Tageszusammenfassung - 20.08.2026

End-of-Day report

Timeframe: Mittwoch 19-08-2026 18:00 - Donnerstag 20-08-2026 18:00 Handler: Guenes Holler Co-Handler: Alexander Riepl

News

Grok exfiltrates user data when malicious instructions are encrypted

Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.

https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.

https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.

https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices.

https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.

https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/

Kritische Sicherheitslücke: Hacker attackieren Gitlab-Instanzen

Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Forscher warnen bereits vor laufenden Angriffen.

https://www.golem.de/news/kritische-sicherheitsluecke-hacker-attackieren-gitlab-instanzen-2608-212127.html

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.The end-to-end experiment used an attacker Worker and a victim Worker controlled ..

https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a ..

https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a ..

https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).The vulnerability in question is ..

https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html

Microsoft untersucht Spieleprobleme nach August-Patchday

Nach der Installation der Windows-Updates vom August-Patchday erhält Microsoft vermehrt Meldungen zu Problemen mit einigen Spielen.

https://www.heise.de/news/Microsoft-untersucht-Spieleprobleme-nach-August-Patchday-11419963.html

Citrix stopft kritische Anmeldungsumgehung in Netscaler ADC und Gateway

In Netscaler ADC und Gateway von Citrix können Angreifer mehrere Lücken missbrauchen. Sie können etwa unbefugt Zugriff erlangen.

https://www.heise.de/news/Citrix-stopft-kritische-Anmeldungsumgehung-in-Netscaler-ADC-und-Gateway-11420304.html

Sicherheitslücke in Microsoft 365 Copilot: KI verrät eigene Schutzmechanismen

Sicherheitsforscher haben Microsofts KI-Assistenten dazu gebracht, seine eigenen Schutzmechanismen offenzulegen.

https://www.heise.de/news/Sicherheitsluecke-in-Microsoft-365-Copilot-KI-verraet-eigene-Schutzmechanismen-11420618.html

GivEnergy enters administration, batteries expose home networks

In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers- home networks, disrupt battery operation, and potentially violate UK product security regulations. While GivEnergy updated installer guidance for newer deployments, older installations may still be exposed, with no clear remediation plan communicated to customers. Even before the latest news, this was ..

https://www.pentestpartners.com/security-blog/givenergy-enters-administration-legacy-home-batteries-still-expose-customer-networks/

A1-Phishing: Gefälschte E-Mails im Umlauf

Mit rund 7 Millionen Kund ist A1 einer der größten Anbieter für Handy, Festnetz und Internet in Österreich. Diese Bekanntheit nutzen Kriminelle aktuell aus und verschicken täuschend echte Phishing-Mails im Namen von A1. Das Ziel: Persönliche Daten und Kontoinformationen.

https://www.watchlist-internet.at/news/a1-phishing-gefaelschte-e-mails-im-umlauf/

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.

https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/

Gefälschte Seite, falsche Software - trotz korrekt aussehender Links

Eine Kampagne mit gefälschten Webseiten zeigt korrekt erscheinende Links an, schiebt Opfern jedoch unerwünschte Software unter.

https://heise.de/-11420547

Supply chain attack on arrayref

On 2026-08-20 at 7:15 UTC we got a report that the proc-macro1 crate was malicious.

https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/

Vulnerabilities

Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101

https://www.drupal.org/sa-contrib-2026-101

Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100

https://www.drupal.org/sa-contrib-2026-100

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-LDquvx5d