End-of-Day report
Timeframe: Donnerstag 27-08-2026 18:00 - Freitag 28-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
News
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut is warning that hackers are actively exploiting a
vulnerability in all versions of its PaperCut NG and PaperCut MF print
management software in zero-day attacks.
https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against
a critical security flaw exploited in ongoing remote code execution
attacks, according to cybersecurity watchdog Shadowserver.
https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
Patch-Defizit in Deutschland: Exploit gefährdet 85 Prozent aller
Exchange-Server
Auf Github ist ein Exploit für eine gefährliche Exchange-Lücke
aufgetaucht. Einen Patch gibt es zwar, doch den haben in Deutschland
nur wenige installiert.
https://www.golem.de/news/patch-defizit-in-deutschland-exploit-gefaehrdet-85-prozent-aller-ex
change-server-2608-212397.html
APT28-Linked HOOKEDGE Backdoor Targets European Government and
Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns
targeting government and diplomatic organizations in Romania, Spain,
and Türkiye between late September 2025 and early April 2026.These
campaigns, per Recorded Future Insikt Group, ..
https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html
Critical cPanel Flaw Could Let One Hosting Customer Take Root
Control of a Whole Server
cPanel has released patches for a security flaw affecting domain
parking and addon domain functionality in cPanel and WebHost Manager
(WHM), which could allow code execution as the root user.The
vulnerability, assigned the CVE identifier CVE-2026-65643, ..
https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated
Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the
ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring
system and exploitable, in certain circumstances, by an unauthenticated
attacker.The company said it deployed a ..
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
19 Chrome and Edge Extensions Found With Wallet-Stealing and
Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome
and one Microsoft Edge extensions that were published over the last six
months and harbored wallet secret stealing and cryptocurrency draining
capabilities.The extensions, per ..
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
AI girlfriend review sites secrets were exposed to the world for
three weeks
Even testing and staging sites need protection from prying eyes.
https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-secrets-were-exposed-to-the-world-for-three-weeks/5293064
CRPx0 hacking service for dummies claims victim count more than
quintupled
Its built to be operated by a human with no technical background.
https://www.theregister.com/cyber-crime/2026/08/27/crpx0-hacking-service-for-dummies-claims-victim-count-more-than-quintupled/5293097
TeamViewer schließt hochriskante Lücken in Clients
Die TeamViewer-Clients können Angreifern das Ausführen von Schadcode
ermöglichen. Updates stopfen die hochriskanten Sicherheitslücken.
https://www.heise.de/news/TeamViewer-stopft-Codeschmuggel-Leck-11432840.html
Google macht Android 17 sicherer: ECH-Unterstützung und
2G-Abschaltung
Mit Android 17 führt Google neue Netzwerksicherheitsfunktionen ein.
Diese sollen Verbindungen absichern und die Privatsphäre im heimischen
WLAN schützen.
https://www.heise.de/news/2G-Abschaltung-und-ECH-Support-Android-17-erhoeht-die-Netzwerksicherheit-11432832.html
-Begrenztes Zeitfenster-: Mehr als 100 Unternehmen warnen vor
KI-Cyberangriffen
Führende KI-Labore sowie mehr als 100 Organisationen warnen in einem
offenen Brief vor einer baldigen Zunahme KI-gestützter Cyberangriffe.
https://www.heise.de/news/Begrenztes-Zeitfenster-Mehr-als-100-Unternehmen-warnen-vor-KI-Cyberangriffen-11432718.html
Zwei kritische Lücken in Next.js - Remote-Code-Ausführung unter
Windows
Die zwei kritischen von Vercel gemeldeten Lücken im
JavaScript-Framework Next.js ermöglichen es Angreifern, Code
auszuführen.
https://www.heise.de/news/Zwei-kritische-Luecken-in-Next-js-Remote-Code-Ausfuehrung-unter-Windows-11433140.html
(OEM-)China-Router von ZBT mit Backdoors
IT-Forscher haben Router vom OEM-Hersteller ZBT untersucht, die
weltweit von Anbietern verkauft werden. Darin fanden sie Backdoors.
https://www.heise.de/news/OEM-China-Router-von-ZBT-mit-Backdoors-11433072.html
Disruptive cyber activity highlights risk from internet-exposed
systems and edge devices
Targeting of operational technology reinforces the need for
organisations to understand what is exposed to the internet, address
avoidable vulnerabilities, and build long-term cyber resilience.
https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices
Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to
Target Credentials and Secrets
GreyNoise is observing automated scanners posing as the web crawlers of
OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged
user agents while requesting the files where misconfigured web servers
frequently leak secrets and credentials.
https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers
Inside 90 days of attacks on AI infrastructure
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers,
and AI frameworks through RCE, blind prompt injection, and memory
credential theft.
https://www.wiz.io/blog/ai-infrastructure-honeypot