End-of-Day report
Timeframe: Donnerstag 06-08-2026 18:00 - Freitag 07-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
News
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. [..] The disclosure does not identify the exact Windows builds or Windows Hello for Business deployment models tested. [..] The new work removes that requirement by treating the Windows Hello for Business key as a FIDO2 passkey through WebAuthn. Mollema found that the five-minute Entra ID challenge is not bound to a session, user, or tenant. An attacker can therefore request it on another host and have the compromised endpoint produce the signed assertion.
https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
Durch Metabase-0day: Datenleck bei Laptophersteller Framework
Der Laptophersteller Framework hat ein Datenleck erlitten und warnt seine Kunden vor abgeflossenen Informationen. Kontakt- und Lieferdaten privater und gewerblicher Kunden kamen abhanden - Zahlungs- und Bestellinformationen nach Frameworks Angaben jedoch nicht. Offenbar nutzten Angreifer eine Zero-Day-Lücke in Metabase aus; der Datenbankhersteller hat Updates veröffentlicht und seine Cloud-Instanzen abgedichtet.
https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptophersteller-Framework-11403050.html
ChainDrop: Inside a Self-Propagating npm Worm
A self-propagating npm worm nicknamed ChainDrop infected over 400 packages that are collectively downloaded hundreds of millions of times each week. This includes malicious versions of widely used packages such as keyv and cacheable-request. Unit 42 has unique observations of this attack.
https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
N-able N-central: 2. Hotfix vom 6. August 2026
Ein Patch gegen die Schwachstelle (CVE-2026-18576) wirkte nicht. Die RMM-Lösung wird bereits angegriffen. Der Hotfix 1 von Anfang August 2026 scheint nicht auszureichen, vor wenigen Stunden wird ein Hotfix 2 nachgeschoben.
https://borncity.com/blog/2026/08/07/n-able-n-central-2-hotfix-vom-6-august-2026/
"deGDID" entfernt GDID in Windows und blockt Neuanlage
Microsoft vergibt in Windows eine eindeutige GDID genannte Kennung, über die Nutzer identifiziert werden können. Der VPN-Anbieter Windscribe hat nun ein Skript entwickelt, um das versteckte GDID-Tracking von Microsoft unter Windows zu blockieren.
https://borncity.com/blog/2026/08/07/degdid-entfernt-gdid-in-windows-und-blockt-neuanlage/
Unternehmen fürchten US-Kill-Switch für kritische IT-Dienste
74 Prozent der Unternehmen befürchten, dass US-Anbieter auf Druck der US-Regierung wichtige Dienste sperren könnten.
https://heise.de/-11403600
Vulnerabilities
Screen Sharing: Gefährliche MacOS-Lücke lässt Angreifer Apple-Systeme kapern
Die besagte Sicherheitslücke ist als CVE-2026-65400 registriert und verfügt mit einem CVSS-Wert von 7,1 über einen hohen Schweregrad. "Ein Angreifer im Netzwerk könnte sich möglicherweise ohne gültige Anmeldedaten bei der Bildschirmfreigabe authentifizieren", heißt es in der Beschreibung. [..] Die gepatchten MacOS-Versionen tragen die Versionsnummern 26.6.1 (Tahoe), 15.7.9 (Sequoia) und 14.8.9 (Sonoma).
https://www.golem.de/news/screen-sharing-gefaehrliche-macos-luecke-laesst-angreifer-apple-systeme-kapern-2608-211694.html
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. [..] As of August 6, 2026, Debian's tracker listed bullseye, bookworm, and trixie kernel packages, including their security repositories, as vulnerable.
https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b.
https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
WordPress 7.0.3 release
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. [..] Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai.
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
LWN: Security updates for Friday
https://lwn.net/Articles/1087742/