Tageszusammenfassung - 20.07.2026

End-of-Day report

Timeframe: Freitag 17-07-2026 18:00 - Montag 20-07-2026 18:00 Handler: Guenes Holler Co-Handler: n/a

News

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/

Cyberangriff: Bafin verhängt 240.000 Euro-Strafe gegen Teamviewer

Weil Teamviewer einen Angriff durch russische Hacker nicht sofort an die Börse meldete, greift die Finanzaufsicht Bafin nun durch.

https://www.golem.de/news/cyberangriff-bafin-verhaengt-240-000-euro-strafe-gegen-teamviewer-2607-211071.html

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.

https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.

https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.

https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.

https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.

https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html

IPFire: Knot Resolver ersetzt Unbound

IPFire Core Update 203 ersetzt Unbound durch Knot Resolver, bringt DNS-Firewall, DoT und 6-GHz-WLAN.

https://www.heise.de/news/IPFire-Knot-Resolver-ersetzt-Unbound-11371136.html

7 Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors

Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up.

https://www.pillar.security/blog/the-week-of-sandbox-escapes

Abbott Laboratories probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.

https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/

Vulnerabilities

Kritische Sicherheitslücken in WordPress - Updates verfügbar

In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter -author__not_in- von -WP_Query- betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt sich diese laut Advisory in Kombination mit einer Schwachstelle in der REST-API (Batch-Route-Confusion) zur Ausführung von beliebigem Code (Remote Code Execution) ausnutzen. Laut Searchlight Cyber ist diese Angriffskette ohne vorherige Authentifizierung und ohne weitere Voraussetzungen in einer Standardinstallation ohne Plugins nutzbar.

https://www.cert.at/de/warnungen/2026/7/kritische-sicherheitslucken-in-wordpress-updates-verfugbar

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip's processing of XZ-compressed data. According to an advisory from the Zero Day Initiative published this week, a specially crafted XZ data can trigger a heap-based buffer overflow, potentially allowing attackers to execute arbitrary code as the user.

https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/

Angriff mit nur 11 Bytes: OpenSSL-Bug lässt Speicher von Servern volllaufen

Durch eine Sicherheitslücke in OpenSSL können Angreifer mit 11-Byte-Paketen den RAM anfälliger Server stark auslasten und Ausfälle herbeiführen.

https://www.golem.de/news/angriff-mit-nur-11-bytes-openssl-bug-laesst-speicher-von-servern-volllaufen-2607-211051.html

Cyberangriff auf Hugging Face: KI erkennt KI-Angriff auf KI-Plattform

Hugging Face hat einen von KI-Agenten ausgeführten Cyberangriff per KI entdeckt. Der Zugriff gelang durch Sicherheitslücken in der KI-Plattform.

https://www.golem.de/news/cyberangriff-auf-hugging-face-ki-erkennt-ki-angriff-auf-ki-plattform-2607-211057.html

Kritische Sicherheitslücke: Schadcode kann auf Nginx-Server schlüpfen

Angreifer können Nginx Open Source und Nginx Plus attackieren. Sicherheitsupdates sind verfügbar.

https://www.heise.de/news/Kritische-Sicherheitsluecke-Schadcode-kann-auf-Nginx-Server-schluepfen-11370300.html

Microsoft verteilt außerplanmäßiges Windows-Update

Microsoft verteilt ein ungeplantes Windows-Update. Es soll Probleme beheben, die insbesondere bei Dell-Computern aufgetreten sind.

https://www.heise.de/news/Windows-Update-ausser-der-Reihe-korrigiert-Performanceprobleme-11369968.html

LWN Security updates for Monday

https://lwn.net/Articles/1083708/

Langflow 1.3.0 Remote Code Execution

https://cxsecurity.com/issue/WLB-2026070007

K000162343: Multiple Oracle Java SE vulnerabilities

https://my.f5.com/manage/s/article/K000162343

Case closed: DIVD-2025-00003 - Multiple vulnerabilities in Mennekes Smart / Premium Charging stations

https://csirt.divd.nl/cases/DIVD-2025-00003/