End-of-Day report
Timeframe: Donnerstag 20-08-2026 18:00 - Freitag 21-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
News
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.
https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/
Slowakei: Russische Backdoor in Verkehrskameras entdeckt
Die Slowakei wollte im Rahmen eines Sanierungspakets 279 neue Verkehrskameras beschaffen. Erste Geräte kamen unerwartet aus Russland - inklusive Backdoor.
https://www.golem.de/news/slowakei-russische-backdoor-in-verkehrskameras-entdeckt-2608-212088.html
N-able Passportal: Zahlreiche Unternehmen durch kritisches Passwort-Leck gefährdet
Ein Forscher hat bei N-able Passportal eine kritische Lücke entdeckt. Angreifer hätten damit leicht Zugangsdaten aus Passwort-Tresoren abgreifen können.
https://www.golem.de/news/n-able-passportal-jede-website-konnte-passwort-tresore-auslesen-2608-212171.html
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated ..
https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
Researcher tricks Apple-s Find My into sharing location data with Linux
Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget
https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
Secure Workload Software has five nasty flaws and even SaaS users have updates to install
https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838
ClaudeFix: Shared Claude Chats Meet ClickFix
ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to -fix- a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim-s system. Zscaler Threat Hunting has analyzed ..
https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix
Zimbra: Warnung vor Angriffen auf Befehlsschmuggel-Lücke
Das polnische CERT warnt vor Angriffen auf eine Befehlsschmuggel-Lücke in der Zimbra Collaboration Suite. Ein Update ist verfügbar.
https://www.heise.de/news/Zimbra-Warnung-vor-Angriffen-auf-Befehlsschmuggel-Luecke-11421424.html
Atlassian schließt mehr als 160 Sicherheitslücken in Confluence & Co.
Angreifer können unter anderem an kritischen Schadcode-Schwachstellen in Softwareprodukten von Atlassian ansetzen.
https://www.heise.de/news/Atlassian-schliesst-mehr-als-160-Sicherheitsluecken-in-Confluence-Co-11421486.html
Dell ObjectScale: Höhere Nutzerrechte erschleichbar
Sicherheitsupdates schließen mehrere Lücken in Dells Object-Storage-Plattform ObjectScale.
https://www.heise.de/news/Dell-ObjectScale-Hoehere-Nutzerrechte-erschleichbar-11421714.html
Lücke in WordPress-Plug-in Elementor Pro: 6 Millionen Webseiten gefährdet
Eine kritische Sicherheitslücke im WordPress-Plug-in Elementor Pro ermöglicht die komplette Übernahme von WordPress.
https://www.heise.de/news/Luecke-in-WordPress-Plug-in-Elementor-Pro-6-Millionen-Webseiten-gefaehrdet-11421805.html
Cyberangriff in Berlin: Behörden weiterhin offline
Zwei Senatsverwaltungen sind nach einem Cyberangriff vom Landesnetz isoliert. Das hat auch Auswirkungen auf die Auszahlung von Wohngeld.
https://heise.de/-11421320
Defeating AI-Assisted Reverse Engineering (or at Least Trying To)
At the beginning of 2026, a customer told us something along the lines of: obfuscation is finished, LLM-assisted reverse engineering breaks it. They had a walkthrough to back it up, produced by their own tooling, in which a model took one of their obfuscated libraries apart and recovered its hidden strings.They were not right, but not entirely wrong either.So we spent a ..
http://blog.quarkslab.com/defeating-ai-assisted-reverse-engineering-or-at-least-trying-to.html
I accidentally logged hundreds of thousands of phone calls to military bases
How an expired nameserver let me take over e164.arpa zones for multiple territories, and why I probably should have checked my logs sooner.
https://lina.sh/blog/hijacking-e164-arpa
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaigns infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.
https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns
If Apple says your iPhone was targeted by mercenary spyware, treat it like an incident
Apples Threat Notifications signal mercenary spyware targeting; learn verification steps, response actions, and layered mobile security defenses for high-risk users.
https://www.jamf.com/blog/apple-threat-notification-mercenary-spyware-response/
Vulnerabilities
[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints
https://developer.joomla.org/security-centre/1070-20260803-core-inconsistent-acl-checks-for-mutating-webservice-endpoints.html