End-of-Day report
Timeframe: Mittwoch 29-07-2026 18:00 - Donnerstag 30-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
HelloNet campaign: new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
https://securelist.com/tr/hellonet-vipnet/120700/
Toy Ghouls- new toy: the GenieLocker ransomware
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian).
https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
Most of what an internet-facing SSH honeypot records is noise. Endless password guessing, and bots that log in, immediately pull down a payload, and move on. On 27 June 2026 my honeypot caught something quieter, and to me more interesting. A bot logged in as root, ran a careful survey of the machine's hardware, and then disconnected without downloading or running anything at all. No malware, no persistence, no second stage.
https://isc.sans.edu/diary/rss/33198
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
Verschlüsselt, aber falsch: Gruppenchats anfällig für manipulierte Inhalte
Alle Mitglieder eines Gruppenchats sollten dieselben Inhalte sehen. Die üblichen Chat-Dienste stellen das nicht sicher. Das ist riskant.
https://www.heise.de/news/Verschluesselt-aber-falsch-Gruppenchats-anfaellig-fuer-manipulierte-Inhalte-11384095.html
Vermeintliche Zollgebühren der Post sind fake!
Eine offene Paketgebühr, ein Link zur Zahlung und eine täuschend echt aussehende Nachricht der Österreichischen Post. Mit dieser Masche versuchen Kriminelle derzeit, an Bankdaten zu gelangen.
https://www.watchlist-internet.at/news/phishing-oesterreichischen-post-zoll/
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
Adform compromised to serve crypto stealer via supply chain attack
Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category.
https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e?source=rss8343faddf0ec4
CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software
Tailored Guidance to Use and Understand OSS Solutions, Contribute to and Produce Projects, and Evaluate AI Models.
https://www.cisa.gov/news-events/news/cisa-guide-helps-federal-agencies-securely-and-effectively-use-open-source-software
Vulnerabilities
Angreifer missbrauchen Backdoor in Ciscos Firewall-Verwaltungssoftware
Angreifer missbrauchen fest einprogrammierte Zugangsdaten in Ciscos Firewall-Verwaltungssoftware. Updates sollen dagegen helfen.
https://www.heise.de/news/Angreifer-missbrauchen-Backdoor-in-Ciscos-Firewall-Verwaltungssoftware-11384735.html
Chrome-Update stopft weitere 370 Sicherheitslecks
Google hat wieder ein massives Sicherheitsupdate für Chrome veröffentlicht. Sieben der geschlossenen Lücken gelten als kritisch.
https://heise.de/-11384153
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
Progress: LoadMaster Critical Security Bulletin - July 2026 - (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690)
https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690
GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/
Drupal Security Advisories 2026-July-29
https://www.drupal.org/security
Publish DFIR-IRIS advisories
https://github.com/sbaresearch/advisories/commit/0e542378f16ec1052b5ad032b487b10bbb7953a3
LWN Security updates for Thursday
https://lwn.net/Articles/1086225/