End-of-Day report
Timeframe: Donnerstag 13-08-2026 18:00 - Freitag 14-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
News
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/
Ukraine shuts down 94 fraudulent call centers, seize millions in cash
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts.
https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash/
Shell investigates potential incident after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/
Security: Der Phish stinkt vom Kopf her
Anti-Phishing-Kampagnen sollen die IT-Laien in einer Firma fit gegen Angriffe machen. Das ist aber komplett der falsche Ansatz. Ein IMHO von R. Zehl
https://www.golem.de/news/security-der-phish-stinkt-vom-kopf-her-2608-211872.html
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Digitale Kaperbriefe: US-Regierung erlaubt Unternehmen offensive Cyberangriffe
Im Kampf gegen transnationale kriminelle Akteure will die US-Regierung verstärkt auf die Privatwirtschaft setzen. Unternehmen sollen selbst angreifen dürfen.
https://www.heise.de/news/Digitale-Kaperbriefe-US-Regierung-erlaubt-Unternehmen-offensive-Cyberangriffe-11413398.html
Studie zum Umgang mit Passkeys: Nutzer wissen zu wenig Bescheid
Passkeys sollen Passwörter ablösen, sie gelten als viel sicherer. In der Praxis fehlt vielen Nutzern noch Wissen, haben US-Forscher herausgefunden.
https://www.heise.de/news/Studie-zum-Umgang-mit-Passkeys-Teilweise-gefaehrlicher-als-Passwoerter-11413954.html
Vermehrt Betrugsversuche auf Buchungsplattformen (booking.com, ..)
Momentan erreichen uns vermehrt Meldungen über Betrugsversuche in Bezug auf Reisebuchungen über Plattformen wie beispielsweise booking.com. Eine der häufigsten Methoden der Kriminellen ist der Missbrauch echter Buchungsdaten. Dabei erhalten Personen nach einer tatsächlichen Buchung über eine Reiseplattform eine Nachricht per E-Mail, SMS ..
https://www.cert.at/de/aktuelles/2026/8/vermehrt-betrugsversuche-auf-buchungsplattformen-bookingcom
New Mirai variant adds stealth capabilities to notorious botnet code
Beyond Mirai-s usual functions, the new code features include encrypted communications with command-and-control servers and a -sniffer- that looks for default access credentials.
https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code
You-re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
Suddenly, you-re in a room. You look around - oh, you-re surrounded by other new starters at your new job. Yes, it-s Monday, and you-re being onboarded.You know the drill - it-s the typical ..
https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Seitenkanal erlaubt Zugriff auf RAM des AMD-Sicherheitscontrollers PSP
Bei alten AMD-Prozessoren lässt sich die in Hardware verankerte RAM-Adressverwaltung manipulieren, um auf vermeintlich geschützte Bereiche zuzugreifen.
https://heise.de/-11414481
How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRTs response to a coordinated multi-organization campaign.
https://www.wiz.io/blog/investigating-github-pat-compromise
Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain
Personal repositories are where corporate secrets quietly escape. Wiz correlates them to your developers, validates the real risk, and drives the fix.
https://www.wiz.io/blog/securing-personal-repositories
Vulnerabilities
External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
https://www.drupal.org/sa-contrib-2026-098
[R1] Security Center Version 6.9.0 Fixes Multiple Vulnerabilities
https://www.tenable.com/security/tns-2026-22