Tageszusammenfassung - 24.08.2026

End-of-Day report

Timeframe: Freitag 21-08-2026 18:00 - Montag 24-08-2026 18:00 Handler: Alexander Riepl Co-Handler: n/a

News

How an Emerging Industrial Protocol Family Could Put OT at Risk

New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes.

https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protocol-family-put-ot-at-risk


Nach Hackerangriff: Berliner Senat überrascht über Größe des IT-Systems

Nach einem Hackerangriff sind zwei Berliner Verwaltungen wieder am Netz. Es gibt jedoch weiter Verdachtsmomente für eine Infiltration.

https://www.golem.de/news/nach-hackerangriff-berliner-senat-ueberrascht-ueber-groesse-des-it-systems-2608-212218.html


Missbrauch von Passkeys: Phishing-Toolkit soll Passwort-Reset umgehen können

Ein ab 10.000 US-Dollar gehandeltes Phishing-Toolkit soll Angreifern über Passkeys einen dauerhaften Zugriff etwa auf gekaperte Google-Konten verleihen.

https://www.golem.de/news/missbrauch-von-passkeys-phishing-toolkit-soll-passwort-reset-umgehen-koennen-2608-212226.html


Security vets rally around $4 paper password books for sale in Australia

Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026

https://www.theregister.com/security/2026/08/24/security-vets-rally-around-4-paper-password-books-for-sale-in-australia/5291234


AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a devs headphones

Sawtooth waves you cant hear still mess with your Bluetooth. Firefox and Brave say theyve got you covered

https://www.theregister.com/security/2026/08/24/aliexpress-accused-of-fingerprinting-shoppers-with-silent-audio-trick-that-also-muted-a-devs-headphones/5291662


The curious case of the effortful fraud

How what looked like a generic phishing site seemingly turned out to be a put-some-effort-into it, targeted fraud.

https://bytesandborscht.com/the-curious-case-of-the-effortful-fraud/


Britische Regierung bestätigt Cyberattacke auf Kraftwerk

Für vier Tage haben Angreifer in Großbritannien ein Kraftwerk abgeschaltet. Die Behörden warnen und besänftigten zugleich.

https://www.heise.de/news/Britische-Regierung-bestaetigt-Cyberattacke-auf-Kraftwerk-11422989.html


Microsoft stopft zahlreiche Cloud-Schwachstellen

Microsoft dokumentiert 18 teils kritische Sicherheitslücken in Cloud-Produkten, die die Entwickler geschlossen haben.

https://www.heise.de/news/Microsoft-stopft-zahlreiche-Cloud-Schwachstellen-11423129.html


-GTA 6--ISO: Vermeintliche Leak-Abbilddatei voller Malware

Bösartige Akteure bieten das vermeintlich geleakte ISO von -GTA 6- im Netz an. Die 113 GByte enthalten aufgepumpte Virendaten.

https://www.heise.de/news/GTA-6-ISO-Vermeintliche-Leak-Abbilddatei-voller-Malware-11423363.html


Notepad++ v8.9.8 stopft 14 Sicherheitslücken

Am Sonntag hat Don Ho Version 8.9.8 des beliebten Editors Notepad++ herausgegeben. Sie schließt etwa Codeschmuggellücken.

https://www.heise.de/news/Notepad-v8-9-8-stopft-14-Sicherheitsluecken-11423868.html


And then the men with guns tell you to do it anyway

Perhaps you can think of a way to design an alerting system which cannot be abused - but I can't.

https://shkspr.mobi/blog/2026/08/and-then-the-men-with-guns-tell-you-to-do-it-anyway/


Everything I own, owned

Over the past couple weeks I-ve been doing agent-driven reverse engineering of peripherals that happen to be within arm-s reach. From those devices, I-ve come away with a full plaintext command shell inside my microphone, a webcam whose activity LED I can switch off while it records, and a key light that hands out memory writes to anyone on the WiFi.

https://schlarp.com/posts/everything-i-own-owned/


Building certgrep.sh: a free certificate transparency search engine

Certificate transparency is one of the best public datasets in security. Every certificate issued by a publicly trusted certificate authority lands in an append-only, cryptographically verifiable log, usually before the certificate is ever used. For anyone hunting malicious infrastructure, that makes certificate transparency (CT) one of the earliest ..

https://haveibeensquatted.com/blog/building-certgrep


Vulnerabilities

The Fabrik Fiasco: Announced, Restricted, Relabelled

https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/


Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

https://mysites.guru/blog/fabrik-4-7-2-security-release/