End-of-Day report
Timeframe: Mittwoch 26-08-2026 18:00 - Donnerstag 27-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
News
New GPUThor attack defeats NVIDIA ECC protection for root access
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation.
https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/
ATF confirms -major incident- after recent Qilin breach claims
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.
https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/
Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.
https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/
Sicherheitslücke beim Mobilfunk: Angreifer konnten per Anruf Gerätedaten ausspähen
Reporter haben eine Sicherheitslücke in den Mobilfunknetzen mehrerer Provider entdeckt. Angreifer konnten ohne Nutzerinteraktion Gerätedaten abgreifen.
https://www.golem.de/news/sicherheitsluecke-beim-mobilfunk-angreifer-haben-per-anruf-geraetedaten-ausgespaeht-2608-212359.html
Threat landscape for industrial automation systems. Q2 2026
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
https://securelist.com/industrial-threat-report-q2-2026/121159/
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/
What We Still Don-t Know About OpenAI-s Hugging Face Hack
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didnt see this fiasco coming.
https://www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-questions-than-it-answers/
Berliner Landesnetz: Sensible Daten bei Cyberangriff womöglich doch betroffen
Eine Cyberattacke traf vor knapp zwei Wochen zwei Berliner Senatsverwaltungen. Bislang hieß es, es seien nur frei verfügbare Geodaten abgeflossen.
https://www.heise.de/news/Sensible-Daten-bei-Cyberangriff-womoeglich-doch-betroffen-11427279.html
Angreifer können an rund 550 Lücken in Dell PowerProtect Cyber Recovery ansetzen
Dells IT-Sicherheitslösung PowerProtect Cyber Recovery bietet viele Angriffspunkte. Admins sollten ihre Instanzen zeitnah über Updates absichern.
https://www.heise.de/news/Sicherheitspatches-Rund-550-Luecken-gefaehrden-Dell-PowerProtect-Cyber-Recovery-11427351.html
Hugging-Face-Angriff: OpenAI-Abschlussbericht liefert neue Erkenntnisse
OpenAIs Bericht zum Hugging-Face-Vorfall zeigt, dass riskante Verhaltensmuster schon beim Training auftraten und Warnsignale nicht ausreichend eskaliert wurden.
https://www.heise.de/news/OpenAI-Abschlussbericht-Rund-700-Agenten-griffen-Hugging-Face-an-11431716.html
Two Alleged -TeamPCP- Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands ..
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/
Microsoft Exchange: Exploit-Code veröffentlicht (CVE-2026-62911)
Wie Heise berichtet, wurde auf Github Exploit-Code für eine Sicherheitslücke in Microsoft Exchange veröffentlicht. Microsoft hat im Rahmen seines regulären Patchzykluses Fixes für diese Sicherheitslücke veröffentlicht, betroffen sind demnach die Versionen Microsoft Exchange Server 2019, 2016 und die Subscription Edition RTM. Für die Version 2016 stellt Microsoft die Fixes nur über sein Extended-Security-Updates-Programm zur Verfügung. Wir teilen ..
https://www.cert.at/de/aktuelles/2026/8/microsoft-exchange-exploit-code-veroffentlicht-cve-2026-62911
CISA Urges SharePoint Hardening After New Exploitations
Update August 26, 2026:CISA has updated this Alert to clarify guidance on avoiding the direct exposure of SharePoint Servers to the internet.Update August 18, 2026:CISA has updated this Alert to reflect the addition of CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) Catalog on August 18, 2026. Update July 28, 2026:CISA has updated this Alert to include CVE-2026-50522 and its addition to the KEV Catalog on July 22, 2026.Update July 16, 2026: CISA has updated this Alert to reflect the ..
https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations
Medical device firm Boston Scientific says cyberattack has disrupted shipment processes
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
https://therecord.media/boston-scientific-cyberattack-disrupts-shipment-processes
Disruptive cyber activity highlights risk from internet-exposed systems and edge devices
Targeting of operational technology reinforces the need for organisations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience.
https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices
Brief independent investigation of agents- behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
Two METR staff members (Hjalmar Wijk and Ajeya Cotra) and a Redwood Research staff member contracting with METR (Ryan Greenblatt) worked on premises at OpenAI over a total of six days1 to attempt to form an independent understanding of model behavior observed during the recent incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned -message board.-
https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn-t previously used. Within minutes, [-]
https://aws.amazon.com/blogs/security/detecting-multi-stage-attacks-on-aws-a-guide-to-cross-service-signal-correlation/
Vulnerabilities
CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105
https://www.drupal.org/sa-contrib-2026-105
Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
https://www.drupal.org/sa-contrib-2026-111
Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110
https://www.drupal.org/sa-contrib-2026-110