Tageszusammenfassung - 31.08.2026

End-of-Day report

Timeframe: Freitag 28-08-2026 18:00 - Montag 31-08-2026 18:00 Handler: Alexander Riepl Co-Handler: n/a

News

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.

https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/

Virenschutz angeblich aus: Microsoft Defender spielt falsche Warnmeldung aus

Einige Windows-Nutzer erhalten seit Wochen Warnmeldungen vom Microsoft Defender, dass der Virenschutz inaktiv sei. Das ist jedoch ein Anzeigefehler.

https://www.golem.de/news/virenschutz-angeblich-aus-microsoft-defender-spielt-falsche-warnmeldung-aus-2608-212431.html

ValleyRAT masquerading as adware

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

https://securelist.com/valleyrat-backdoor-adware/121175/

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/

The Linux Kernel Is Approaching 2,000 CVEs Per Release

Phoronix reports on Greg Kroah-Hartmans recent slide from his upcoming talk in Paris at Kernel Recipes 2026 (September 21 to 23):With the proliferation of AI/LLM models analyzing the Linux kernels vast codebase, there has been a surge in the number of CVEs per kernel release. After typically being around 500 CVEs fixed per release, we are now approaching ..

https://linux.slashdot.org/story/26/08/29/0547248/the-linux-kernel-is-approaching-2000-cves-per-release

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor ..

https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html

Microsoft Teams Has Become a Haven for Scammers in China

Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.

https://www.wired.com/story/microsoft-teams-is-becoming-a-haven-for-chinese-scammers/

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.

https://www.wired.com/story/atm-flaws-reveal-key-weaknesses-in-the-software-supply-chain/

30 Bitcoin oder Leak - Ransomware-Bande erpresst Berlin

Die Gruppe -Rhysida- will 30 Bitcoin von Berlin, oder vertrauliche Daten veröffentlichen. Die Stadt will nicht zahlen, sagte Kai Wegner.

https://www.heise.de/news/30-Bitcoin-oder-Leak-Ransomware-Bande-erpresst-Berlin-11434325.html

Exchange-Sicherheitslücke: 85 Prozent der On-Prem-Server in Deutschland anfällig

Ein Proof-of-Concept-Exploit für eine hochriskante Exchange-Lücke ist öffentlich. 85 Prozent der On-Premises-Server sind anfällig.

https://www.heise.de/news/Exchange-Sicherheitsluecke-85-Prozent-der-On-Prem-Server-in-Deutschland-anfaellig-11434785.html

Root-Sicherheitslücke bedroht cPanel/WHM

In aktuellen Versionen haben die Entwickler der Webhosting-Control-Panel-Software cPanel/WHM eine Schwachstelle geschlossen.

https://www.heise.de/news/Root-Sicherheitsluecke-bedroht-cPanel-WHM-11434895.html

WatchGuard Security-Appliances: Schadcode-Lücken in Firebox OS geschlossen

Firewalls und VPN-Technik von WatchGuard sind attackierbar. Reparierte Versionen von Firebox OS sind verfügbar.

https://www.heise.de/news/WatchGuard-Security-Appliances-Schadcode-Luecken-in-Firebox-OS-geschlossen-11434937.html

Überwachungs-Schnittstellen in weltweit verkauften Routern aus China entdeckt

"EndlessDoors", "DarkLantern" und "SpeakingStone" geben Zugriff, wo keiner sein sollte. Die Router von ZBT werden unter verschiedenen Marken angeboten

https://www.derstandard.at/story/3000000337615/ueberwachungs-schnittstellen-in-weltweit-verkauften-routern-aus-china-entdeckt

"Gravierende Sicherheitslücke": Mobilfunknetze plaudern bei Anruf sensible Daten aus

Teilweise konnten sowohl die eindeutige Gerätekennung IMEI als auch Details zur Betriebssystemversion erfasst werden. Heimische Provider wiegeln weitgehend ab

https://www.derstandard.at/story/3000000337719/gravierende-sicherheitsluecke-mobilfunknetze-plaudern-bei-anruf-sensible-daten-aus

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/

PaperCut warns of hackers using printer management software flaw in attacks

PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.

https://therecord.media/papercut-warns-of-hackers-using-printer-management-vulnerabilities

Omarchy: Any User Process Can Escalate to Root

A security issue in Omarchy-s default Docker configuration meant that essentially every program running in the user-s desktop session could escalate to root without a password, sudo, or a privilege prompt.

https://0xcc.io/posts/omarchy-root-creds/

curl: a CVE dispute

A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE or not. No more bogus ..

https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

Ten malicious versions were published with valid npm provenance after a threat actor abused a comment-triggered GitHub Actions publishing workflow, with the latest release still compromised at the time of writing.The Socket Threat Research Team is investigating an ongoing Mini Shai-Hulud compromise, affecting the npm package @7nohe/openapi-react-query-codegen. On August 28, ..

https://socket.dev/blog/openapi-react-query-codegen-npm-compromise