Tageszusammenfassung - 23.07.2026

End-of-Day report

Timeframe: Mittwoch 22-07-2026 18:00 - Donnerstag 23-07-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke

Am Microsoft-Patchday im Juli waren bereits Angriffe auf eine SharePoint-Schwachstelle bekannt. Die hatte jedoch lediglich den Schweregrad -mittel-. Jetzt warnen IT-Sicherheitsfirmen und -Behörden vor beobachteten Attacken auf eine kritische SharePoint-Lücke, für die ebenfalls ein Softwareflicken seit dem Patchday bereitsteht. Zudem wurden Angriffe auf Check Point SmartConsole beobachtet.

https://www.heise.de/news/Microsoft-SharePoint-Angriffe-auf-weitere-Sicherheitsluecke-11374506.html


China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.

https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html


Linux kernel team publishes 432 CVEs in two days

If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didn-t take long for seasoned sysadmins to start expressing concerns.

https://www.theregister.com/security/2026/07/22/linux-kernel-team-publishes-432-cves-in-two-days/5276497


8000 PCs über Steam infiziert: Cyberkriminelle verteilen Malware via Fake-Games

Cyberkriminelle haben Steam genutzt, um zahlreiche PCs mit Malware zu infizieren. Die Schadsoftware war in Spielen versteckt und wurde gezielt beworben.

https://www.heise.de/news/8-000-PCs-ueber-Steam-infiziert-Cyberkriminelle-verteilen-Malware-via-Fake-Games-11376061.html


Chaos ransomwares msaRAT: Living off the browser to build a covert C2 channel

Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data.

https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/


New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs

Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.

https://hackread.com/new-trickbot-variant-dns-control-infected-windows-pcs/


Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)

Today we walk through Dark Elevator, a LPE in Windows 11. We reported it to Microsoft on May 20, 2026, and it is now fixed as CVE-2026-50343.

https://blog.calif.io/p/dark-elevator-windows-install-service


RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel-s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode.

https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600


Silent Replacement of Trusted macOS App Executables

A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix.

https://mysk.blog/2026/07/23/macos-overwrite-app-executables/


Next chapter: Restructuring GitHub-s bug bounty program

GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team.

https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/


The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security

New category market definition and buyer framework for securing users, agents, identities, and data at the endpoint. A five zone framework for securing AI-centric software at the endpoint.

https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control


New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.

https://socket.dev/blog/slopsquatting-targets-across-frontier-llms?utm_medium=feed

Vulnerabilities

VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability

Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version.

https://kb.cert.org/vuls/id/847406


Atlassian: Schadcode-Lücken bedrohen Bamboo und Bitbucket

Nutzen Angreifer erfolgreich Sicherheitslücken in Atlassian Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, Jira Service Management oder Sourcetree für macOS/Windows aus, können sie PCs im schlimmsten Fall vollständig kompromittieren. Sicherheitsupdates stehen zum Download bereit.

https://www.heise.de/news/Atlassian-Schadcode-Luecken-bedrohen-Bamboo-und-Bitbucket-11375008.html


Drupal Security Advisories 2026-July-22

https://www.drupal.org/security


Ricoh MFP and Printer Products: Vulnerability in SSH Function

https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-000006


LWN Security updates for Thursday

https://lwn.net/Articles/1084401/