End-of-Day report
Timeframe: Montag 24-08-2026 18:00 - Dienstag 25-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
News
Police arrests dozens of suspects in global cybercrime crackdown
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups.
https://www.bleepingcomputer.com/news/security/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown/
Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/
Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk
Third-party scripts are common on websites. They help with analytics, ads, live chat, social media, video, payments, and many other features. While not all are risky, every external tag, pixel, widget, or embed adds to your website-s vulnerability. These tools can read page content, collect visitor data, change what users see, and connect ..
https://blog.sucuri.net/2026/08/third-party-script-security-how-tags-pixels-and-embeds-can-put-websites-at-risk.html
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including ..
https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor ..
https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.While threat actors are ..
https://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.html
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.The findings were ..
https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html
You dont want this Sleepwalker backdoor on your Windows machine
Its own command language, 23 instructions - signs point to well-resourced operation rather than an opportunistic one
https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021
Crooks push Mac malware through fake OpenAI Codex ads
Sponsored search results lead developers straight into a ClickFix malware trap
https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads/5291899
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
Disclosed in January and honeypots buzzed soon after, CISA says it-s finally time for the USG to plug the gap
https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/5292107
Kriminalisierung: Informatiker verlangen Freipass für IT-Sicherheitsforscher
Die Gesellschaft für Informatik fordert die Bundesregierung auf, ethische Hacker endlich wirksam vor Strafverfolgung zu schützen.
https://www.heise.de/news/Kriminalisierung-Informatiker-verlangen-Freipass-fuer-IT-Sicherheitsforscher-11424219.html
Angreifer nehmen Oracle Weblogic und HTTP-Server ins Visier
Angreifer missbrauchen eine Sicherheitslücke in Oracle HTTP-Server und Weblogic Server, die komplette Kompromittierung ermöglicht.
https://www.heise.de/news/Attacken-auf-Oracle-Weblogic-und-HTTP-Server-beobachtet-11424527.html
Zugriffsverwaltung Keycloak: Kontoübernahme durch Passwort-Rücksetzfunktion
In dem Identitäts- und Zugriffssteuerungssystem Keycloak können Angreifer einen Fehler beim Passwort-Rücksetzen missbrauchen, um Konten zu übernehmen.
https://www.heise.de/news/Zugriffsverwaltung-Keycloak-Kontouebernahme-durch-Passwort-Ruecksetzfunktion-11424729.html
WhatsApp führt mehrere Passkeys ein und ersetzt PINs
WhatsApp verbessert die Kontosicherheit durch die Unterstützung mehrerer Passkeys, stärkere Passwörter und Kontextinformationen bei unbekannten Anrufen.
https://www.heise.de/news/WhatsApp-Mehr-Passkeys-und-verbesserte-Sicherheit-bei-unbekannten-Anrufen-11425433.html
Phishing-Versuch greift Login-Daten für Onlinebroker ab
Eine SMS-Nachricht, ein Login-Portal - und fertig ist die Phishing-Falle. Kriminelle versenden aktuell im Namen des Onlinebrokers -flatex- Warnungen vor dem Ablaufen der für Überweisungen benötigten iTAN-Card. Über die Fake-Anmeldeseite wollen sie an Benutzername und Passwort ihrer Opfer gelangen.
https://www.watchlist-internet.at/news/phishing-login-daten-onlinebroker/
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
To assess the impact of AI-enabled malware, we collected and analyzed over 400 malware samples that integrate AI in some capacity, from brand impersonation and large language model (LLM)-generated code to agentic execution loops. Our central finding was that the AI malware space is currently overwhelmingly composed of ..
https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
Large DDoS attack knocks Norwegian public services offline
The Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.
https://therecord.media/norway-cyberattack-ddos-government
A Tale of Two SOCs: Insights From Two Red Team Assessments
The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but ..
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
ToxNetV2: An AI-Assisted Botnet Controller
ToxNetV2 is an AArch64 Linux peer-to-peer botnet that integrates an LLM into the operational workflow of its controller. As uncovered in the Joe Reverser analysis, the controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval. The resulting ..
https://www.joesecurity.org/blog/6764463444623599134
Open VSX Unblocks Extension IDs Used in Malware Campaign
Over a five-day period from August 16 through August 20, the registry unblocked AlDuncanson.react-hooks-snippets, magne-sjaastad.opm-flow-editor-support, and rumbledb.jsoniq-vscode. All three IDs had been used by impostors in the 77-extension evil-twin campaign documented by Manifold Security earlier this month. Legitimate versions of the OPM and RumbleDB ..
https://socket.dev/blog/open-vsx-unblocks-malicious-extension-ids
Vulnerabilities
TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025
TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023
TYPO3-EXT-SA-2026-021: Broken Access Control in extension "Forum" (pforum)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021