Tageszusammenfassung - 21.08.2026

End-of-Day report

Timeframe: Donnerstag 20-08-2026 18:00 - Freitag 21-08-2026 18:00 Handler: Alexander Riepl Co-Handler: Guenes Holler

News

Hundreds of leaked AWS keys give full control over corporate accounts

More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.

https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/

Slowakei: Russische Backdoor in Verkehrskameras entdeckt

Die Slowakei wollte im Rahmen eines Sanierungspakets 279 neue Verkehrskameras beschaffen. Erste Geräte kamen unerwartet aus Russland - inklusive Backdoor.

https://www.golem.de/news/slowakei-russische-backdoor-in-verkehrskameras-entdeckt-2608-212088.html

N-able Passportal: Zahlreiche Unternehmen durch kritisches Passwort-Leck gefährdet

Ein Forscher hat bei N-able Passportal eine kritische Lücke entdeckt. Angreifer hätten damit leicht Zugangsdaten aus Passwort-Tresoren abgreifen können.

https://www.golem.de/news/n-able-passportal-jede-website-konnte-passwort-tresore-auslesen-2608-212171.html

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated ..

https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html

Researcher tricks Apple-s Find My into sharing location data with Linux

Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget

https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Secure Workload Software has five nasty flaws and even SaaS users have updates to install

https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838

ClaudeFix: Shared Claude Chats Meet ClickFix

ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to -fix- a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim-s system. Zscaler Threat Hunting has analyzed ..

https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix

Zimbra: Warnung vor Angriffen auf Befehlsschmuggel-Lücke

Das polnische CERT warnt vor Angriffen auf eine Befehlsschmuggel-Lücke in der Zimbra Collaboration Suite. Ein Update ist verfügbar.

https://www.heise.de/news/Zimbra-Warnung-vor-Angriffen-auf-Befehlsschmuggel-Luecke-11421424.html

Atlassian schließt mehr als 160 Sicherheitslücken in Confluence & Co.

Angreifer können unter anderem an kritischen Schadcode-Schwachstellen in Softwareprodukten von Atlassian ansetzen.

https://www.heise.de/news/Atlassian-schliesst-mehr-als-160-Sicherheitsluecken-in-Confluence-Co-11421486.html

Dell ObjectScale: Höhere Nutzerrechte erschleichbar

Sicherheitsupdates schließen mehrere Lücken in Dells Object-Storage-Plattform ObjectScale.

https://www.heise.de/news/Dell-ObjectScale-Hoehere-Nutzerrechte-erschleichbar-11421714.html

Lücke in WordPress-Plug-in Elementor Pro: 6 Millionen Webseiten gefährdet

Eine kritische Sicherheitslücke im WordPress-Plug-in Elementor Pro ermöglicht die komplette Übernahme von WordPress.

https://www.heise.de/news/Luecke-in-WordPress-Plug-in-Elementor-Pro-6-Millionen-Webseiten-gefaehrdet-11421805.html

Cyberangriff in Berlin: Behörden weiterhin offline

Zwei Senatsverwaltungen sind nach einem Cyberangriff vom Landesnetz isoliert. Das hat auch Auswirkungen auf die Auszahlung von Wohngeld.

https://heise.de/-11421320

Defeating AI-Assisted Reverse Engineering (or at Least Trying To)

At the beginning of 2026, a customer told us something along the lines of: obfuscation is finished, LLM-assisted reverse engineering breaks it. They had a walkthrough to back it up, produced by their own tooling, in which a model took one of their obfuscated libraries apart and recovered its hidden strings.They were not right, but not entirely wrong either.So we spent a ..

http://blog.quarkslab.com/defeating-ai-assisted-reverse-engineering-or-at-least-trying-to.html

I accidentally logged hundreds of thousands of phone calls to military bases

How an expired nameserver let me take over e164.arpa zones for multiple territories, and why I probably should have checked my logs sooner.

https://lina.sh/blog/hijacking-e164-arpa

Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaigns infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.

https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns

If Apple says your iPhone was targeted by mercenary spyware, treat it like an incident

Apples Threat Notifications signal mercenary spyware targeting; learn verification steps, response actions, and layered mobile security defenses for high-risk users.

https://www.jamf.com/blog/apple-threat-notification-mercenary-spyware-response/

Vulnerabilities

[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints

https://developer.joomla.org/security-centre/1070-20260803-core-inconsistent-acl-checks-for-mutating-webservice-endpoints.html