End-of-Day report
Timeframe: Freitag 31-07-2026 18:00 - Montag 03-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/
Inside the Underground Business of BTMOB RAT
BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it.
https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.
https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/
Coldcard-Wallets: Massenhafte Bitcoin-Diebstähle erschüttern die Kryptobranche
Bitcoins im Wert von mehr als 70 Millionen Euro haben zuletzt unverhofft die Besitzer gewechselt. Grund ist eine Schwachstelle in Hardware-Wallets von Coinkite.
https://www.golem.de/news/coldcard-wallets-massenhafte-bitcoin-diebstaehle-erschuettern-die-kryptobranche-2608-211532.html
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
https://isc.sans.edu/diary/rss/33206
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
Both major AI labs- models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
https://www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/
The Risk of Fine-Tuned Open-Weight Models
In the last weeks I was wondering how to continue offensive security and malware development over the next months or even years with the help of AI.
https://www.msecops.de/blog/posts/backdoored-llms/
Auswärtiges Amt warnt vor IT-Fachkräften aus Nordkorea
IT-Fachkräfte aus Nordkorea unterwandern zunehmend westliche Unternehmen. Jetzt gibt es eine internationale Warnung davor.
https://www.heise.de/news/Auswaertiges-Amt-warnt-vor-IT-Fachkraeften-aus-Nordkorea-11394444.html
Cyberangriff auf Liechtenstein - 31.000 Datensätze betroffen
Die Regierung Liechtensteins meldet einen Angriff auf ein Personenverzeichnis. Was steckt hinter dem Zugriff auf 31.000 Datensätze?
https://www.heise.de/news/Cyberangriff-auf-Liechtenstein-31-000-Datensaetze-betroffen-11395010.html
Apple: Limit für Bug-Meldungen pro Person
Apple reagiert auf die Flut von KI-generierten Sicherheitsmeldungen und begrenzt die Einreichungen pro Person.
https://www.heise.de/news/Apple-Limit-fuer-Bug-Meldungen-pro-Person-11395377.html
Traumjob von zuhause? Achtung Geldwäschefalle!
Kriminelle geben sich als Personaler:innen aus, um ahnungslose Menschen für Geldwäsche zu missbrauchen. Die Opfer wissen dabei oft von nichts. Wir zeigen, wie Sie den Betrug erkennen.
https://www.watchlist-internet.at/news/traumjob-von-zuhause-geldwaesche/
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
This article analyzes new attack classes against passwordless authentication, focusing on Google-s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
The Hidden CCS2 Attack Surface on EV Chargers
An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage.
https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers
Guide to Bypassing Hotel Wi-Fi Captive Portals (With Permission)
Have you ever been curious about how easy it is to bypass that pesky captive portal? This article guides you through 3 different methods.
https://projectblack.io/blog/bypassing-hotel-wi-fi-captive-portals/
Vulnerabilities
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.
https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html
Adobe Campaign Classic Schwachstelle CVE-2026-48449 (CVSS 3.x 10.0) gepatcht
Adobe musste die Tage die Schwachstelle CVE-2026-48449 in seinem Produkt Adobe Campaign Classic patchen. Es handelt sich um eine Authorisierungsschwachstelle, die das umgehen einer Anmeldung ermöglicht. Die Schwachstelle wurde mit einem CVSS 3.x von 10.0, also dem höchstmöglichen Wert, als kritisch eingestuft.
https://borncity.com/blog/2026/08/03/adobe-campaign-classic-schwachstelle-cve-2026-48449-cvss-3-x-10-0-gepatcht/
LWN Security updates for Monday
https://lwn.net/Articles/1086897/
Synology-SA-26:12 Synology Assistant
https://www.synology.com/en-global/support/security/Synology_SA_26_12