End-of-Day report
Timeframe: Montag 10-08-2026 18:00 - Dienstag 11-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
News
New Pass-ta-key attack reveals all the things we didnt know about passkeys
Why passkey apps treat Windows differently than other operating systems.
https://arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-attack-is-mostly-a-nothingburger/
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network.
https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.
https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus
Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft.
https://www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-forscher-bei-cybertests-aus-2608-211748.html
Kein Klick nötig: Plug-and-Pwn-Angriff kapert Windows-Systeme per USB
Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen - manchmal sogar aus der Ferne.
https://www.golem.de/news/kein-klick-noetig-plug-and-pwn-angriff-kapert-windows-systeme-per-usb-2608-211809.html
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platforms plugins team to temporarily disable their downloads."Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California drivers license and a New York bank account.The
https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security ..
https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
Lahmer x86-Befehl hebelt triviale Schutzfunktion aus
Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus.
https://www.heise.de/news/Lahmer-x86-Befehl-hebelt-triviale-Schutzfunktion-aus-11409272.html
Patchday: SAP Commerce Cloud komplett kompromittierbar
SAP schließt in seinem Softwareproduktportfolio mehrere unter anderem kritische Sicherheitslücken.
https://www.heise.de/news/Patchday-SAP-Commerce-Cloud-komplett-kompromittierbar-11410169.html
Sexual predators targeting online accounts for intimate images, FBI warns
The FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.
https://www.malwarebytes.com/blog/news/2026/08/sexual-predators-targeting-online-accounts-for-intimate-images-fbi-warns
The Permanent Threat: Analyzing Aeternum-s Blockchain-Based C2 Operations and Communications
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.
https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
Poland uncovers second heat plant cyberattack that went hidden for months
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden
LexisNexis deaktiviert nach "verdächtigen Server-Aktivitäten" drei Dienste
Aktuell ist unklar, was genau passiert ist. Aber seit vorigen Mittwoch, den 5. August 2026, scheint bei LexisNexis etwas passiert zu seine. Der Anbieter hat nach "verdächtigen Server-Aktivitäten" gleich drei Dienste deaktiviert und Verbindungen zu Drittanbietern getrennt. Es laufen Untersuchungen ..
https://borncity.com/blog/2026/08/10/lexisnexis-deaktiviert-nach-verdaechtigen-server-aktivitaeten-drei-dienste/
Steam-Hardware: Käufer müssen nach Cyberangriff mit Betrugsmails rechnen
Bei Valves Logistikpartner CEVA sind Namen und Adressen europäischer Steam-Hardware-Käufer abgeflossen. Valve warnt vor falschen Nachrichten.
https://heise.de/-11409514
Google Phishing Kit: When Phishing Becomes a Real-Time Remote Browser
Most of the phishing pages are mere static clones of the login form, whereas sophisticated phishing kits implement adversary-in-the-middle techniques that perform authentication in real-time. In particular, the design being analyzed below fits into the Browser-in-the-Middle (BitM) scheme where the victim-facing page becomes the client for the browser session running at the backend of the phishing operation.The captured network traffic and the extracted client-side artifacts ..
https://www.joesecurity.org/blog/2909557602925734728
Inside the Metabase SQLi: Exploited in the Wild
Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense.
https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
Vulnerabilities
TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
It has been discovered that TYPO3 CMS is susceptible to broken access control.
https://news.typo3.com/security/advisory/typo3-core-sa-2026-021
Security updates for Tuesday
Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, ..
https://lwn.net/Articles/1088226/
August 2026 Security Update
https://www.ivanti.com/blog/august-2026-security-update
SAP Security Patch Day August 2026 | RedRays
https://redrays.io/blog/sap-security-patch-day-august-2026/