End-of-Day report
Timeframe: Mittwoch 05-08-2026 18:00 - Donnerstag 06-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
News
COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/
Schweiz: Bundesamt für Informatik und Telekommunikation über Sharepoint gehackt
Ein Cyberangriff hat das Schweizer BIT getroffen. Angreifer sind über Microsoft Sharepoint eingedrungen und haben Hunderte Nutzerkonten kompromittiert.
https://www.golem.de/news/schweiz-bundesamt-fuer-informatik-und-telekommunikation-ueber-sharepoint-gehackt-2608-211659.html
"Wiederkehrendes Muster": OpenSSL-Entwickler wettert gegen KI-Hacks
Seit einigen Tagen hacken sich vermehrt KI-Modelle von OpenAI, Anthropic und Meta durchs Netz. Das Problem liegt laut OpenSSL-Entwickler Hudson aber nicht bei der KI.
https://www.golem.de/news/wiederkehrendes-muster-openssl-entwickler-wettert-gegen-ki-hacks-2608-211664.html
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developers computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and ..
https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side ..
https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available ..
https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Cybersecurity researchers have disclosed a security issue with Apples iCloud Private Relay tool that can expose a users real IP address.Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users privacy by routing ..
https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.Its August 3 scan counted 4,407 exposed Rockwell ..
https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html
ClaudeFix: Shared Claude Chats Meet ClickFix
ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to -fix- a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim-s system. Zscaler Threat Hunting has identified ..
https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix
Fehlende Kontaktmöglichkeit: Deutschland verschläft Sicherheit per security.txt
Nur 1,8 Prozent der deutschen Webseiten bieten eine standardisierte security.txt an. Das BSI warnt vor den Risiken und verweist auf kommende Meldepflichten.
https://www.heise.de/news/Fehlende-Kontaktmoeglichkeit-Deutschland-verschlaeft-Sicherheit-per-security-txt-11402270.html
Scammers target OnlyFans users with deepfakes
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers.
https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-users-with-deepfakes
Apple-s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didnt exist.
https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.
https://unit42.paloaltonetworks.com/ai-token-jacking/
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
https://hackread.com/octlurk-silklurk-backdoors-target-6-countries/
Sicherheitspatches: Angreifer können Schadcode auf n8n-Servern ausführen
Die n8n-Entwicklwer haben in aktuellen Versionen insgesamt 18 Sicherheitslücken geschlossen.
https://heise.de/-11400494
Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS
Jamf Threat Labs uncovers a macOS campaign using a fake Zoom installer to deploy Overlord RAT. Built with .NET, this cross-platform technique simultaneously targets Windows, joining Go- and Rust-based cross-platform malware.
https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
Vulnerabilities
Cisco IOS XE Software Security Hardening Release: August 2026
As part of Ciscos ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not ..
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ
Veeam: Vulnerabilities Resolved in Veeam ONE 13.1
Veeam has released 6 new security advisories for Veeam ONE (1x critical, 4x high, 1x medium)
https://www.veeam.com/kb4892
Security updates for Thursday
Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark).
https://lwn.net/Articles/1087489/
Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094
https://www.drupal.org/sa-contrib-2026-094
Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093
https://www.drupal.org/sa-contrib-2026-093