End-of-Day report
Timeframe: Donnerstag 16-07-2026 18:00 - Freitag 17-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
News
Kurz nach Microsoft-Patchday: Kritische Sharepoint-Lücke wird aktiv ausgenutzt
Bei der besagten Sicherheitslücke handelt es sich um CVE-2026-58644. Laut Beschreibung kann ein Angreifer damit aus der Ferne Schadcode einschleusen und zur Ausführung bringen. Ursache ist eine mögliche Deserialisierung nicht-vertrauenswürdiger Daten in Microsoft Sharepoint. Den Angaben zufolge muss ein Angreifer für eine erfolgreiche Ausnutzung mindestens als Site Owner authentifiziert sein.
https://www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint-luecke-wird-aktiv-ausgenutzt-2607-211000.html
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropics Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claudes access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
https://www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions/
New ClickLock macOS malware traps users into revealing login password
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/
Ernst & Young discloses data breach after support system hack
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
https://www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.
https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
Windows Server 2022: Mainstream-Support endet in 90 Tagen
Windows Server 2022 fällt in 90 Tagen aus dem Mainstream-Support. Erweiterte Sicherheitsupdates gibt es bis 2031 - und danach ESU.
https://www.heise.de/news/Windows-Server-2022-Mainstream-Support-endet-in-90-Tagen-11368549.html
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
The report spotlights four defining trends shaping the threat landscape. We-ll take a closer look at Trend 1: AI Has Become a Force Multiplier for Attackers.
https://unit42.paloaltonetworks.com/ai-incident-response-report/
Vulnerabilities
Google Chrome: Ungeplantes Sicherheitsupdate Nummer zwei in dieser Woche
Google aktualisiert Chrome eigentlich jeden Mittwoch. Diese Woche folgt ein zweites Update, das mehrere kritische Lücken schließt. [..] Drei davon gelten als -kritisch-, es handelt sich um nicht näher erläuterte Use-after-free-Schwachstellen in den Komponenten CameraCapture (CVE-2026-15899), GPU (CVE-2026-15900) sowie Network (CVE-2026-15901).
https://heise.de/-11368362
Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available
The latest Notepad++ vulnerabilities addressed in version 8.9.7 include several high-impact security flaws that could expose Windows systems to arbitrary code execution, file overwrite attacks, memory corruption, and authentication bypass. Among the most critical issues is a PowerShell command injection vulnerability in the installer, alongside fixes for CVE-2026-52886, CVE-2026-54758, and CVE-2026-57233.
https://thecyberexpress.com/notepad-vulnerabilities-v897/
VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
https://kb.cert.org/vuls/id/885548
LWN: Security updates for Friday
https://lwn.net/Articles/1083388/