Tageszusammenfassung - 28.08.2026

End-of-Day report

Timeframe: Donnerstag 27-08-2026 18:00 - Freitag 28-08-2026 18:00 Handler: Alexander Riepl Co-Handler: n/a

News

PaperCut warns of NG, MF flaw exploited in zero-day attacks

PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.

https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.

https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/

Patch-Defizit in Deutschland: Exploit gefährdet 85 Prozent aller Exchange-Server

Auf Github ist ein Exploit für eine gefährliche Exchange-Lücke aufgetaucht. Einen Patch gibt es zwar, doch den haben in Deutschland nur wenige installiert.

https://www.golem.de/news/patch-defizit-in-deutschland-exploit-gefaehrdet-85-prozent-aller-ex
change-server-2608-212397.html

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.These campaigns, per Recorded Future Insikt Group, ..

https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.The vulnerability, assigned the CVE identifier CVE-2026-65643, ..

https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.The company said it deployed a ..

https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.The extensions, per ..

https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html

AI girlfriend review sites secrets were exposed to the world for three weeks

Even testing and staging sites need protection from prying eyes.

https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-secrets-were-exposed-to-the-world-for-three-weeks/5293064

CRPx0 hacking service for dummies claims victim count more than quintupled

Its built to be operated by a human with no technical background.

https://www.theregister.com/cyber-crime/2026/08/27/crpx0-hacking-service-for-dummies-claims-victim-count-more-than-quintupled/5293097

TeamViewer schließt hochriskante Lücken in Clients

Die TeamViewer-Clients können Angreifern das Ausführen von Schadcode ermöglichen. Updates stopfen die hochriskanten Sicherheitslücken.

https://www.heise.de/news/TeamViewer-stopft-Codeschmuggel-Leck-11432840.html

Google macht Android 17 sicherer: ECH-Unterstützung und 2G-Abschaltung

Mit Android 17 führt Google neue Netzwerksicherheitsfunktionen ein. Diese sollen Verbindungen absichern und die Privatsphäre im heimischen WLAN schützen.

https://www.heise.de/news/2G-Abschaltung-und-ECH-Support-Android-17-erhoeht-die-Netzwerksicherheit-11432832.html

-Begrenztes Zeitfenster-: Mehr als 100 Unternehmen warnen vor KI-Cyberangriffen

Führende KI-Labore sowie mehr als 100 Organisationen warnen in einem offenen Brief vor einer baldigen Zunahme KI-gestützter Cyberangriffe.

https://www.heise.de/news/Begrenztes-Zeitfenster-Mehr-als-100-Unternehmen-warnen-vor-KI-Cyberangriffen-11432718.html

Zwei kritische Lücken in Next.js - Remote-Code-Ausführung unter Windows

Die zwei kritischen von Vercel gemeldeten Lücken im JavaScript-Framework Next.js ermöglichen es Angreifern, Code auszuführen.

https://www.heise.de/news/Zwei-kritische-Luecken-in-Next-js-Remote-Code-Ausfuehrung-unter-Windows-11433140.html

(OEM-)China-Router von ZBT mit Backdoors

IT-Forscher haben Router vom OEM-Hersteller ZBT untersucht, die weltweit von Anbietern verkauft werden. Darin fanden sie Backdoors.

https://www.heise.de/news/OEM-China-Router-von-ZBT-mit-Backdoors-11433072.html

Disruptive cyber activity highlights risk from internet-exposed systems and edge devices

Targeting of operational technology reinforces the need for organisations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience.

https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices

Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets

GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigured web servers frequently leak secrets and credentials.

https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers

Inside 90 days of attacks on AI infrastructure

Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.

https://www.wiz.io/blog/ai-infrastructure-honeypot