Qilin actors are deliberately exploiting an authentication bypass vulnerability as an entry point into production environments,an indicator of ransomware campaigns targeting the industrial sector.
The alert describes active in-the-wild exploitation (webshell installation, persistent infection) rather than patch availability alone,critical for security of internet-facing WordPress instances.
CVE-2026-50522 is already under active exploitation and is the third SharePoint vulnerability in July 2026 to come under attack immediately after disclosure; prior variants were weaponized as zero-days before patching.
A local privilege escalation flaw in Windows WMI allows local attackers to escalate from low-privilege to SYSTEM-level access; affects Windows Server 2022/2019 and all AD-joined clients in hybrid DACH infrastructure.
A local privilege escalation vulnerability in Windows WMI requires already-compromised low-privilege accounts for exploitation, but poses significant risk in multi-user production environments.
Russian intelligence-linked APTs are actively exploiting misconfigured routers as entry points into European critical-infrastructure organisations; this is an active, ongoing campaign pattern with direct relevance to EU/DACH regions.
MFA bypass in ADSelfService Plus allows attackers to compromise AD-integrated authentication and gain unauthorized access to enterprise-wide resources.
SANDWORM exploits AI coding assistants and LLM toolchains as novel supply-chain attack vectors by fingerprinting runtime behavior of developer workstations and CI automation,a qualitatively new threat class for organizations conducting internal software development.
Critical
NEW North Korea (state-sponsored), Russia (beneficiary) C3
North Korean IT worker networks directly finance Russia's war effort through sanctions evasion; this demonstrates an operationalized alliance between North Korea and Russia that elevates DACH organizations as potential targets for retaliation or espionage.
The vulnerability enables remote code execution via specially crafted HTML pages without prior authentication, requiring immediate patch prioritization for all Chrome installations in production environments.
The Qilin ransomware group is actively exploiting a critical authentication bypass flaw in Palo Alto PAN-OS GlobalProtect to infiltrate networks, indicating an ongoing campaign against enterprise environments.
The vulnerability enables remote code execution within the Chrome sandbox via crafted HTML pages, but is a standard patch update with no evidence of active exploitation in the wild.
The vulnerability allows local attackers to exploit heap corruption via malicious files; it requires local access and is therefore primarily relevant in scenarios involving untrusted file handling or USB access.
Kratos platform automated approximately 15,000 phishing campaigns per month; BKA dismantling reveals operational vulnerability of centralized phishing-as-a-service infrastructure in German jurisdiction.
BSI warning for multiple unspecified vulnerabilities in Chrome and Edge , patch details are missing; follow-up advisories with CVE numbers and CVSS scores are to be expected.
HollowGraph abuses Microsoft's legitimate Calendar service as a bidirectional command-and-control channel, bypassing traditional email and network-based detection and blurring the line between legitimate cloud operations and malware communication.
The BSI/BürgerCERT advisory discloses multiple vulnerabilities in widely-used browsers without technical details, likely coordinating with vendors ahead of public disclosure.
The BSI warning covers multiple unspecified vulnerabilities in Firefox/Thunderbird without CVE details or active exploitation confirmation; unclear whether public exploits exist or if this is an aggregated patch summary.
wp2shell vulnerabilities in WordPress Core enable unauthenticated remote code execution; exploitation activity began within hours of patch release, and compromised sites are used as delivery mechanisms for credential theft, malware, and fraud.
Unknown threat actors are actively exploiting multiple SonicWall SMA1000 zero-days to deploy custom malware on VPN appliances , a direct attack vector against remote access infrastructure.
OilRig APT exploits Outlook calendar events as a steganographic C2 channel and leverages DNS AAAA records for configuration recovery,a novel abuse pattern of Microsoft-hosted services.
A leading remote access provider was ordered by German financial regulator to pay damages , a signal for increased liability of security failures in critical B2B tools.
The alert describes a known operational issue with WSUS synchronization without new security or exploit implications, but only administrative measures to resolve delays.
BSI warning on generic Linux kernel DoS vulnerabilities without specific CVE references or exploit status , requires contextualisation and link to specific patches.
Russian intelligence services are conducting systematic cyber-espionage against NATO and Ukrainian military infrastructure, indicating escalated cyber-warfare operations in the immediate geographic context of the DACH region.
A critical, unauthenticated RCE vulnerability in HTTP.sys enables attackers to execute kernel-level code or trigger denial-of-service conditions by sending crafted HTTP packets to affected servers.
GigaWiper combines remote-access functionality with data-destruction capabilities in a modular platform and has been observed in active intrusions since October 2025.
BSI advisory on an Edge vulnerability with security-bypass potential requires immediate prioritization of patches and browser updates across the estate.
BSI alerts on multiple vulnerabilities in Firefox/ESR enabling RCE and security bypass , no specific CVE disclosed, indicating coordination with vendor for responsible disclosure.
The BSI warns of multiple vulnerabilities in Microsoft developer tools that can lead to remote code execution, privilege escalation, and DoS attacks , a summary of multiple updates without specific CVE details.
The BSI alert addresses multiple OpenSSH vulnerabilities generically without naming specific CVE-IDs or affected versions, making precise risk assessment difficult.
BSI advisory on multiple RCE and disclosure vulnerabilities in Adobe Acrobat/Reader without specific CVE details in the alert; patch status and PoC availability unclear from the notice.
BSI warns of multiple unspecified Chrome vulnerabilities with potential for code execution; specific CVE numbers and version information are absent from the advisory.
BaFin penalty against TeamViewer indicates inadequate security measures in a widely-used remote-access tool that is critical for IT support in manufacturing.
The malware leverages legitimate Microsoft Graph API to obfuscate command-and-control traffic through manipulated calendar events, bypassing traditional network monitoring.
The campaign exploits fake GitHub repositories disguised as AI tools and MCP servers to deceive developers and inject malware into supply chains , a significant risk for organizations whose engineers pull dependencies directly from GitHub.
Attackers combine fileless techniques and low-detection loaders to deploy multiple RATs and stealers in BEC campaigns, bypassing traditional malware detection mechanisms.
An authenticated vulnerability in Microsoft Edge enables local code execution with elevated privileges; specific CVE and CVSS metrics are required for prioritization.
The digest highlights a surge of zero-days and pre-authentication RCEs in the current week, including evidence that threat actor UTA0533 exploited multiple SonicWall SMA vulnerabilities as zero-days before public disclosure.