ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts.
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jum
Lahmer x86-Befehl hebelt triviale Schutzfunktion aus
Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus.
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from
Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will eith
Dobrindt baut Drohnenabwehr nach Vorfall in Leipzig massiv aus
Nach dem versuchten Drohnenanschlag auf dem Leipziger Flughafen wächst der politische Druck. Innenminister Dobrindt reagiert mit mehr Abwehreinheiten.
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 I
Anzeige: Microsoft 365 mit Zero Trust absichern
Microsoft 365 Zero Trust verlangt klare Kontrollen für Identitäten, Daten und Geräte. Ein Online-Workshop zeigt, wie Schutzmechanismen und Monitoring strukturiert umgesetzt werden. (<a href="https://www.golem.de/specials
BSI-Workshop: Erstellung geeigneter Vorgabendokumente für Interconnection-Point-Funktionen in 5G-Mobilfunknetzen
Der BSI-Workshop "Erstellung geeigneter Vorgabendokumente für Interconnection-Point-Funktionen in 5G-Mobilfunknetzen" richtet sich hauptsächlich an Firmen aus dem Bereich Router und findet vor Ort in Berlin sta
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data le
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting doc
Member of The Com sent to prison for blackmail, sextortion
A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide.
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attac
LexisNexis shuts down services after suspicious activity on servers
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, I
Curl-Entwickler sucht Verstärkung: "Niemand hier will mit Windows arbeiten"
Der Open-Source-Entwickler Daniel Stenberg sucht Helfer für das Curl-Security-Team. Die derzeitigen sieben Mitglieder haben alle eine Windows-Aversion. (<a href="https://www.golem.de/specials/open-source/">Open Source</a
Schadcode-Attacken auf Progress LoadMaster im Gange
Derzeit haben Angreifer Progress LoadMaster auf dem Schirm und attackieren aktiv Systeme. Sicherheitspatches sind verfügbar.
Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher
Im Rahmen des PCC-Bug-Bounty-Programms, das seit 2024 Sicherheitsexperten offensteht, kam es zu einem erfolgreichen Angriff. Telemetrie-Daten konnten abfließen.
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]
Pwnie Award: Microsoft gewinnt Schampreis für angedrohte Strafverfolgung
Microsoft hat durch seinen Streit mit Chaotic Eclipse einen Pwnie Award gewonnen. Annehmen wollte ihn wohl keiner - aus Angst vor Jobverlust. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</
Jetzt patchen! Admin-Attacken auf Metabase beobachtet
Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln.
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names
Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Cybertests aus
Das KI-Modell Kimi K3 hat bei Cybertests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.de
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding
Partnerangebot: NIS2 kompakt, Cyber-Sicherheit als Führungsaufgabe - nGENn GmbH in Kooperation mit IHK Hessen innovativ
NIS2 macht IT-Sicherheit endgültig zur Chefsache und das mit persönlicher Haftung für die Geschäftsführung. Im kostenfreien Webinar klären wir in einer Stunde die zwei Fragen, die uns am h&#
Partnerangebot: UNIVADO – “Security & AI Awareness Paket”
Im Partnerbeitrag der UNIVADO geht es um das UNIVADO Security & AI Awareness Paket – eine moderne Komplettlösung für Datenschutz, Cybersecurity und KI-Kompetenz. Unternehmen können sich 10 kostenlose
ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Berliner Staatsanwaltschaft: 350 Anklagen gegen Encrochat- und Sky-ECC-Nutzer
Die Berliner Staatsanwaltschaft zieht Zwischenbilanz zu Kryptohandys. Der Angriff auf die Systeme durch die Staatsapparate sind weiter umstritten. (<a href="https://www.golem.de/specials/man-in-the-middle/">Man-in-the-Mi
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]
Astra: OpenAI will neues KI-Modell vorerst nicht veröffentlichen
Wie gefährlich darf eine KI werden, bevor sie zur Waffe wird? OpenAI kann diese Frage bei seinem Modell Astra derzeit nicht mehr sicher beantworten. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="h
Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky