Tageszusammenfassung - 29.07.2026

End-of-Day report

Timeframe: Dienstag 28-07-2026 18:00 - Mittwoch 29-07-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

vBulletin fixes critical pre-auth RCE flaw with public exploit

A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [..] SSD Secure Disclosure has also published a technical analysis for CVE-2026-61511, explaining that the sanitization restrictions can be bypassed using the so-called -phpfuck- technique. [..] CVE-2026-61511 was reported to vBulletin on June 25, 2026, and version 6.2.2, which addressed the flaw, was released on July 1.

https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/

Passwort-Hashes auslesbar: 20 Jahre alte BMC-Lücke gefährdet über 24.000 Server

Sicherheitsforscher von Lava haben 24.650 über das Internet erreichbare und für die Verwaltung von Serversystemen genutzte Baseboard Management Controller (BMC) ausfindig gemacht, die aufgrund einer zwei Jahrzehnte alten Sicherheitslücke Passwort-Hashes leaken. [..] Die Sicherheitslücke ist zwar, wie schon die CVE-ID erahnen lässt, erst 2013 öffentlich bekannt geworden, nach Angaben der Forscher war sie aber schon von Beginn an in IPMI 2.0 enthalten - und damit seit 2004. Trotz dieses Alters sind noch heute 36.872 Server-BMCs über IPMI erreichbar und davon 24.650 anfällig für CVE-2013-4786, wie Lava auf einem eigenen Dashboard zeigt.

https://www.golem.de/news/passwort-hashes-auslesbar-20-jahre-alte-bmc-luecke-gefaehrdet-ueber-24-000-server-2607-211397.html

CubePilot drone software dev hit by DNS hijacking to intercept traffic

CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack.

https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/

Nationale Sicherheit: FCC verbietet Importe chinesischer Roboter

Die US-Fernmeldebehörde FCC verbietet die Zulassung neuer chinesischer Roboter und Wechselrichter wegen angeblicher Sicherheitsrisiken.

https://www.golem.de/news/nationale-sicherheit-fcc-verbietet-importe-chinesischer-roboter-2607-211388.html

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html

JFrogs 0-days let OpenAIs models hack Hugging Face

We now know how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog-s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman. While Landman wouldn't confirm that these flaws were the zero-days that OpenAI-s models found and exploited, ultimately allowing them to breach the massive model mart, OpenAI later admitted the connection.

https://www.theregister.com/security/2026/07/28/jfrogs-0-days-let-openais-models-hack-hugging-face/5280001

Some notes about Anthropic-s new results

Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is an improved attack against reduced-round AES. Anthropic also released a blog post describing the research process that produced these results.

https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/

Attackers Are Turning Microsoft-s Trusted Login System Into Their Latest Phishing Weapon

Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft-s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft-s trusted authentication flow while concealing its malicious intent.

https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon/

Fake-PayPal-Mails: Rückerstattung und Abbuchung als Köder

Kriminelle verschicken derzeit gefälschte PayPal-Nachrichten, um an Zugangsdaten und Bankdaten zu gelangen. Eine Mail lockt mit einer Rückzahlung von 95,66 Euro, die andere warnt vor einer Abbuchung von 909,00 Euro.

https://www.watchlist-internet.at/news/fake-paypal-mails-rueckerstattung-und-abbuchung-als-koeder/

GitHub Blog: Disrupting supply chain attacks on npm and GitHub Actions

Explore the changes weve shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.

https://github.blog/security/supply-chain-security/disrupting-supply-chain-attacks-on-npm-and-github-actions/

Vulnerabilities

Gitea: Remote Code Execution via diffpatch Git Hook Installation

Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository. CVE-2026-60004

https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m

Broadcom: VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. [..] VMware vCenter contains a directory traversal vulnerability in the Syslog server. [..] VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Jetbrains: Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) - Update to 2025.11.7 or 2026.1.3 Now

A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077. If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.

https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/

OpenWrt: Updates schließen teils kritische Sicherheitslücken

Das OpenWrt-Projekt hat aktualisierte Fassungen veröffentlicht, die teils als kritisches Risiko eingestufte Sicherheitslücken stopfen. [..] Mit einem einzigen UDP-Paket können Angreifer aus dem Netz ohne vorherige Anmeldung den Pufferüberlauf ausnutzen.

https://heise.de/-11381496

LWN: Security updates for Wednesday

https://lwn.net/Articles/1086031/

Node.js: Wednesday, July 29, 2026 Security Releases

https://nodejs.org/en/blog/vulnerability/july-2026-security-releases