End-of-Day report
Timeframe: Montag 03-08-2026 18:00 - Dienstag 04-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
News
Phishing-Mails der ÖGK jetzt auch im Dialekt
Manche Betrugsmaschen halten sich hartnäckig über Jahre. Dazu zählen Phishing-Mails im Namen der Österreichischen Gesundheitskasse (ÖGK). Nun setzen die Kriminellen auch auf Dialekt.
https://www.watchlist-internet.at/news/phishing-mails-der-oegk/
NuGet-Sicherheit: Microsoft verkürzt Gültigkeit von API-Keys auf 30 Tage
Eine kürzere Gültigkeit von API-Keys zur Paketveröffentlichung soll die Sicherheit von NuGet stärken. Sie betrifft sowohl bestehende als auch neue Keys.
https://heise.de/-11396124
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.
https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.
https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
AI slop pollutes the CVE pipeline with fake vulns
With NIST still buried under its backlog, expect AI-generated bogus reports to continue.
https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462
Wenn die IT ausfällt: Krisensimulation für Krankenhäuser
Wie Krankenhäuser bei IT-Ausfällen reagieren, testet Nico Brüggemann vom Fraunhofer SIT. Er erklärt, warum Abläufe oft nur auf dem Papier funktionieren.
https://www.heise.de/hintergrund/Wenn-die-IT-ausfaellt-Krisensimulation-fuer-Krankenhaeuser-11395892.html
Almost Half of Malware Samples Communicate Direct to IP
Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total.
https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
EU-Cybersecurity-Pflichten für Hersteller & Betriebe - Hands-on
Auf Hersteller und Unternehmen in Europa kommen in den nächsten Wochen und Monaten (z.B. ab 11.09.2026) einige Cybersecurity-Pflichten zu, die EU-weit geregelt sind. NIS-2, Cyber Resilience Act und Maschinenverordnung. Mir hat der Betreiber einer entsprechenden Infoseite einige Informationen zukommen lassen. Ich nutze die Gelegenheit, einen kuren Überblick über die Sachlage zu geben.
https://borncity.com/blog/2026/08/04/eu-cybersecurity-pflichten-fuer-hersteller-betriebe-hands-on/
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Socket-s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespaces and spreading to packages owned by other maintainers, were published with a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanized versions of other packages the stolen npm token can reach. The affected packages collectively account for tens of millions of weekly downloads. New packages are appearing in real time, and Socket team will keep on updating the list.
https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain?utm_medium=feed
Vulnerabilities
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
Jetzt patchen! Angreifer attackieren N-able N-central
N-ables Endpoint-Managementlösung N-central ist verwundbar und Angreifer attackieren bereits Instanzen. Admins sollten zügig handeln.
https://www.heise.de/news/Jetzt-patchen-Angreifer-attackieren-N-able-N-central-11397397.html
Check Point: Angreifer können Security-Management-Server übernehmen
Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download.
https://heise.de/-11398187
Broadcom Fixes Multiple Critical VMware Vulnerabilities
Broadcom-s latest security advisory resolves five vulnerabilities affecting core VMware products. The most severe vulnerabilities carry a CVSS score of 9.8, allowing attackers to bypass authentication or execute arbitrary code on vulnerable systems. Because vCenter Server acts as the centralized management platform for VMware environments, successful exploitation could provide attackers with extensive control over virtual infrastructure. There are currently no confirmed reports of widespread exploitation, but the technical impact warrants immediate remediation.
https://thecyberthrone.in/2026/08/03/broadcom-fixes-multiple-critical-vmware-vulnerabilities/
LWN Security updates for Tuesday
https://lwn.net/Articles/1087068/
Security Vulnerabilities fixed in Firefox for Android 153.0.3
https://www.mozilla.org/en-US/security/advisories/mfsa2026-73/
[R1] Sensor Proxy Version 1.4.2 Fixes One Vulnerability
https://www.tenable.com/security/tns-2026-21
Zyxel security advisory for path traversal vulnerability in the configuration file execution CLI command of ZLD firewalls
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026
Zyxel security advisory for command injection and improper authentication vulnerabilities in certain APs, FWA7, and Security Routers
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026
List of Security Fixes and Improvements in Veeam ONE
https://www.veeam.com/kb4858