Tageszusammenfassung - 07.08.2026

End-of-Day report

Timeframe: Donnerstag 06-08-2026 18:00 - Freitag 07-08-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. [..] The disclosure does not identify the exact Windows builds or Windows Hello for Business deployment models tested. [..] The new work removes that requirement by treating the Windows Hello for Business key as a FIDO2 passkey through WebAuthn. Mollema found that the five-minute Entra ID challenge is not bound to a session, user, or tenant. An attacker can therefore request it on another host and have the compromised endpoint produce the signed assertion.

https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html

Durch Metabase-0day: Datenleck bei Laptophersteller Framework

Der Laptophersteller Framework hat ein Datenleck erlitten und warnt seine Kunden vor abgeflossenen Informationen. Kontakt- und Lieferdaten privater und gewerblicher Kunden kamen abhanden - Zahlungs- und Bestellinformationen nach Frameworks Angaben jedoch nicht. Offenbar nutzten Angreifer eine Zero-Day-Lücke in Metabase aus; der Datenbankhersteller hat Updates veröffentlicht und seine Cloud-Instanzen abgedichtet.

https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptophersteller-Framework-11403050.html

ChainDrop: Inside a Self-Propagating npm Worm

A self-propagating npm worm nicknamed ChainDrop infected over 400 packages that are collectively downloaded hundreds of millions of times each week. This includes malicious versions of widely used packages such as keyv and cacheable-request. Unit 42 has unique observations of this attack.

https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/

N-able N-central: 2. Hotfix vom 6. August 2026

Ein Patch gegen die Schwachstelle (CVE-2026-18576) wirkte nicht. Die RMM-Lösung wird bereits angegriffen. Der Hotfix 1 von Anfang August 2026 scheint nicht auszureichen, vor wenigen Stunden wird ein Hotfix 2 nachgeschoben.

https://borncity.com/blog/2026/08/07/n-able-n-central-2-hotfix-vom-6-august-2026/

"deGDID" entfernt GDID in Windows und blockt Neuanlage

Microsoft vergibt in Windows eine eindeutige GDID genannte Kennung, über die Nutzer identifiziert werden können. Der VPN-Anbieter Windscribe hat nun ein Skript entwickelt, um das versteckte GDID-Tracking von Microsoft unter Windows zu blockieren.

https://borncity.com/blog/2026/08/07/degdid-entfernt-gdid-in-windows-und-blockt-neuanlage/

Unternehmen fürchten US-Kill-Switch für kritische IT-Dienste

74 Prozent der Unternehmen befürchten, dass US-Anbieter auf Druck der US-Regierung wichtige Dienste sperren könnten.

https://heise.de/-11403600

Vulnerabilities

Screen Sharing: Gefährliche MacOS-Lücke lässt Angreifer Apple-Systeme kapern

Die besagte Sicherheitslücke ist als CVE-2026-65400 registriert und verfügt mit einem CVSS-Wert von 7,1 über einen hohen Schweregrad. "Ein Angreifer im Netzwerk könnte sich möglicherweise ohne gültige Anmeldedaten bei der Bildschirmfreigabe authentifizieren", heißt es in der Beschreibung. [..] Die gepatchten MacOS-Versionen tragen die Versionsnummern 26.6.1 (Tahoe), 15.7.9 (Sequoia) und 14.8.9 (Sonoma).

https://www.golem.de/news/screen-sharing-gefaehrliche-macos-luecke-laesst-angreifer-apple-systeme-kapern-2608-211694.html

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. [..] As of August 6, 2026, Debian's tracker listed bullseye, bookworm, and trixie kernel packages, including their security repositories, as vulnerable.

https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html

SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free

SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b.

https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564

WordPress 7.0.3 release

WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. [..] Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai.

https://wordpress.org/news/2026/08/wordpress-7-0-3-release/

LWN: Security updates for Friday

https://lwn.net/Articles/1087742/