Tageszusammenfassung - 03.08.2026

End-of-Day report

Timeframe: Freitag 31-07-2026 18:00 - Montag 03-08-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

Arch Linux disables AUR package adoption to stop malware flood

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.

https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/

Inside the Underground Business of BTMOB RAT

BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it.

https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.

https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/

Coldcard-Wallets: Massenhafte Bitcoin-Diebstähle erschüttern die Kryptobranche

Bitcoins im Wert von mehr als 70 Millionen Euro haben zuletzt unverhofft die Besitzer gewechselt. Grund ist eine Schwachstelle in Hardware-Wallets von Coinkite.

https://www.golem.de/news/coldcard-wallets-massenhafte-bitcoin-diebstaehle-erschuettern-die-kryptobranche-2608-211532.html

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

https://isc.sans.edu/diary/rss/33206

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.

https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html

The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier

Both major AI labs- models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?

https://www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/

The Risk of Fine-Tuned Open-Weight Models

In the last weeks I was wondering how to continue offensive security and malware development over the next months or even years with the help of AI.

https://www.msecops.de/blog/posts/backdoored-llms/

Auswärtiges Amt warnt vor IT-Fachkräften aus Nordkorea

IT-Fachkräfte aus Nordkorea unterwandern zunehmend westliche Unternehmen. Jetzt gibt es eine internationale Warnung davor.

https://www.heise.de/news/Auswaertiges-Amt-warnt-vor-IT-Fachkraeften-aus-Nordkorea-11394444.html

Cyberangriff auf Liechtenstein - 31.000 Datensätze betroffen

Die Regierung Liechtensteins meldet einen Angriff auf ein Personenverzeichnis. Was steckt hinter dem Zugriff auf 31.000 Datensätze?

https://www.heise.de/news/Cyberangriff-auf-Liechtenstein-31-000-Datensaetze-betroffen-11395010.html

Apple: Limit für Bug-Meldungen pro Person

Apple reagiert auf die Flut von KI-generierten Sicherheitsmeldungen und begrenzt die Einreichungen pro Person.

https://www.heise.de/news/Apple-Limit-fuer-Bug-Meldungen-pro-Person-11395377.html

Traumjob von zuhause? Achtung Geldwäschefalle!

Kriminelle geben sich als Personaler:innen aus, um ahnungslose Menschen für Geldwäsche zu missbrauchen. Die Opfer wissen dabei oft von nichts. Wir zeigen, wie Sie den Betrug erkennen.

https://www.watchlist-internet.at/news/traumjob-von-zuhause-geldwaesche/

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

This article analyzes new attack classes against passwordless authentication, focusing on Google-s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.

https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/

The Hidden CCS2 Attack Surface on EV Chargers

An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage.

https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers

Guide to Bypassing Hotel Wi-Fi Captive Portals (With Permission)

Have you ever been curious about how easy it is to bypass that pesky captive portal? This article guides you through 3 different methods.

https://projectblack.io/blog/bypassing-hotel-wi-fi-captive-portals/

Vulnerabilities

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.

https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html

Adobe Campaign Classic Schwachstelle CVE-2026-48449 (CVSS 3.x 10.0) gepatcht

Adobe musste die Tage die Schwachstelle CVE-2026-48449 in seinem Produkt Adobe Campaign Classic patchen. Es handelt sich um eine Authorisierungsschwachstelle, die das umgehen einer Anmeldung ermöglicht. Die Schwachstelle wurde mit einem CVSS 3.x von 10.0, also dem höchstmöglichen Wert, als kritisch eingestuft.

https://borncity.com/blog/2026/08/03/adobe-campaign-classic-schwachstelle-cve-2026-48449-cvss-3-x-10-0-gepatcht/

LWN Security updates for Monday

https://lwn.net/Articles/1086897/

Synology-SA-26:12 Synology Assistant

https://www.synology.com/en-global/support/security/Synology_SA_26_12