Tageszusammenfassung - 13.08.2026

End-of-Day report

Timeframe: Mittwoch 12-08-2026 18:00 - Donnerstag 13-08-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

Neue Phishing-Welle trifft zahlreiche Hotels: Gäste sollten wachsam sein

Mitten in der Ferienzeit häufen sich erfolgreiche Angriffe auf IT-Dienstleister der Hotelbranche. Gäste erhalten derzeit vermehrt täuschend echt wirkende Phishing-Nachrichten, die sie zu Zahlungen oder zur Preisgabe von Kreditkartendaten drängen. Einer der aktuellen Fälle betrifft den österreichischen IT-Dienstleister Seekda. Nach einem Phishing-Angriff informiert Seekda erste Betroffene über ungewöhnliche Zugriffsmuster auf seine Systeme. Das Ausmaß des Sicherheitsvorfalls dürfte groß sein.

https://www.heise.de/news/Phishing-Wellen-Cyberangriffe-auf-IT-Dienstleister-fuer-Hotels-11412013.html

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users traffic through SOCKS5 proxies operated by a single provider.

https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy/

Android malware combo takes out loans and relays victims credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [..] When receiving a call from your bank and asked to take urgent action, it is advisable to terminate the call, dial the number listed on the organization's official website, and ask to connect with the same support agent.

https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [..] Reco says all of the attacks originate from the IP address 158.220.87.79, hosted by German VPS provider Contabo, and almost always use the default Go-http-client/1.1 user agent when downloading data. This IP address is associated with the city-forum.com domain, which has resolved to the server since at least March 2025, indicating that the infrastructure has remained in place for more than a year.

https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals/

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks, Industrial Ethernet 1000 Series Switches, Packaged Contact Center Enterprise and Unified Contact Center Enterprise, RoomOS, Secure Firewall Adaptive Security Appliance, Secure Firewall Management Center, Secure Firewall Threat Defense Center, Secure Workload, Unified Intelligence Center

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-LDquvx5d

Verschlüsselter KI--Denkprozess- gehackt: Schwache Modelle verraten Geheimnisse

Über eine Sicherheitslücke lassen sich Abwägungsprotokolle von KI-Top-Systemen wie GPT-5 im Klartext auslesen - mithilfe kleinerer Modelle desselben Anbieters.

https://www.heise.de/hintergrund/Verschluesselter-KI-Denkprozess-gehackt-Schwache-Modelle-verraten-Geheimnisse-11412087.html

How BitLocker PINs help protect your data and devices

The NCSC provides guidance on how to securely configure Microsoft Windows. This includes setting up BitLocker, which encrypts your device to protect the data and the operating system from tampering. Our guidance recommends that BitLocker be configured to require a PIN before decrypting your device.

https://www.ncsc.gov.uk/blogs/how-bitlocker-pins-help-protect-your-data-and-devices

WhatsApp-Benutzernamen: Vor- und Nachteile im Überblick

Wie schützt ein WhatsApp-Benutzername vor Betrug - und welche Daten gibt man preis? Verbraucherschützer bewerten den Status quo beim Meta-Messenger.

https://heise.de/-11412273

Vulnerabilities

Fortinet FortiManager FGFM Authentication Weakening via CLI Configuration

An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. CVE-2026-70468

https://fortiguard.fortinet.com/psirt/FG-IR-26-160

GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6

These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately.

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/

Palo Alto Networks Security Advisories 12.08.2026

https://security.paloaltonetworks.com/

LWN: Security updates for Thursday

https://lwn.net/Articles/1088715/