End-of-Day report
Timeframe: Freitag 24-07-2026 18:00 - Montag 27-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
SourTrade: Malvertising-Malware im Browser kompiliert
IT-Forscher haben eine mittels Malvertising verteilte Malware entdeckt. Die wird erst im Browser zusammengebaut.
https://www.heise.de/news/SourTrade-Malvertising-Malware-im-Browser-kompiliert-11378977.html
How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026
Ransomware-s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.
https://thecyberexpress.com/the-gentlemen-ransomware-group/
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/
Landes-Geheimdienstchef Kramer: OpenAI-Hackerangriff war "kein Skynet-Szenario"
Nach dem Hackerangriff auf Hugging Face mahnt der Thüringer Verfassungsschutz zur Besonnenheit. Er forderte aber ein KI-Frühwarnsystem für die Sicherheitsbehörden.
https://www.golem.de/news/landes-geheimdienstchef-kramer-openai-hackerangriff-war-kein-skynet-szenario-2607-211287.html
Alle Daten gelöscht: US-Bürger wegen Nutzung einer GrapheneOS-Funktion angeklagt
Ein Mann wurde bei der Einreise in die USA durchsucht. Er trickste die Grenzpolizei mit einem Duress-Passwort aus - und muss sich dafür nun vor Gericht verantworten.
https://www.golem.de/news/alle-daten-geloescht-us-buerger-wegen-nutzung-einer-grapheneos-funktion-angeklagt-2607-211299.html
Zugangsdaten im Visier: Hacker beim Datenklau über Hotel-WLANs erwischt
Eine russische Hackergruppe kapert wohl WLAN-Ausrüstung in Einrichtungen, um systematisch Microsoft-Zugangsdaten abzugreifen.
https://www.golem.de/news/zugangsdaten-im-visier-hacker-beim-datenklau-ueber-hotel-wlans-erwischt-2607-211305.html
Datenpanne in Gebets-App: Sicherheitslücke in "Gottes Tech-Stack" aufgedeckt
Eine Forscherin hat die offizielle Gebets-App des Papstes untersucht. "Gottes Tech-Stack" erwies sich als angreifbar und leakte Nutzerdaten.
https://www.golem.de/news/700-000-nutzer-betroffen-suendhaftes-datenleck-bei-gebets-app-des-papstes-2607-211313.html
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.
https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools.
https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update
One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpoint-leaves-some-linux-boxes-defenseless-after-update/5278914
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX.
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
Geburtstagsgeschenk von Rituals? Vorsicht vor dieser Abofalle!
Viele bekannte Marken überraschen ihre Kund:innen zum Geburtstag mit kleinen Geschenken. Genau dieses Vertrauen machen sich Kriminelle zunutze: Sie verschicken gefälschte E-Mails im Namen von Rituals und locken mit einem Geschenkset. In Wahrheit landen die Opfer in einer teuren Abofalle.
https://www.watchlist-internet.at/news/geburtstagsgeschenk-von-rituals-vorsicht-vor-dieser-abofalle/
Tenant-Übernahme möglich und drei kritische Sicherheitslücke in MS-Infrastruktur
Jeffrey Schwartz berichtet von der BlackHat 2026 in den USA, und einem speziellen Thema: Die Standard-Einstellung in Azure Automation ermöglichte eine mandantenübergreifende Identitätsübernahme. Dann gab es drei kritische Sicherheitslücken in der Infrastruktur von Microsoft (u.a. bei Bing Images), die die Ausführung von Remote-Code (RCE) ermöglichen. Kleine Nachschau zu diesen Sachverhalten.
https://borncity.com/blog/2026/07/27/tenant-uebernahme-moeglich-und-drei-kritische-sicherheitsluecke-in-ms-infrastruktur/
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware?utm_medium=feed
Project ORBITAL
The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.
https://blog.bushidotoken.net/2026/07/project-orbital.html
Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on default GitLab installations.
https://thecyberexpress.com/gitlab-vulnerability-oj-parser-rce/
Vulnerabilities
Angreifer können MongoDB abstürzen lassen und Daten manipulieren
Die MongoDB-Entwickler haben in aktuellen Versionen zahlreiche Sicherheitslücken geschlossen. Bislang gibt es keine Hinweise auf laufende Attacken.
https://heise.de/-11378494
Sicherheitsupdate: Dateitransferlösung MOVEit ist verwundbar
Admins, die in Unternehmen für den Dateitransfer MOVEit nutzen, sollten die Software zeitnah auf den aktuellen Stand bringen. Geschieht das nicht, kann im schlimmsten Fall Schadcode auf PCs gelangen. Die Entwickler haben in einer neuen Version mehrere Schwachstellen geschlossen.
https://heise.de/-11379295
LWN Security updates for Monday
https://lwn.net/Articles/1085554/