End-of-Day report
Timeframe: Mittwoch 19-08-2026 18:00 - Donnerstag 20-08-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
News
Grok exfiltrates user data when malicious instructions are encrypted
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.
https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.
https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/
Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/
New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices.
https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/
Kritische Sicherheitslücke: Hacker attackieren Gitlab-Instanzen
Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Forscher warnen bereits vor laufenden Angriffen.
https://www.golem.de/news/kritische-sicherheitsluecke-hacker-attackieren-gitlab-instanzen-2608-212127.html
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.The end-to-end experiment used an attacker Worker and a victim Worker controlled ..
https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a ..
https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a ..
https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).The vulnerability in question is ..
https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
Microsoft untersucht Spieleprobleme nach August-Patchday
Nach der Installation der Windows-Updates vom August-Patchday erhält Microsoft vermehrt Meldungen zu Problemen mit einigen Spielen.
https://www.heise.de/news/Microsoft-untersucht-Spieleprobleme-nach-August-Patchday-11419963.html
Citrix stopft kritische Anmeldungsumgehung in Netscaler ADC und Gateway
In Netscaler ADC und Gateway von Citrix können Angreifer mehrere Lücken missbrauchen. Sie können etwa unbefugt Zugriff erlangen.
https://www.heise.de/news/Citrix-stopft-kritische-Anmeldungsumgehung-in-Netscaler-ADC-und-Gateway-11420304.html
Sicherheitslücke in Microsoft 365 Copilot: KI verrät eigene Schutzmechanismen
Sicherheitsforscher haben Microsofts KI-Assistenten dazu gebracht, seine eigenen Schutzmechanismen offenzulegen.
https://www.heise.de/news/Sicherheitsluecke-in-Microsoft-365-Copilot-KI-verraet-eigene-Schutzmechanismen-11420618.html
GivEnergy enters administration, batteries expose home networks
In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers- home networks, disrupt battery operation, and potentially violate UK product security regulations. While GivEnergy updated installer guidance for newer deployments, older installations may still be exposed, with no clear remediation plan communicated to customers. Even before the latest news, this was ..
https://www.pentestpartners.com/security-blog/givenergy-enters-administration-legacy-home-batteries-still-expose-customer-networks/
A1-Phishing: Gefälschte E-Mails im Umlauf
Mit rund 7 Millionen Kund ist A1 einer der größten Anbieter für Handy, Festnetz und Internet in Österreich. Diese Bekanntheit nutzen Kriminelle aktuell aus und verschicken täuschend echte Phishing-Mails im Namen von A1. Das Ziel: Persönliche Daten und Kontoinformationen.
https://www.watchlist-internet.at/news/a1-phishing-gefaelschte-e-mails-im-umlauf/
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
Gefälschte Seite, falsche Software - trotz korrekt aussehender Links
Eine Kampagne mit gefälschten Webseiten zeigt korrekt erscheinende Links an, schiebt Opfern jedoch unerwünschte Software unter.
https://heise.de/-11420547
Supply chain attack on arrayref
On 2026-08-20 at 7:15 UTC we got a report that the proc-macro1 crate was malicious.
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Vulnerabilities
Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101
https://www.drupal.org/sa-contrib-2026-101
Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
https://www.drupal.org/sa-contrib-2026-100
Cisco Advance Notification for Publication of August 19, 2026, Security Advisories
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-LDquvx5d