Tageszusammenfassung - 12.08.2026

End-of-Day report

Timeframe: Dienstag 11-08-2026 18:00 - Mittwoch 12-08-2026 18:00 Handler: Guenes Holler Co-Handler: n/a

News

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.

https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more than 2,500 organizations.

https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html

Brandenburg: Cyberangriff legt IT-System der Gedenkstätten lahm

Die Stiftung Brandenburgische Gedenkstätten wurde Opfer eines Ransomware-Angriffs. IT-Systeme sind derzeit außer Betrieb, ein Datenabfluss wird vermutet.

https://www.heise.de/news/Brandenburg-Cyberangriff-legt-IT-System-der-Gedenkstaetten-lahm-11410695.html

Threema: DDoS-Angriffe sorgen für Ausfälle bei Messenger

Nach einem Angriff auf einen Dienstleister von Threema war der Messenger am Dienstag stundenlang nicht nutzbar. Am Mittwoch dauern die Attacken an.

https://www.heise.de/news/Stoerungen-bei-Threema-DDoS-Angriffe-sorgen-fuer-Ausfaelle-bei-Messenger-11411479.html

Deadbugz: Currently Active MCP Supply-Chain Campaign

Pillar Security Researchers identified an active campaign to distribute a malicious Model Context Protocol (MCP) server through public GitHub pull requests. The server calls itself productivity-suite and initially looks harmless: it offers text formatting and summarization. After a connected client makes three tool calls, however, it changes the instructions it returns to the AI agent. The new metadata directs the agent to seek sensitive information, including SSH keys, AWS credentials, shell history, and Kubernetes configuration, and to conceal the activity from the user.

https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign

Vulnerabilities

Nordkoreas Hacker schlagen zu: Angriffe auf Windows-Nutzer in Europa beobachtet

Die Hackergruppe Lazarus greift Windows-Nutzer über eine Treiberlücke an. Microsoft hat sie zusammen mit über 400 weiteren Sicherheitslücken gepatcht.

https://www.golem.de/news/auch-in-europa-nordkoreanische-hacker-attackieren-windows-nutzer-2608-211834.html

Kein Klick nötig: Lücke ermöglicht heimliche Schadcode-Attacken über Zoom-Meetings

Eine Sicherheitslücke in Zoom lässt Angreifer anderen Meeting-Teilnehmern unbemerkt Schadcode unterschieben. Nutzer sollten zügig updaten.

https://www.golem.de/news/kein-klick-noetig-luecke-ermoeglicht-heimliche-schadcode-attacken-ueber-zoom-meetings-2608-211845.html

Zero-Day-Lücke im Defender: Chaotic Eclipse leakt neuen Windows-Exploit

Ein neuer Exploit namens Shieldbreak umgeht einen früheren Patch für den Microsoft Defender. Angreifer erhalten damit unter Windows Systemrechte.

https://www.golem.de/news/zero-day-luecke-im-defender-chaotic-eclipse-leakt-neuen-windows-exploit-2608-211855.html

Böse Screen-Sharing-Lücke in macOS: Exploit aus Apples Patch gebaut

Wer Apples praktische Bildschirm-teilen-Funktion auf dem Mac nutzt, muss sein Betriebssystem aktualisieren. Ein Exploit ließ sich schnell entwickeln.

https://www.heise.de/news/Boese-Screen-Sharing-Luecke-in-macOS-Exploit-aus-Apples-Patch-gebaut-11411035.html

Patchday Adobe: Schadcode-Schlupflöcher bedrohen Campaign Classic und ColdFusion

Wichtige Sicherheitsupdates schließen mehrere Schwachstellen an Adobe-Anwendungen.

https://www.heise.de/news/Patchday-Adobe-Schadcode-Schlupfloecher-bedrohen-Campaign-Classic-und-ColdFusion-11410951.html

Der Security-Ko-Prozessor in vielen CPUs ist unsicher

Das Trusted Platform Module ist das wichtigste Glied in der Vertrauenskette von PCs. Ausgerechnet dieses TPM ist angreifbar.

https://www.heise.de/news/Der-Security-Ko-Prozessor-in-vielen-CPUs-ist-unsicher-11411837.html

Cisco warnt vor Attacken auf Secure Firewall Adaptive Security Appliance

Derzeit lassen Angreifer Cisco Secure Firewall Adaptive Security Appliance nach Attacken abstürzen. Ein Sicherheitspatch ist verfügbar.

https://heise.de/-11411427

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/

ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-26-532/

ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-26-531/

ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-26-530/

ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-26-527/

PSIRT FortiGuard Labs Heap overflow in kernel driver due to missing size validation

https://fortiguard.fortinet.com/psirt/FG-IR-26-156

PSIRT FortiGuard Labs Broken access control in the RADIUS type admin group

https://fortiguard.fortinet.com/psirt/FG-IR-26-158

LWN Security updates for Wednesday

https://lwn.net/Articles/1088476/