Tageszusammenfassung - 30.07.2026

End-of-Day report

Timeframe: Mittwoch 29-07-2026 18:00 - Donnerstag 30-07-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

HelloNet campaign: new malicious modules launched through the ViPNet update system

We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).

https://securelist.com/tr/hellonet-vipnet/120700/

Toy Ghouls- new toy: the GenieLocker ransomware

The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian).

https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/

Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)

Most of what an internet-facing SSH honeypot records is noise. Endless password guessing, and bots that log in, immediately pull down a payload, and move on. On 27 June 2026 my honeypot caught something quieter, and to me more interesting. A bot logged in as root, ran a careful survey of the machine's hardware, and then disconnected without downloading or running anything at all. No malware, no persistence, no second stage.

https://isc.sans.edu/diary/rss/33198

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.

https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.

https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html

Verschlüsselt, aber falsch: Gruppenchats anfällig für manipulierte Inhalte

Alle Mitglieder eines Gruppenchats sollten dieselben Inhalte sehen. Die üblichen Chat-Dienste stellen das nicht sicher. Das ist riskant.

https://www.heise.de/news/Verschluesselt-aber-falsch-Gruppenchats-anfaellig-fuer-manipulierte-Inhalte-11384095.html

Vermeintliche Zollgebühren der Post sind fake!

Eine offene Paketgebühr, ein Link zur Zahlung und eine täuschend echt aussehende Nachricht der Österreichischen Post. Mit dieser Masche versuchen Kriminelle derzeit, an Bankdaten zu gelangen.

https://www.watchlist-internet.at/news/phishing-oesterreichischen-post-zoll/

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.

https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/

Adform compromised to serve crypto stealer via supply chain attack

Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category.

https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e?source=rss8343faddf0ec4

CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software

Tailored Guidance to Use and Understand OSS Solutions, Contribute to and Produce Projects, and Evaluate AI Models.

https://www.cisa.gov/news-events/news/cisa-guide-helps-federal-agencies-securely-and-effectively-use-open-source-software

Vulnerabilities

Angreifer missbrauchen Backdoor in Ciscos Firewall-Verwaltungssoftware

Angreifer missbrauchen fest einprogrammierte Zugangsdaten in Ciscos Firewall-Verwaltungssoftware. Updates sollen dagegen helfen.

https://www.heise.de/news/Angreifer-missbrauchen-Backdoor-in-Ciscos-Firewall-Verwaltungssoftware-11384735.html

Chrome-Update stopft weitere 370 Sicherheitslecks

Google hat wieder ein massives Sicherheitsupdate für Chrome veröffentlicht. Sieben der geschlossenen Lücken gelten als kritisch.

https://heise.de/-11384153

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh

Progress: LoadMaster Critical Security Bulletin - July 2026 - (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690)

https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690

GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/

Drupal Security Advisories 2026-July-29

https://www.drupal.org/security

Publish DFIR-IRIS advisories

https://github.com/sbaresearch/advisories/commit/0e542378f16ec1052b5ad032b487b10bbb7953a3

LWN Security updates for Thursday

https://lwn.net/Articles/1086225/