Tageszusammenfassung - 11.08.2026

End-of-Day report

Timeframe: Montag 10-08-2026 18:00 - Dienstag 11-08-2026 18:00 Handler: Alexander Riepl Co-Handler: Guenes Holler

News

New Pass-ta-key attack reveals all the things we didnt know about passkeys

Why passkey apps treat Windows differently than other operating systems.

https://arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-attack-is-mostly-a-nothingburger/

Hackers breached a small Polish energy plant via private APN last year

Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network.

https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.

https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.

https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/

Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus

Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft.

https://www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-forscher-bei-cybertests-aus-2608-211748.html

Kein Klick nötig: Plug-and-Pwn-Angriff kapert Windows-Systeme per USB

Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen - manchmal sogar aus der Ferne.

https://www.golem.de/news/kein-klick-noetig-plug-and-pwn-angriff-kapert-windows-systeme-per-usb-2608-211809.html

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platforms plugins team to temporarily disable their downloads."Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California drivers license and a New York bank account.The

https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html

Abyssos: Technical Analysis of a New Modular RAT

In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security ..

https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat

Lahmer x86-Befehl hebelt triviale Schutzfunktion aus

Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus.

https://www.heise.de/news/Lahmer-x86-Befehl-hebelt-triviale-Schutzfunktion-aus-11409272.html

Patchday: SAP Commerce Cloud komplett kompromittierbar

SAP schließt in seinem Softwareproduktportfolio mehrere unter anderem kritische Sicherheitslücken.

https://www.heise.de/news/Patchday-SAP-Commerce-Cloud-komplett-kompromittierbar-11410169.html

Sexual predators targeting online accounts for intimate images, FBI warns

The FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.

https://www.malwarebytes.com/blog/news/2026/08/sexual-predators-targeting-online-accounts-for-intimate-images-fbi-warns

The Permanent Threat: Analyzing Aeternum-s Blockchain-Based C2 Operations and Communications

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.

https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.

https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden

LexisNexis deaktiviert nach "verdächtigen Server-Aktivitäten" drei Dienste

Aktuell ist unklar, was genau passiert ist. Aber seit vorigen Mittwoch, den 5. August 2026, scheint bei LexisNexis etwas passiert zu seine. Der Anbieter hat nach "verdächtigen Server-Aktivitäten" gleich drei Dienste deaktiviert und Verbindungen zu Drittanbietern getrennt. Es laufen Untersuchungen ..

https://borncity.com/blog/2026/08/10/lexisnexis-deaktiviert-nach-verdaechtigen-server-aktivitaeten-drei-dienste/

Steam-Hardware: Käufer müssen nach Cyberangriff mit Betrugsmails rechnen

Bei Valves Logistikpartner CEVA sind Namen und Adressen europäischer Steam-Hardware-Käufer abgeflossen. Valve warnt vor falschen Nachrichten.

https://heise.de/-11409514

Google Phishing Kit: When Phishing Becomes a Real-Time Remote Browser

Most of the phishing pages are mere static clones of the login form, whereas sophisticated phishing kits implement adversary-in-the-middle techniques that perform authentication in real-time. In particular, the design being analyzed below fits into the Browser-in-the-Middle (BitM) scheme where the victim-facing page becomes the client for the browser session running at the backend of the phishing operation.The captured network traffic and the extracted client-side artifacts ..

https://www.joesecurity.org/blog/2909557602925734728

Inside the Metabase SQLi: Exploited in the Wild

Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense.

https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild

Vulnerabilities

TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool

It has been discovered that TYPO3 CMS is susceptible to broken access control.

https://news.typo3.com/security/advisory/typo3-core-sa-2026-021

Security updates for Tuesday

Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, ..

https://lwn.net/Articles/1088226/

August 2026 Security Update

https://www.ivanti.com/blog/august-2026-security-update

SAP Security Patch Day August 2026 | RedRays

https://redrays.io/blog/sap-security-patch-day-august-2026/