End-of-Day report
Timeframe: Freitag 07-08-2026 18:00 - Montag 10-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
News
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/
AI-Generated Patches Fail Half the Time
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
https://www.darkreading.com/application-security/ai-generated-patches-fail-half-time
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.
https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
No, no nasties to see here, guv...
https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china/5285430
Sensitive Info Goes Into -No Reply- Emails Constantly. This Guy Sees It All
Two security researchers bought cheap domains-including noreply.net and deleteduser.com-and set up email listening services. Hundreds of companies are sending them corporate secrets.
https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/
Russian military hackers pose as recruiters to target Ukrainian IT workers
Ukraine-s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia-s GRU military intelligence agency.
https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers
Jeans-Hersteller Levi Strauss & Co. erleidet Datenpanne
Levi Strauss, als Anbieter von Jeans bekannt, hat die Woche einen Datenschutzvorfall erlitten. Mitarbeiter wurden über Social Media ausgetrickst. Dem Angreifer gelang dann wohl der Zugriff auf drei Rechner von Mitarbeitern.
https://borncity.com/blog/2026/08/08/jeans-hersteller-levi-strauss-co-erleidet-datenpanne/
SANS Institute rät Sicherheitsteams, offene Türen für KI-Agenten zu schließen
Die Sicherheitsvorfälle bei Anthropic, Open AI und Meta, sowie bei Bytedance, bei denen AI-Modelle oder Agenten aus ihrer Testumgebung ausbrachen und Angriff im Internet durchführten, hat die Branche aufgeschreckt. Das SANS Institute gibt Sicherheitsteams den Tipp: Offene Türen für KI-Agenten zu schließen.
https://borncity.com/blog/2026/08/09/sans-institute-raet-sicherheitsteams-offene-tueren-fuer-ki-agenten-zu-schliessen/
Investigating a Multi-Stage PowerShell Loader
During recent threat hunting, I identified suspicious PowerShell content being served directly from an IP address and a domain: hxxp://203[.]188[.]171[.]166/hxxps://dorenzaa[.]com/ Both locations returned PowerShell rather than a conventional user-facing webpage. The PowerShell was responsible for retrieving a ZIP archive from Vercel-hosted infrastructure, extracting it locally, and executing an executable from the extracted content.
https://malwr-analysis.com/2026/08/08/investigating-a-multi-stage-powershell-loader/
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
Vulnerabilities
Jetzt patchen! Admin-Attacken auf Metabase beobachtet
Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln.
https://heise.de/-11404526
Schadcode-Attacken auf Progress LoadMaster im Gange
Derzeit haben Angreifer Progress LoadMaster auf dem Schirm und attackieren aktiv Systeme. Sicherheitspatches sind verfügbar.
https://heise.de/-11404612
LWN Security updates for Monday
https://lwn.net/Articles/1088057/
Security updates 1.6.18 and 1.7.3 released
https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3