Tageszusammenfassung - 27.07.2026

End-of-Day report

Timeframe: Freitag 24-07-2026 18:00 - Montag 27-07-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

SourTrade: Malvertising-Malware im Browser kompiliert

IT-Forscher haben eine mittels Malvertising verteilte Malware entdeckt. Die wird erst im Browser zusammengebaut.

https://www.heise.de/news/SourTrade-Malvertising-Malware-im-Browser-kompiliert-11378977.html


How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026

Ransomware-s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.

https://thecyberexpress.com/the-gentlemen-ransomware-group/


ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.

https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/


Landes-Geheimdienstchef Kramer: OpenAI-Hackerangriff war "kein Skynet-Szenario"

Nach dem Hackerangriff auf Hugging Face mahnt der Thüringer Verfassungsschutz zur Besonnenheit. Er forderte aber ein KI-Frühwarnsystem für die Sicherheitsbehörden.

https://www.golem.de/news/landes-geheimdienstchef-kramer-openai-hackerangriff-war-kein-skynet-szenario-2607-211287.html


Alle Daten gelöscht: US-Bürger wegen Nutzung einer GrapheneOS-Funktion angeklagt

Ein Mann wurde bei der Einreise in die USA durchsucht. Er trickste die Grenzpolizei mit einem Duress-Passwort aus - und muss sich dafür nun vor Gericht verantworten.

https://www.golem.de/news/alle-daten-geloescht-us-buerger-wegen-nutzung-einer-grapheneos-funktion-angeklagt-2607-211299.html


Zugangsdaten im Visier: Hacker beim Datenklau über Hotel-WLANs erwischt

Eine russische Hackergruppe kapert wohl WLAN-Ausrüstung in Einrichtungen, um systematisch Microsoft-Zugangsdaten abzugreifen.

https://www.golem.de/news/zugangsdaten-im-visier-hacker-beim-datenklau-ueber-hotel-wlans-erwischt-2607-211305.html


Datenpanne in Gebets-App: Sicherheitslücke in "Gottes Tech-Stack" aufgedeckt

Eine Forscherin hat die offizielle Gebets-App des Papstes untersucht. "Gottes Tech-Stack" erwies sich als angreifbar und leakte Nutzerdaten.

https://www.golem.de/news/700-000-nutzer-betroffen-suendhaftes-datenleck-bei-gebets-app-des-papstes-2607-211313.html


BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.

https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html


DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.

https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html


Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools.

https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html


Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update

One bug disabled the security service on restart, another blocked installation on hardened RHEL systems

https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpoint-leaves-some-linux-boxes-defenseless-after-update/5278914


Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX.

https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor


Geburtstagsgeschenk von Rituals? Vorsicht vor dieser Abofalle!

Viele bekannte Marken überraschen ihre Kund:innen zum Geburtstag mit kleinen Geschenken. Genau dieses Vertrauen machen sich Kriminelle zunutze: Sie verschicken gefälschte E-Mails im Namen von Rituals und locken mit einem Geschenkset. In Wahrheit landen die Opfer in einer teuren Abofalle.

https://www.watchlist-internet.at/news/geburtstagsgeschenk-von-rituals-vorsicht-vor-dieser-abofalle/


Tenant-Übernahme möglich und drei kritische Sicherheitslücke in MS-Infrastruktur

Jeffrey Schwartz berichtet von der BlackHat 2026 in den USA, und einem speziellen Thema: Die Standard-Einstellung in Azure Automation ermöglichte eine mandantenübergreifende Identitätsübernahme. Dann gab es drei kritische Sicherheitslücken in der Infrastruktur von Microsoft (u.a. bei Bing Images), die die Ausführung von Remote-Code (RCE) ermöglichen. Kleine Nachschau zu diesen Sachverhalten.

https://borncity.com/blog/2026/07/27/tenant-uebernahme-moeglich-und-drei-kritische-sicherheitsluecke-in-ms-infrastruktur/


Fake Corepack Site Distributes Infostealer and Proxyware to Developers

A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware?utm_medium=feed


Project ORBITAL

The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.

https://blog.bushidotoken.net/2026/07/project-orbital.html


Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution

A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on default GitLab installations.

https://thecyberexpress.com/gitlab-vulnerability-oj-parser-rce/

Vulnerabilities

Angreifer können MongoDB abstürzen lassen und Daten manipulieren

Die MongoDB-Entwickler haben in aktuellen Versionen zahlreiche Sicherheitslücken geschlossen. Bislang gibt es keine Hinweise auf laufende Attacken.

https://heise.de/-11378494


Sicherheitsupdate: Dateitransferlösung MOVEit ist verwundbar

Admins, die in Unternehmen für den Dateitransfer MOVEit nutzen, sollten die Software zeitnah auf den aktuellen Stand bringen. Geschieht das nicht, kann im schlimmsten Fall Schadcode auf PCs gelangen. Die Entwickler haben in einer neuen Version mehrere Schwachstellen geschlossen.

https://heise.de/-11379295


LWN Security updates for Monday

https://lwn.net/Articles/1085554/