Tageszusammenfassung - 04.08.2026

End-of-Day report

Timeframe: Montag 03-08-2026 18:00 - Dienstag 04-08-2026 18:00 Handler: Guenes Holler Co-Handler: n/a

News

Phishing-Mails der ÖGK jetzt auch im Dialekt

Manche Betrugsmaschen halten sich hartnäckig über Jahre. Dazu zählen Phishing-Mails im Namen der Österreichischen Gesundheitskasse (ÖGK). Nun setzen die Kriminellen auch auf Dialekt.

https://www.watchlist-internet.at/news/phishing-mails-der-oegk/

NuGet-Sicherheit: Microsoft verkürzt Gültigkeit von API-Keys auf 30 Tage

Eine kürzere Gültigkeit von API-Keys zur Paketveröffentlichung soll die Sicherheit von NuGet stärken. Sie betrifft sowohl bestehende als auch neue Keys.

https://heise.de/-11396124

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.

https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.

https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.

https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.

https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html

AI slop pollutes the CVE pipeline with fake vulns

With NIST still buried under its backlog, expect AI-generated bogus reports to continue.

https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462

Wenn die IT ausfällt: Krisensimulation für Krankenhäuser

Wie Krankenhäuser bei IT-Ausfällen reagieren, testet Nico Brüggemann vom Fraunhofer SIT. Er erklärt, warum Abläufe oft nur auf dem Papier funktionieren.

https://www.heise.de/hintergrund/Wenn-die-IT-ausfaellt-Krisensimulation-fuer-Krankenhaeuser-11395892.html

Almost Half of Malware Samples Communicate Direct to IP

Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total.

https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/

EU-Cybersecurity-Pflichten für Hersteller & Betriebe - Hands-on

Auf Hersteller und Unternehmen in Europa kommen in den nächsten Wochen und Monaten (z.B. ab 11.09.2026) einige Cybersecurity-Pflichten zu, die EU-weit geregelt sind. NIS-2, Cyber Resilience Act und Maschinenverordnung. Mir hat der Betreiber einer entsprechenden Infoseite einige Informationen zukommen lassen. Ich nutze die Gelegenheit, einen kuren Überblick über die Sachlage zu geben.

https://borncity.com/blog/2026/08/04/eu-cybersecurity-pflichten-fuer-hersteller-betriebe-hands-on/

Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack

Socket-s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespaces and spreading to packages owned by other maintainers, were published with a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanized versions of other packages the stolen npm token can reach. The affected packages collectively account for tens of millions of weekly downloads. New packages are appearing in real time, and Socket team will keep on updating the list.

https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain?utm_medium=feed

Vulnerabilities

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.

https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html

Jetzt patchen! Angreifer attackieren N-able N-central

N-ables Endpoint-Managementlösung N-central ist verwundbar und Angreifer attackieren bereits Instanzen. Admins sollten zügig handeln.

https://www.heise.de/news/Jetzt-patchen-Angreifer-attackieren-N-able-N-central-11397397.html

Check Point: Angreifer können Security-Management-Server übernehmen

Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download.

https://heise.de/-11398187

Broadcom Fixes Multiple Critical VMware Vulnerabilities

Broadcom-s latest security advisory resolves five vulnerabilities affecting core VMware products. The most severe vulnerabilities carry a CVSS score of 9.8, allowing attackers to bypass authentication or execute arbitrary code on vulnerable systems. Because vCenter Server acts as the centralized management platform for VMware environments, successful exploitation could provide attackers with extensive control over virtual infrastructure. There are currently no confirmed reports of widespread exploitation, but the technical impact warrants immediate remediation.

https://thecyberthrone.in/2026/08/03/broadcom-fixes-multiple-critical-vmware-vulnerabilities/

LWN Security updates for Tuesday

https://lwn.net/Articles/1087068/

Security Vulnerabilities fixed in Firefox for Android 153.0.3

https://www.mozilla.org/en-US/security/advisories/mfsa2026-73/

[R1] Sensor Proxy Version 1.4.2 Fixes One Vulnerability

https://www.tenable.com/security/tns-2026-21

Zyxel security advisory for path traversal vulnerability in the configuration file execution CLI command of ZLD firewalls

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026

Zyxel security advisory for command injection and improper authentication vulnerabilities in certain APs, FWA7, and Security Routers

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026

List of Security Fixes and Improvements in Veeam ONE

https://www.veeam.com/kb4858