://www.cert.at/de/tagesberichte/2026/4/tagesberichte-28042026"/><author><name>CERT.at</name></author><updated>2026-04-28T18:25:25Z</updated><published>2026-04-28T18:25:25Z</published><summary type="html">&lt;h2&gt;End-of-Day report&lt;/h2&gt;


Timeframe:   Montag 27-04-2026 18:00 - Dienstag 28-04-2026 18:00
Handler:     Guenes Holler
Co-Handler:  Michael Schlagenhaufer


&lt;h2&gt;      News       &lt;/h2&gt;


&lt;h3&gt;Open source package with 1 million monthly downloads stole user credentials&lt;/h3&gt;

On Friday, unknown attackers exploited the vulnerability to push a new version of element-data, a command-line interface that helps users monitor performance and anomalies in machine-learning systems. [..] The malicious version was tagged as 0.23.3 and was published to the developers- Python Package Index and Docker image accounts. It was removed about 12 hours later, on Saturday. [..] If you-re one of millions using element-data, it-s time to check for compromise.
&lt;p /&gt;
&lt;A HREF=&quot;https://arstechnica.com/security/2026/04/open-source-package-with-1-million-monthly-downloads-stole-user-credentials/&quot;&gt;https://arstechnica.com/security/2026/04/open-source-package-with-1-million-monthly-downloads-stole-user-credentials/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Windows-Shell-Lücke wird angegriffen&lt;/h3&gt;

Im Februar hat Microsoft eine Windows-Shell-Lücke geschlossen, jedoch unvollständig. Jetzt wurden Angriffe entdeckt. [..] Die Auswirkungen scheinen nicht so gravierend wie vor dem unzureichenden Patch aus dem Februar. [..]  Akamai hat im Blog jedoch eine weitergehende Analyse veröffentlicht. Die IT-Analysten stufen die neue Schwachstelle anders als Microsoft als Zero-Click-Schwachstelle ein. [..] Microsoft hat die neue Schwachstelle CVE-2026-32202 (CVSS 4.3, Risiko -mittel-) am April-Patchday mit Softwareflicken ausgebessert.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Windows-Shell-Luecke-wird-angegriffen-11274647.html&quot;&gt;https://www.heise.de/news/Windows-Shell-Luecke-wird-angegriffen-11274647.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data&lt;/h3&gt;

Application security company Checkmarx has confirmed that the LAPSUS$ threat group leaked data stolen from its private GitHub repository. Although the investigation is ongoing, Checkmarx believes that the access vector was the Trivy supply-chain attack attributed to the hacker group known as TeamPCP. which provided access to credentials from downstream users.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.bleepingcomputer.com/news/security/checkmarx-confirms-lapsus-hackers-leaked-its-stolen-github-data/&quot;&gt;https://www.bleepingcomputer.com/news/security/checkmarx-confirms-lapsus-hackers-leaked-its-stolen-github-data/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cyberangriff trifft Medtronic: Datenklau bei großem Medizintechnik-Konzern&lt;/h3&gt;

Medtronic ist vor allem für seine Herzschrittmacher bekannt. Nun gesteht der Konzern, dass Hacker Daten aus seiner IT-Umgebung abziehen konnten. [..] Shinyhunters hatte Medtronic einem Bericht von Bleeping Computer zufolge schon am 18. April im Darknet erpresst. Die Hackergruppe gab dort an, mehr als neun Millionen Datensätze respektive &quot;Terabytes&quot; an personenbezogenen Daten und anderen unternehmensinternen Informationen erbeutet zu haben. [..] Der Konzern versichert zudem, die Netzwerke seiner Krankenhauskunden seien von den IT-Netzwerken von Medtronic getrennt und würden von den IT-Teams der jeweiligen Kunden gesichert und verwaltet. 
&lt;p /&gt;
&lt;A HREF=&quot;https://www.golem.de/news/datenklau-cyberangriff-trifft-medizintechnik-konzern-medtronic-2604-208080.html&quot;&gt;https://www.golem.de/news/datenklau-cyberangriff-trifft-medizintechnik-konzern-medtronic-2604-208080.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Cyber Threat Intelligence - Art, Science, something else entirely?&lt;/h3&gt;

As everyone who has been in this area for a while can probably still remember, hoarding indicators of compromise is a fun activity and can be incredibly enticing when you have not yet a real clue of what you are doing. It is, at least initially, certainly more interesting than diving straight into anthropological, psychological, sociological, or analytical textbooks. However, as I became more experienced in and, more importantly, more fascinated by the analytical work that makes intelligence .. well, intelligence .. I began to notice that it's not really clear what &quot;type&quot; of activity intelligence analysis is.
&lt;p /&gt;
&lt;A HREF=&quot;https://bytesandborscht.com/cyber-threat-intelligence-art-science-something-else-entirely/&quot;&gt;https://bytesandborscht.com/cyber-threat-intelligence-art-science-something-else-entirely/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Secure-Boot-Zertifikate: Microsoft Defender verschafft Überblick&lt;/h3&gt;

Die Zeit wird knapp: Die Secure-Boot-Zertifikate aus 2011 laufen ab Juni dieses Jahres ab. [..] Im Message-Center der Windows-Release-Health-Notizen hat Microsoft jetzt die neue Funktion für den Microsoft Defender angekündigt. [..] Jetzt können IT-Teams an zentraler Stelle die Verbreitung der Secure-Boot-Zertifikate aus dem Jahr 2023 in ihrem Gerätepark einsehen, erklärt das Unternehmen.
&lt;p /&gt;
&lt;A HREF=&quot;https://www.heise.de/news/Secure-Boot-Zertifikate-Microsoft-Defender-verschafft-Ueberblick-11275033.html&quot;&gt;https://www.heise.de/news/Secure-Boot-Zertifikate-Microsoft-Defender-verschafft-Ueberblick-11275033.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;VECT: Ransomware by design, Wiper by accident&lt;/h3&gt;

VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum. [..] Check Point Research discovers that the VECT 2.0 ransomware permanently destroys -large files- rather than encrypting them.
&lt;p /&gt;
&lt;A HREF=&quot;https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/&quot;&gt;https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;KI-Enkeltrick und Deepfakes: Interpol warnt vor verschärfter Betrugswelle&lt;/h3&gt;

Europa ist zum primären Ziel einer weltweiten Betrugswelle geworden. Laut dem -Global Financial Fraud Threat Assessment 2026- von Interpol verzeichnete keine andere Region einen so starken Anstieg bei Betrugsmaschen: ein Plus von 69 Prozent im Vergleich zum Vorjahr. [..] Der Interpol-Bericht verdeutlicht, dass der Erfolg dieser Betrugsmaschen auf einer hochgradig arbeitsteiligen Unterwelt basiert. Ein Faktor sei die Zunahme von -Fraud-as-a-Service--Modellen.
&lt;p /&gt;
&lt;A HREF=&quot;https://heise.de/-11274056&quot;&gt;https://heise.de/-11274056&lt;/a&gt;




&lt;h2&gt; Vulnerabilities &lt;/h2&gt;


&lt;h3&gt;Xen Security Advisories 20.04.2026&lt;/h3&gt;

Xen has released 5 new security advisories.
&lt;p /&gt;
&lt;A HREF=&quot;https://xenbits.xen.org/xsa/&quot;&gt;https://xenbits.xen.org/xsa/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Mozilla Security Advisories for Firefox 28.04.2026&lt;/h3&gt;

Mozilla has release multiple security advisories for Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. (1x critical)
&lt;p /&gt;
&lt;A HREF=&quot;https://www.mozilla.org/en-US/security/advisories/&quot;&gt;https://www.mozilla.org/en-US/security/advisories/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Notepad++ Releases 8.9.4 Patch to Fix String Injection Vulnerability (CVE-2026-3008) in 8.9.3&lt;/h3&gt;

A vulnerability has been identified in the popular open-source text editor, Notepad++, with the release of CVE-2026-3008. The vulnerability, discovered and reported by CSA under its Responsibility Vulnerability Disclosure Policy, is linked to a potential string injection flaw in Notepad++ version 8.9.3. To mitigate the risk associated with this vulnerability, users and administrators are strongly urged to update their installations to version 8.9.4 immediately.
&lt;p /&gt;
&lt;A HREF=&quot;https://thecyberexpress.com/notepad-cve-2026-3008-vulnerability/&quot;&gt;https://thecyberexpress.com/notepad-cve-2026-3008-vulnerability/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Security updates available in Foxit PDF Reader 2026.1.1 and Foxit PDF Editor 2026.1.1/14.0.4&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.foxit.com/support/security-bulletins.html&quot;&gt;https://www.foxit.com/support/security-bulletins.html&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;LWN: Security updates for Tuesday&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://lwn.net/Articles/1070184/&quot;&gt;https://lwn.net/Articles/1070184/&lt;/a&gt;

&lt;hr&gt;

&lt;h3&gt;Zyxel security advisory for command injection vulnerabilities in certain 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders&lt;/h3&gt;
&lt;p /&gt;
&lt;A HREF=&quot;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-04-28-2026&quot;&gt;https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-04-28-2026&lt;/a&gt;</summary><dc:creator>CERT.at</dc:creator><dc:date>2026-04-28T18:25:25Z</dc:date></entry></feed>
