End-of-Day report
Timeframe: Dienstag 21-07-2026 18:00 - Mittwoch 22-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
News
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [..] While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed.
https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
OpenAI hackt beliebtes KI-Portal, macht daraus PR-Stunt
Die neuesten Modelle seien bei einem Sicherheitstest eigenständig -ausgebrochen- und hätten Hugging Face attackiert. [..] Der US-Konzern OpenAI hat nun die Verantwortung dafür übernommen.
https://futurezone.at/digital-life/openai-hugging-face-hack-pr-stunt/403177512
Cyberangriff: Nextcloud-Nutzer wurden auf verdächtige Cloudbox umgeleitet
Die offizielle Website von Nextcloud ist nach verdächtigen Umleitungen der Besucher temporär vom Netz genommen worden. Ursache war ein Cyberangriff. [..] Da die Nextcloud-Website auf Wordpress basiert, ist denkbar, dass der Angriff unter Ausnutzung zweier kürzlich bekannt gewordener Sicherheitslücken in dem CMS ausgeführt wurde.
https://www.golem.de/news/cyberangriff-nextcloud-nutzer-wurden-auf-verdaechtige-cloudbox-umgeleitet-2607-211142.html
Windows: Global Device ID führt zu gerichtswirksamer Identifikation
Microsoft nutzt in Windows eine Global Device ID (GDID). Die macht Windows-Installationen eindeutig erkennbar, sie übersteht Neustarts und Windows-Updates und lässt sich nicht entfernen. [..] Auf GitHub hat sich ein User mit dem Handle -SmtimesIWndr- die Mühe gemacht und Informationen zur Windows GDID zusammengesammelt. Es handelt sich demnach um einen Bestandteil der Windows-Telemetrie, der wird zusammen mit anderen Informationen an Microsofts Server gesendet. [..] Der Global Device Identifier lässt sich also nicht einfach loswerden.
https://heise.de/-11373417
PyPI: Releases now reject new files after 14 days
The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn ones television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LGs webOS store allow unknown third-parties to route their Internet traffic through a users TV.
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
Klimabonus-Phishing ist zurück: Klicken Sie nicht auf diesen Mail-Link!
Die Kriminellen lassen nicht locker: Aktuell wieder in einer neuen Variante betreffend den Klimabonus im Umlauf. Eine betrügerische E-Mail verspricht Empfänger:innen 290 Euro.
https://www.watchlist-internet.at/news/klimabonus-phishing-mail/
Adobe Chrome extension flaw let sites access private WhatsApp chats
Exploiting them requires only that the target running the Adobe Acrobat extension be lured to a web page under the threat actor's control. [..] The issue has been fixed in 26.5.2.3 and delivered automatically to users.
https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Hidden text on a web page was enough to make Kiro, AWSs agentic coding IDE, rewrite its own configuration file and run an attackers code on a developers machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution.
https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
Vulnerabilities
Serv-U: Datentransfersoftware Serv-U hat 15 kritische Sicherheitslücken
SolarWinds stopft mit dem Update auf Serv-U 2026.3 insgesamt 15 kritische Sicherheitslücken sowie eine mittleren Schweregrads. Die Auswirkungen reichen von der Rechteausweitung über Informationslecks hin zur Ausführung von eingeschleustem Schadcode aus dem Netz.
https://heise.de/-11373098
Ubuntu: Root-Lücke in snapd gefährdet unzählige Linux-Systeme
Angreifer können damit ihre Rechte ausweiten und Root-Zugriff erlangen. Laut Blogbeitrag der Forscher gelingt das bei anfälligen Ubuntu-Versionen bereits in der Standardkonfiguration. Patches sind verfügbar und sollten zeitnah installiert werden. [..] Die Ursache liegt in snap-confine, einer Komponente, die für den Aufbau der Ausführungsumgebung von Snap-Paketen zuständig ist. CVE-2026-8933
https://www.golem.de/news/ubuntu-root-luecke-in-snapd-gefaehrdet-unzaehlige-linux-systeme-2607-211151.html
Oracle Critical Patch Update Advisory - July 2026
This Critical Patch Update contains 1449 new security patches across the product families listed below.
https://www.oracle.com/security-alerts/cpujul2026.html
Check Point: Security Advisory - Action Required - July 2026 Security Update
As part of Check Point-s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. [..] This only affects a very specific configuration - when Management is exposed directly to the internet without IP restrictions. We-ve already notified the affected customers.
https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
Plane: VU#762226: Plane contains multi-tenant authorization bypass vulnerability
https://kb.cert.org/vuls/id/762226
LWN: Security updates for Wednesday
https://lwn.net/Articles/1084210/
QNAP: Kritische Schwachstellen in QNAP NAS File Station 5
https://www.syss.de/pentest-blog/kritische-schwachstellen-in-qnap-nas-file-station-5