End-of-Day report
Timeframe: Montag 20-07-2026 18:00 - Dienstag 21-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
News
JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/
Attackers Combo Up Evasion Tactics for BEC Phishing
Researchers at Fortinet since late March have observed the campaign, dubbed "The TFF Trap," which uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger, according to a report published last week. The name comes from attackers' use of a TrueType Font (.ttf) file to hide the AutoIT/Lua loader used to deliver malware.
https://www.darkreading.com/endpoint-security/attackers-combo-evasion-tactics-bec-phishing
LG Monitors Silently Install Adware-Like App On Windows PCs
VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages.
https://hardware.slashdot.org/story/26/07/20/1736218/lg-monitors-silently-install-adware-like-app-on-windows-pcs
Malicious cloud customers can bring down the power grid
The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling.
https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193
AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware
Inside the 7,600-repository FakeGit operation that brought SmartLoader into the AI capability supply chain, using GitHub repositories, public AI registries, and agent-readable instructions to create a new enterprise attack surface.
https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware
What happens if you visit a WordPress site hacked through wp2shell?
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there-s another question worth asking: what happens to ordinary visitors when they land on a compromised site?
https://www.malwarebytes.com/blog/bugs/2026/07/what-happens-if-you-visit-a-wordpress-site-hacked-through-wp2shell
Monday, July 27, 2026 Security Releases
The Node.js project will release new versions of the 26.x, 24.x, 22.x releases lines on or shortly after, Monday, July 27, 2026 in order to address: The highest severity issue fixed in this release is HIGH.
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
Rumänien: Cyberkrimineller löscht die gesamte Grundbuchdatenbank des Landes
Ein Angreifer löscht die gesamte rumänische Grundbuchdatenbank, nachdem eine Erpressung scheiterte, und bringt damit den Immobilienmarkt zum Stillstand.
https://heise.de/-11371451
Passkeys in der Praxis - Teil 1: Die Architektur von Passkeys
So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.
https://heise.de/-11364345
Suno-Datenleck: Have I Been Pwned ergänzt 55 Millionen Konten
Das Have-I-Been-Pwned-Projekt hat mehr als 55 Millionen Konten aus dem Suno-Datenleck zur Datenhalde hinzugefügt.
https://heise.de/-11371843
Vulnerabilities
Zimbra: Patch Release Update: Zimbra 10.1.20
This release contains fixes for multiple critical security issues including a permanent fix for the critical SNMP vulnerability disclosed in our recent security advisory. The release also includes bug fixes in licensing and mail filtering.
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
Sicherheitspatch Grafana: Angreifer können sensible Daten abgreifen
Wie aus einer Warnmeldung von GrafanaLabs hervorgeht, ist die Lücke (CVE-2026-28381) als -kritisch- eingestuft. Dem Beitrag zufolge sind Grafana-Installationen mit aktivem Snowflake-Datasource-Connector von der Schwachstelle betroffen.
https://heise.de/-11371859
LWN: Security updates for Tuesday
https://lwn.net/Articles/1083948/
Mozilla Foundation Security Advisories July 21, 2026
https://www.mozilla.org/en-US/security/advisories/
Tenable: [R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1
https://www.tenable.com/security/tns-2026-19
Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026