=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 22-09-2026 18:00 − Mittwoch 23-09-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Ab 1.10: Meldepflicht für IT-Vorfälle in Österreich ∗∗∗
---------------------------------------------
Die NIS-2-Richtlinie beschert Österreich Registrierungspflichten für Unternehmen und Behörden. Diese erhalten Zuwachs: Das neue Bundesamt für Cybersicherheit.
---------------------------------------------
https://www.heise.de/news/Ab-1-10-Meldepflicht-fuer-IT-Vorfaelle-in-Oesterr…
∗∗∗ Gefälschter FinanzOnline-Mail: 3.612 Euro Steuererstattung versprochen ∗∗∗
---------------------------------------------
Mit einer neuen Variante des bekannten FinanzOnline-Phishings versuchen Kriminelle derzeit, an Bankdaten von Österreicher:innen zu gelangen. In einer gefälschten E-Mail wird eine Steuererstattung von 3.612 Euro versprochen.
---------------------------------------------
https://www.watchlist-internet.at/news/gefaelschter-finanzonline-mail/
∗∗∗ Hacker dringen in Systeme von Fresenius Medical Care ein ∗∗∗
---------------------------------------------
Medizinische Geräte, Patientenversorgung, Produktion und laufender Geschäftsbetrieb sollen laut Konzern nicht beeinträchtigt sein.
---------------------------------------------
https://www.derstandard.at/story/3000000340976/hacker-dringen-in-systeme-vo…
∗∗∗ Microsoft: September Windows updates break Always On VPN connections ∗∗∗
---------------------------------------------
Microsoft has notified IT administrators that users may experience Always On VPN connection issues after installing the September 2026 Windows 11 security updates.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-wi…
∗∗∗ Absturzgefahr: Exploit lässt Angreifer DJI-Drohnen mitten im Flug kapern ∗∗∗
---------------------------------------------
Mehrere Drohnenmodelle des Herstellers DJI sind anfällig für eine gefährliche Sicherheitslücke, die eine vollständige Kontrollübernahme ermöglicht. Nutzer sollten nach korrigierten Firmware-Versionen Ausschau halten.
---------------------------------------------
https://www.golem.de/news/per-bluetooth-exploit-laesst-angreifer-dji-drohne…
∗∗∗ Macfinger ClickFix campaign, (Tue, Sep 22nd) ∗∗∗
---------------------------------------------
I've found several legitimate websites with injected script for a campaign using the ClickFix social engineering technique. This particular ClickFix campaign was documented earlier this month on the Ransom-ISAC Blog, but it doesn't appear to have a nickname yet. Since this campaign is targeting macOS environments through a fingerprinting process, I'm calling it the "Macfinger ClickFix" campaign. No, this is not related to the MacFinger utility from decades ago. Instead, think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore.
---------------------------------------------
https://isc.sans.edu/diary/rss/33360
∗∗∗ Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape ∗∗∗
---------------------------------------------
A use-after-free in the Linux kernels AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases.
---------------------------------------------
https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html
∗∗∗ Recent Increase of Hybrid Attacks Against Defense Sector in Europe ∗∗∗
---------------------------------------------
Recently, a wave of sabotage attacks has been reported in Europe. In most cases Russia is suspected to be responsible. These events follow a broader pattern of hybrid activity directed at European infrastructure, logistics networks, and organizations supporting Ukraine.
---------------------------------------------
https://www.truesec.com/hub/blog/recent-increase-of-hybrid-attacks-against-…
∗∗∗ Iranian Cyber Espionage Campaign ∗∗∗
---------------------------------------------
An Iranian threat actor is conducting a cyber espionage campaign targeting Iranian nationals abroad. The attacker reaches out to the victim on various messaging apps, like Telegram or Whatsapp. The actor often claims to be an individual previously known to the target or technical support from the social messaging platform.
---------------------------------------------
https://www.truesec.com/hub/blog/iranian-cyber-espionage-campaign
=====================
= Vulnerabilities =
=====================
∗∗∗ Cyberangriffe auf F5 BIG-IP, Check Point Security und Arista VeloCloud ∗∗∗
---------------------------------------------
IT-Verantwortliche müssen rasch handeln, um bereitgestellte Aktualisierungen zu installieren. Mehrere IT-Sicherheitsbehörden warnen vor derzeit laufenden Angriffen auf Sicherheitslücken in F5 BIG-IP, Check Point Security Gateway und Management sowie Arista VeloCloud Orchestrator On-Premise.
---------------------------------------------
https://heise.de/-11462590
∗∗∗ Patchday: Adobe Connect ist unter Android, macOS und Windows verwundbar ∗∗∗
---------------------------------------------
Es sind wichtige Sicherheitsupdates für verschiedene Adobe-Anwendungen erschienen.
---------------------------------------------
https://heise.de/-11462802
∗∗∗ NetBSD 10.2 stopft einige Sicherheitslücken ∗∗∗
---------------------------------------------
NetBSD ist jüngst als Point-Release 10.2 erschienen. Die Entwickler schließen damit einige Sicherheitslücken.
---------------------------------------------
https://heise.de/-11463028
∗∗∗ Gleich noch ein Sicherheitsupdate für WordPress ∗∗∗
---------------------------------------------
Angreifer können WordPress dazu bringen, nicht vorgesehene .php-Dateien aufzurufen. Das kann zur Ausführung von Code führen.
---------------------------------------------
https://heise.de/-11462385
∗∗∗ Ubiquiti schließt Denial-of-Service-Lücken in Firewalls und Gateways ∗∗∗
---------------------------------------------
In UniFi-Firewalls und -Gateways klaffen hochriskante Denial-of-Service-Lücken. Aktualisierte Firmware stopft die Lecks.
---------------------------------------------
https://heise.de/-11463176
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1096191/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 21-09-2026 18:00 − Dienstag 22-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ "Bundesamt für Cybersicherheit" geht mit Oktober an den Start ∗∗∗
---------------------------------------------
Leiter Markus Kasinger war zuvor bei Austrian Power Grid. Zu den Aufgaben gehört die Weiterentwicklung der nationalen Cybersicherheitsstrategie.
---------------------------------------------
https://www.derstandard.at/story/3000000340881/bundesamt-fuer-cybersicherhe…
∗∗∗ New Windows Defender zero-day blocks Microsoft antivirus updates ∗∗∗
---------------------------------------------
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-da…
∗∗∗ Politik: EU-Kommission will Europol-Datenbefugnisse ausweiten ∗∗∗
---------------------------------------------
Ein Verordnungsentwurf sieht den Abbau von Schutzmechanismen bei Europol vor, um KI-Systeme anlasslos mit Daten zu speisen.
---------------------------------------------
https://www.golem.de/news/politik-eu-kommission-will-europol-datenbefugniss…
∗∗∗ Smart-TVs: Youtuber entfernt WLAN-Modul aus neuem LG-TV ∗∗∗
---------------------------------------------
Nach Berichten über Spionagefunktionen entfernt ein Youtuber Hardwarekomponenten aus seinem LG OLED G6. Der Fernseher funktioniert weiterhin.
---------------------------------------------
https://www.golem.de/news/smart-tvs-youtuber-entfernt-wlan-modul-aus-neuem-…
∗∗∗ Unmasking EvilTokens: Getting to the root of device code phishing ∗∗∗
---------------------------------------------
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltoke…
∗∗∗ Microsoft wirft SMS-basierte Authentifizierung aus Entra ID raus ∗∗∗
---------------------------------------------
Microsofts Identitätsverwaltung und Login-Lösung Entra ID erlaubt die Authentifizierung mit SMS. Das soll bald ein Ende haben.
---------------------------------------------
https://heise.de/-11461055
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdates: Click2Shell-Lücke zum Kompromittieren von WordPress-Websites ∗∗∗
---------------------------------------------
Aufgrund mehrerer Sicherheitslücken raten die WordPress-Entwickler zu einem zügigen Update. Bislang gibt es keine Hinweise auf Attacken.
---------------------------------------------
https://heise.de/-11460973
∗∗∗ Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access ∗∗∗
---------------------------------------------
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow
vulnerability that could result in arbitrary operating system (OS) command execution.
---------------------------------------------
https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html
∗∗∗ D-Link warns of max severity zero-day bug in DIR-822A routers ∗∗∗
---------------------------------------------
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity…
∗∗∗ New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups ∗∗∗
---------------------------------------------
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed. As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July.
---------------------------------------------
https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1096022/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 18-09-2026 18:00 − Montag 21-09-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Cyberangriff trifft Universität: LMU München bestätigt Abfluss von Studentendaten ∗∗∗
---------------------------------------------
Ein Angreifer ist an persönliche Daten von Studenten der Ludwig-Maximilians-Universität München gelangt. Auch Bankdaten sollen betroffen sein.
---------------------------------------------
https://www.golem.de/news/cyberangriff-trifft-universitaet-lmu-muenchen-bes…
∗∗∗ Hackerangriff auf die GUTcert; Kundendaten abgeflossen ∗∗∗
---------------------------------------------
Unschöne Nachricht für Kunden, die sich über die GUTcert einer Zertifizierung unterzogen haben. Der Anbieter ist Opfer eines Hackerangriffs geworden, bei dem auch Kundendaten abgeflossen sind. Betroffene scheinen vom Unternehmen gerade informiert zu werden, wie ein Leser mir heute mitteilte.
---------------------------------------------
https://borncity.com/blog/2026/09/20/hackerangriff-auf-die-gutcert-kundenda…
∗∗∗ Gyazo server flaw exploited to steal 23.6 million user records ∗∗∗
---------------------------------------------
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-…
∗∗∗ ShinyHunters hacks Clop leak site, threatens to extort ransomware gang ∗∗∗
---------------------------------------------
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operations data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak…
∗∗∗ North Korean WaterPlum hackers infected 30,000 devices worldwide ∗∗∗
---------------------------------------------
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hacke…
∗∗∗ Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO ∗∗∗
---------------------------------------------
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.
---------------------------------------------
https://securelist.com/tr/payload-ransomware-via-group-policy/121335/
∗∗∗ CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories ∗∗∗
---------------------------------------------
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
---------------------------------------------
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
∗∗∗ TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
---------------------------------------------
https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
∗∗∗ Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation ∗∗∗
---------------------------------------------
GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable intrusions we observed including the theft of more than 18,000 sensitive records from a western government.
---------------------------------------------
https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-gover…
∗∗∗ EU prüft OpenAI nach nicht gemeldetem Sicherheitsvorfall ∗∗∗
---------------------------------------------
Nach einem Vorfall beim Software-Register RubyGems meldete OpenAI diesen nicht der EU. Die europäischen Behörden prüfen nun die Einhaltung des AI Acts.
---------------------------------------------
https://heise.de/-11458971
∗∗∗ Cisco Zero-Day Highlights API Endpoint Authentication Issues ∗∗∗
---------------------------------------------
The authentication bypass flaw CVE-2026-76460 impacts Ciscos Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
---------------------------------------------
https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endp…
=====================
= Vulnerabilities =
=====================
∗∗∗ Behörde warnt: Angriffe auf Lücken im Linux-Kernel beobachtet ∗∗∗
---------------------------------------------
Die Cisa warnt vor laufenden Angriffen auf Linux-Systeme über drei gefährliche Sicherheitslücken in Kernel-Komponenten. Korrekturen sind verfügbar.
---------------------------------------------
https://www.golem.de/news/behoerde-warnt-angriffe-auf-luecken-im-linux-kern…
∗∗∗ Synology warnt: Kritische NAS-Lücken ermöglichen Datenklau ∗∗∗
---------------------------------------------
Angreifer können durch mehrere Sicherheitslücken lesend und schreibend auf NAS-Geräte von Synology zugreifen. Patches sind verfügbar.
---------------------------------------------
https://www.golem.de/news/synology-warnt-kritische-nas-luecken-ermoeglichen…
∗∗∗ Werbeblocker Pi-hole: Update stopft Codeschmuggel-Lücken ∗∗∗
---------------------------------------------
Ein Update für den DNS-basierten Werbeblocker Pi-hole schließt teils hochriskante Codeschmuggel-Lücken.
---------------------------------------------
https://www.heise.de/news/Werbeblocker-Pi-hole-Update-stopft-Codeschmuggel-…
∗∗∗ Fremdzugriffe auf SolarWinds Access Rights Manager vorstellbar ∗∗∗
---------------------------------------------
Ein Sicherheitspatch schließt eine Schwachstelle in SolarWinds Access Rights Manager. Bislang gibt es keine Hinweise auf Attacken.
---------------------------------------------
https://heise.de/-11459978
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1095702/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 17-09-2026 18:00 − Freitag 18-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Schockanrufe: Wenn Angst und Zeitdruck zur Falle werden ∗∗∗
---------------------------------------------
In einer bundesweiten Kampagne informiert das Bundeskriminalamt gemeinsam mit Partnerorganisationen über die zunehmende Gefahr sogenannter Schockanrufe. Dabei werden nicht nur die Methoden organisierter Tätergruppen näher beleuchtet, zusätzlich gibt es auch Tipps, wie Sie Schockanrufe frühzeitig erkennen und richtig reagieren. Ziel der Kampagne ist es, insbesondere ältere Menschen sowie deren Angehörige für die Methoden organisierter Tätergruppen zu sensibilisieren.
---------------------------------------------
https://www.watchlist-internet.at/news/schockanrufe/
∗∗∗ New RatHat Android malware uses AI to automate device control ∗∗∗
---------------------------------------------
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-u…
∗∗∗ Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer ∗∗∗
---------------------------------------------
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-…
∗∗∗ Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files ∗∗∗
---------------------------------------------
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.
---------------------------------------------
https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
∗∗∗ Researchers find way to listen in on headphones from afar ∗∗∗
---------------------------------------------
Eves dropping in on Alice and Bob
---------------------------------------------
https://www.theregister.com/security/2026/09/17/researchers-find-way-to-lis…
∗∗∗ Supply-Chain-Angriff: Quellcode von CrowdSec durch Unbekannte ausgeleitet ∗∗∗
---------------------------------------------
Vor vier Monaten gelangten über dreihundert Repositories in fremde Hände. Doch die Auswirkungen des Angriff von Mai schätzt der WAF-Hersteller als gering ein.
---------------------------------------------
https://www.heise.de/news/Supply-Chain-Angriff-Quellcode-von-CrowdSec-durch…
∗∗∗ Nordkoreanische Cybergruppe bestiehlt IT-Fachleute auf Jobsuche ∗∗∗
---------------------------------------------
Sicherheitsbehörden warnen vor einer Cybergruppe aus Nordkorea, die gezielt IT-Spezialisten angreift. Was hinter der Kampagne „Contagious Interview“ steckt.
---------------------------------------------
https://heise.de/-11458275
∗∗∗ Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation ∗∗∗
---------------------------------------------
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.
---------------------------------------------
https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
=====================
= Vulnerabilities =
=====================
∗∗∗ Root-Sicherheitslücke gefährdet Check Point Security Management and Log Servers ∗∗∗
---------------------------------------------
Ein Sicherheitsupdate schließt eine kritische Schadcode-Schwachstelle in Check Point Security Management and Log Servers.
---------------------------------------------
https://www.heise.de/news/Root-Sicherheitsluecke-gefaehrdet-Check-Point-Sec…
∗∗∗ Jetzt aktualisieren: Angreifer konnten beliebige Daten von Synology-NAS auslesen ∗∗∗
---------------------------------------------
Gleich auf drei verschiedenen Wegen konnten Angreifer Daten von Synology-NAS klauen. Der Hersteller behebt mit einem Flicken auch weniger dringende Lücken.
---------------------------------------------
https://www.heise.de/news/Jetzt-aktualisieren-Angreifer-konnten-beliebige-D…
∗∗∗ 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS ∗∗∗
---------------------------------------------
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.
---------------------------------------------
https://www.wordfence.com/blog/2026/09/100000-wordpress-sites-exposed-to-re…
∗∗∗ Atlassian: Angreifer können Confluence Data Center ausspionieren ∗∗∗
---------------------------------------------
Atlassian hat zahlreiche Sicherheitslücken in Bitbucket, Jira & Co. geschlossen. Admins sollten die verfügbaren Sicherheitspatches zeitnah
installieren.
---------------------------------------------
https://heise.de/-11458267
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1095219/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 16-09-2026 18:00 − Donnerstag 17-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Fake-Webseiten: Kriminelle kopieren den Online-Auftritt echter Hotels ∗∗∗
---------------------------------------------
Die Absicht ist klar, die momentane Häufung hingegen ein wenig ungewöhnlich. In den letzten Wochen wurden besonders viele Fake-Webseiten gemeldet, die gezielt den Onlineauftritt von (Familien-)Hotels kopieren. Kriminelle wollen damit vorrangig an Kontaktdaten ihrer Opfer gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-webseiten-echte-hotels/
∗∗∗ Cisco warns of max severity ISE zero-day exploited in attacks ∗∗∗
---------------------------------------------
The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration. [..] Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-serv…
∗∗∗ EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats ∗∗∗
---------------------------------------------
European Commission President Ursula von der Leyen has proposed an Emergency Security Protocol that would allow any European Union member state to trigger a coordinated response to security incidents including cyberattacks, sabotage and drone incursions. [..] Under the proposed Emergency Security Protocol, a single member state could trigger the mechanism, prompting all 27 EU governments to convene. The proposed framework would be designed to coordinate a European response, deter further escalation and mitigate the consequences of an incident.
---------------------------------------------
https://thecyberexpress.com/eu-emergency-security-protocol-targets-threats/
∗∗∗ OpenAI führt Framework zur Meldung von KI-Sicherheitsvorfällen ein ∗∗∗
---------------------------------------------
OpenAI will dem Fehlverhalten seiner eigenen KI-Modelle systematischer auf den Grund gehen. Hierzu wurde jetzt ein neues Framework vorgestellt, das solche Fälle systematisch verfolgen, untersuchen und offenlegen soll. Bislang hatte das US-Unternehmen solche Sicherheitsvorfälle nur auf Ad-hoc-Basis bekanntgegeben. Im dazugehörigen Blogpost bekräftigt OpenAI zugleich Forderungen nach einer Verlangsamung der KI-Weiterentwicklung, wie sie zuletzt auch vom Rivalen Anthropic erhoben wurden, um den Sicherheitsrisiken Rechnung zu tragen, die aus den Fortschritten in der KI erwachsen.
---------------------------------------------
https://www.heise.de/news/OpenAI-fuehrt-Framework-zur-Meldung-von-KI-Sicher…
∗∗∗ The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents ∗∗∗
---------------------------------------------
During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper. This report details the new crimeware campaign that began with the mass infection of users via compromised torrent tracker file storage. [..] Further analysis of the attack revealed that the threat actors did not compromise the torrent trackers themselves. Instead, they compromised a widely used public repository of torrent files — itorrents[.]org.
---------------------------------------------
https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/
∗∗∗ Revolut phishing texts appear days after data breach ∗∗∗
---------------------------------------------
Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.
---------------------------------------------
https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-tex…
∗∗∗ Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilins AI use ∗∗∗
---------------------------------------------
In Japan, The Gentlemen was the most active ransomware group in the first half of 2026. Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year.
---------------------------------------------
https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-fir…
∗∗∗ GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk ∗∗∗
---------------------------------------------
GitHub has added cache-mode to GitHub Actions, a new setting that limits how workflows and jobs can access the Actions cache. It targets cache poisoning, the technique attackers used to compromise the Ultralytics PyPI package in 2024 and the TanStack npm packages in May 2026.
---------------------------------------------
https://socket.dev/blog/github-actions-cache-mode
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone ∗∗∗
---------------------------------------------
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. CVE-2026-81642
---------------------------------------------
https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.ht…
∗∗∗ BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS ∗∗∗
---------------------------------------------
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature.
---------------------------------------------
https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.ht…
∗∗∗ Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2026-013
∗∗∗ Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2022-005
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094962/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 15-09-2026 18:00 − Mittwoch 16-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Account-Takeover: Tanz-Voting-Masche hat wieder WhatsApp-Konten im Visier ∗∗∗
---------------------------------------------
Eine aus dem Vorjahr bekannte Falle wird aktuell verstärkt ausgespielt. Kriminelle versenden über gehackte WhatsApp-Accounts Nachrichten, die zur Teilnahme an einem Voting drängen. Ziel ist die Übernahme weiterer Konten, die später für den Versand verschiedenster Phishing-Messages missbraucht werden. Was ein Zahnarztbesuch mit der ganzen Sache zu tun hat, verrät der Artikel.
---------------------------------------------
https://www.watchlist-internet.at/news/account-takeover-whatsapp-konten/
∗∗∗ Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites ∗∗∗
---------------------------------------------
Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites. After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-p…
∗∗∗ Windows Server 2022 reaches end of mainstream support next month ∗∗∗
---------------------------------------------
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches…
∗∗∗ Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works ∗∗∗
---------------------------------------------
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.
---------------------------------------------
https://www.wired.com/story/hackers-flock-camera-data-shows-how-system-work…
∗∗∗ Atomic macOS (AMOS) Stealer Activity ∗∗∗
---------------------------------------------
This article reviewed an Atomic stealer malware infection from early August 2026. The resulting analysis includes behavior from the infected macOS host, malware samples, post-infection artifacts and traffic patterns that indicate the types of information collected by this malware.
---------------------------------------------
https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/
∗∗∗ Securing the unpatchable in an age of AI-driven vulnerabilities ∗∗∗
---------------------------------------------
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.
---------------------------------------------
https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai…
∗∗∗ Angreifer attackieren Acronis Backup für cPanel/WHM und Plesk ∗∗∗
---------------------------------------------
Aufgrund von laufenden Attacken müssen Admins Acronis Backup für cPanel/WHM und Plesk aktualisieren.
---------------------------------------------
https://heise.de/-11454681
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco Security Advisories 2026 Sep 16 ∗∗∗
---------------------------------------------
Cisco has release 13 new CRITICAL security advisories for Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard.
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/publicationListing.x
∗∗∗ Oracle Critical Security Patch Update Advisory - September 2026 ∗∗∗
---------------------------------------------
This Critical Security Patch Update contains 673 new security patches across the product families listed below.
---------------------------------------------
https://www.oracle.com/security-alerts/cspusep2026.html
∗∗∗ Google Pixel owners urged to patch actively exploited modem flaw ∗∗∗
---------------------------------------------
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
---------------------------------------------
https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094720/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 14-09-2026 18:00 − Dienstag 15-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Eine Phishing-Mail, vier Fallen, drei Sprachen – Wenn Kriminelle schlampig arbeiten ∗∗∗
---------------------------------------------
Betrugsmaschen im Namen von FinanzOnline gehören zu den absoluten Dauerbrennern und werden laufend gemeldet. Weil den Kriminellen bei der Erstellung einer aktuellen Masche aber einige Fehler unterlaufen sind, bleiben die dazugehörigen Erfolgsaussichten relativ gering. Analyse eines betrügerischen Hoppalas.
---------------------------------------------
https://www.watchlist-internet.at/news/wenn-kriminelle-schlampig-arbeiten/
∗∗∗ Twitch extension with 30K installs exposes users’ OAuth tokens ∗∗∗
---------------------------------------------
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users Twitch OAuth session tokens to a commercial bot service.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-in…
∗∗∗ Confidential Computing gebrochen: DDRop-Angriff ermöglicht Datenklau in der Cloud ∗∗∗
---------------------------------------------
Damit DDRop erfolgreich ausgeführt werden kann, ist ein physischer Zugriff auf die Serverhardware erforderlich, um das von den Forschern entwickelte Interposer-Gerät zu installieren. [..] Hinter DDRop steckt ein Team aus neun Sicherheitsforschern von Google, der ETH Zürich, der KU Leuven sowie der Durham University. Sie entwickelten ein Gerät, das für den Angriff erforderlich ist. [..] Wie die Forscher auf einer Informationsseite zu DDRop schildern, kann das Gerät Schreibvorgänge im Arbeitsspeicher "verschwinden lassen", indem es absichtlich einen Paritätsfehler einschleust. Dadurch soll das Speichermodul die Schreibbefehle verwerfen, wovon der Prozessor aber wohl nichts mitbekommt.
---------------------------------------------
https://www.golem.de/news/confidential-computing-gebrochen-ddrop-angriff-er…
∗∗∗ The Ghost in the Chat: how a bot that isn't in your group steals messages from Telegram HTML exports ∗∗∗
---------------------------------------------
A stored XSS in Telegram Desktop's HTML export pipeline lets a bot that never joins your group plant invisible JavaScript in an inline keyboard button. The payload sleeps in message history for months and detonates the moment a participant exports the chat and opens the HTML file — every message rendered in that document can be shipped to the attacker's server, and the page itself can be rewritten. [..] Telegram shipped a fix in July, but the app update does not update files exported with earlier versions, so old HTML exports can still carry the script.
---------------------------------------------
https://expatch.com/writeups/telegram-html-export-xss.html
∗∗∗ HBO Max Reddit account compromised to serve ClickFix attacks ∗∗∗
---------------------------------------------
Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max.
---------------------------------------------
https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-c…
∗∗∗ Angriff auf Verschlüsselung: Netzrechtler fordern EU-Eingreifen gegen Kanada ∗∗∗
---------------------------------------------
Ein internationales Bündnis aus Zivilgesellschaft und Datenschutzorganisationen wendet sich in einem offenen Brief an die EU-Spitze. Anlass ist Kanadas umstrittener Gesetzentwurf C-22 (Lawful Access Act), der vor dem Beschluss im Senat steht. Was wie eine nationale Angelegenheit wirkt, entpuppt sich laut dem Schreiben als extraterritorialer Zugriff auf die digitale Sicherheit auch in Europa. [..] Besonders alarmierend ist laut der Allianz die Gefährdung der Ende-zu-Ende-Verschlüsselung – ähnlich wie bei der in der EU diskutierten Chatkontrolle.
---------------------------------------------
https://heise.de/-11452910
∗∗∗ LG äußert sich zu Vorwürfen bezüglich Smart-TV-Tracking ∗∗∗
---------------------------------------------
LG hat auf die Untersuchung von Gamers Nexus zu Smart-TVs reagiert. Der Hersteller erläutert die ACR-Funktion, bleibt bei vielen Vorwürfen jedoch vage.
---------------------------------------------
https://heise.de/-11452996
∗∗∗ 1.1.1.1 prüft DNS jetzt mit Post-Quanten-Kryptografie ∗∗∗
---------------------------------------------
Cloudflare hat ML-DSA-44-Validierung für seinen DNS-Resolver 1.1.1.1 aktiviert. [..] Mit der Resolver-Validierung ist noch keine vollständige Post-Quanten-DNSSEC-Kette verfügbar. Dafür müssten autoritative Nameserver Zonen mit ML-DSA-44 signieren, Registrare die passenden DS-Records annehmen und Registries sie in den übergeordneten Zonen veröffentlichen. Schließlich müsste auch die Root-Zone den Algorithmus unterstützen und ihr Post-Quanten-Schlüssel als Vertrauensanker in Resolvern hinterlegt sein.
---------------------------------------------
https://heise.de/-11453315
∗∗∗ Revolut-Datenleck: Hacker nutzen echte Behörden-Domain für Diebstahl ∗∗∗
---------------------------------------------
Ein raffinierter Betrug trifft die Neobank Revolut: Über eine verifizierte Regierungs-Domain erbeuteten Hacker sensible Kundendaten und erpressen nun Opfer.
---------------------------------------------
https://heise.de/-11453866
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar ∗∗∗
---------------------------------------------
In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461
---------------------------------------------
https://www.cert.at/de/warnungen/2026/9/kritische-sicherheitslucke-in-cisco…
∗∗∗ Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Apple Updates Everything, (Mon, Sep 14th) ∗∗∗
---------------------------------------------
https://isc.sans.edu/diary/rss/33336
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094469/
∗∗∗ Mozilla Foundation Security Advisories September 15, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 11-09-2026 18:00 − Montag 14-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent ∗∗∗
---------------------------------------------
On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118. [..] The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-po…
∗∗∗ Security through obscurity is dead, and AI delivered the fatal blow ∗∗∗
---------------------------------------------
The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. [..] During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS).
---------------------------------------------
https://www.theregister.com/security/2026/09/13/security-through-obscurity-…
∗∗∗ Perfect-10 GitLab bug under attack days after patch lands ∗∗∗
---------------------------------------------
CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10.
---------------------------------------------
https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under…
∗∗∗ Wie ein Wiener eine KI-Spionagesoftware von Anthropic stoppte ∗∗∗
---------------------------------------------
Künstliche Intelligenz lud Schadsoftware auf eine Plattform mit Millionen Nutzern. Ein Cybersicherheitsforscher aus Österreich verhinderte, dass sie sich weiter verbreiten konnte.
---------------------------------------------
https://www.derstandard.at/story/3000000339589/wie-ein-wiener-eine-ki-spion…
∗∗∗ Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection ∗∗∗
---------------------------------------------
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
---------------------------------------------
https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-iden…
∗∗∗ Webseite BGP.Exchange kompromittiert (12. Sept. 2026) ∗∗∗
---------------------------------------------
Der Anbieter der Seite BGP.Exchange ist gehackt worden, die Webseite ist kompromittiert. Zum 12. September 2026 zeigt die Webseite ein "Defacement" und es wird wohl auch "Schund" über deren Mail-System verschickt.
---------------------------------------------
https://borncity.com/blog/2026/09/12/webseite-bgp-exchange-kompromittiert-1…
∗∗∗ Datenleck: Revolut gibt sensible Nutzerdaten an Angreifer ∗∗∗
---------------------------------------------
ie Bank ist auf eine gefälschte Datenanforderung einer angeblichen Behörde hereingefallen und hat sensible Kundendaten (Ausweiskopien etc.) an Betrüger herausgegeben. [..] Die potenziell offengelegten Daten umfassen Kopien von Pässen und Führerscheinen, Selfies zur Identitätsprüfung sowie persönliche Informationen (Namen, Geburtsdaten, Berufe, Postadressen, E-Mail-Adressen und Telefonnummern). Auch finanzielle Daten (IBAN, Kontoauszüge und vollständige Transaktionshistorien, einschließlich Bitcoin-Operationen) sind angeblich betroffen.
---------------------------------------------
https://borncity.com/blog/2026/09/13/datenleck-revolut-gibt-sensible-nutzer…
∗∗∗ The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37] ∗∗∗
---------------------------------------------
Until May 2025, I liked PGP, and the GNU Privacy Guard. I poked at it in my free time a lot. One day, that suddenly changed, when I flew too close to the sun and ended up uncovering a vulnerability that allows you to easily spoof a PGP signature when opened naively with the GPG tool. [..] I disclosed these a few weeks before 39c3 in December 2025. And while some of the vulnerabilities - like the memory corruption in the message parser - got addressed properly, this was not the case for all of them.
---------------------------------------------
https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-discl…
=====================
= Vulnerabilities =
=====================
∗∗∗ LWN: Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094211/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 10-09-2026 18:00 − Freitag 11-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Gilt ab heute: CRA setzt 24-Stunden-Frist für Sicherheitsmeldungen ∗∗∗
---------------------------------------------
Der Cyber Resilience Act verpflichtet Hersteller von Produkten mit digitalen Elementen zu Mindeststandards für die Cybersicherheit. Betroffen sind nicht nur vernetzte Geräte wie Router oder industrielle Steuerungen, sondern auch Software. Die meisten Anforderungen gelten für Produkte, die ab dem 11. Dezember 2027 neu auf den EU-Markt kommen. Ab heute, also dem 11. September 2026, müssen Hersteller jedoch bereits aktiv ausgenutzte Schwachstellen und schwerwiegende Sicherheitsvorfälle melden.
---------------------------------------------
https://heise.de/-11450208
∗∗∗ Enisa: Anthropic öffnet Mythos-Modell für EU-Cyberagentur ∗∗∗
---------------------------------------------
Nach monatelangen Verhandlungen gibt Anthropic der EU-Agentur Enisa Zugang zu seinem KI-Modell Mythos. Doch die neueste Version gibt es nicht.
---------------------------------------------
https://www.golem.de/news/enisa-anthropic-oeffnet-mythos-modell-fuer-eu-cyb…
∗∗∗ Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 ∗∗∗
---------------------------------------------
Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control.
---------------------------------------------
https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-o…
∗∗∗ PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws ∗∗∗
---------------------------------------------
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
---------------------------------------------
https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
∗∗∗ ClickFix attacks infecting PCs and Macs are going viral ∗∗∗
---------------------------------------------
It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command.
---------------------------------------------
https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and…
∗∗∗ Multiple crypto companies warn customers of phishing emails after alleged provider breach ∗∗∗
---------------------------------------------
Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use.
---------------------------------------------
https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
∗∗∗ Portasplit-Sicherheitslücke: Midea verteilt Updates an Klimageräte ∗∗∗
---------------------------------------------
Midea aktualisiert in den nächsten Wochen automatisch alle PortaSplit-Klimageräte. Der Hersteller reagiert damit auf einen Hinweis von heise security und einem anonymen Whistleblower. Der hatte eine Android-App entwickelt, um ein Sicherheitsproblem zu demonstrieren. Mit ihr ließen sich beliebige Geräte per Bluetooth Low Energy (BLE) fernsteuern – auch gegen den Willen ihrer Besitzer.
---------------------------------------------
https://heise.de/-11449892
∗∗∗ Certificate Authority unter Windows mit PowerShell betreiben ∗∗∗
---------------------------------------------
Mit diesem Blog-Post hier demonstriere ich, wie unter Verwendung von Windows 11 Bordmitteln (Powershell, es wird kein OpenSSL benötigt) eine CA erstellt und daraus Code-Signing-Zertifikate, Webserver-Zertifikate ...
---------------------------------------------
https://hitco.at/blog/certificate-authority-windows-powershell-ca-smime-cod…
∗∗∗ Beliebige Dateien (z.B. 7z, zip, yaml, …) mittels Catalog-Files und PowerShell signieren ∗∗∗
---------------------------------------------
Die Nutzung eines Code-Signing-Zertifikats zur Authenticode-Signatur ist für zahlreiche Datei-Typen die dies unterstützen direkt inline möglich. Als Beispiele seien *.exe, *.dll, *.ps1, … genannt. Dieses kurze How-To beschäftigt sich allerdings mit Datei-Typen, die keine Signatur unterstützen. Beispielsweise ein YAML-Konfigurationsfile im Textformat, oder ZIP-Container sowie 7zip-Containerfiles.
---------------------------------------------
https://hitco.at/blog/beliebige-dateien-7z-zip-yaml-mittels-catalogfiles-po…
∗∗∗ A rant about phishing: Its not the users fault (and not DNS either) ∗∗∗
---------------------------------------------
"For safety, don't click suspicious links" Neither the username, password nor 2FA prompts are hosted on the company's own domain. Combine that with token expiration triggering random authetication pop-ups, it becomes nearly impossible to notice phishing... because the real thing looks identical to a scam [..] An organization MUST use a single, well recognized, root domain.
---------------------------------------------
https://maurycyz.com/misc/domains/
=====================
= Vulnerabilities =
=====================
∗∗∗ ARISTA Security Advisory 0158 ∗∗∗
---------------------------------------------
Both CVE-2026-73456 and CVE-2026-73457 affect Arista EOS-based platforms with gRPC Network Packet Sampling Interface (gNPSI) configured. which is disabled by default. [..] Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
---------------------------------------------
https://www.arista.com/en/support/advisories-notices/security-advisory/2471…
∗∗∗ GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 ∗∗∗
---------------------------------------------
On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE) and Enterprise Edition (EE). [..] For security fixes, the issues detailing each vulnerability are made public on our issue tracker 90 days after the release in which they were patched.
---------------------------------------------
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-releas…
∗∗∗ Forgejo 16.0.4 has a critical security bug fix (RCE - Remote Code Execution) ∗∗∗
---------------------------------------------
https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-publi…
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1093765/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 09-09-2026 18:00 − Donnerstag 10-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ ID-Austria Phishing als Türöffner für falschen Bankanruf ∗∗∗
---------------------------------------------
„Jemand aus dem Ausland möchte Geld von Ihrem Konto abbuchen!“ Mit dieser Behauptung schrecken Kriminelle derzeit auf. Sie geben sich am Telefon als Bankmitarbeiter:innen aus und überreden ihre Opfer, Geld auf ein vermeintlich sicheres Konto zu überweisen.
---------------------------------------------
https://www.watchlist-internet.at/news/id-austria-phishing-bankanruf/
∗∗∗ OpenAI-Agenten haben auf mehr als 10 weiteren Websites unerlaubt kommuniziert ∗∗∗
---------------------------------------------
KI-Agenten, die von OpenAI lediglich mit Internetrecherchen beauftragt und denen das Veröffentlichen eigener Beiträge untersagt war, haben weit mehr als nur eine Website zur Diskussion genutzt. Verschiedene unabhängige Sicherheitsforscher haben die ausgebrochenen OpenAI-Agenten auf mehr als zehn weiteren Webseiten gefunden. Dort haben diese größtenteils Wiki-Bereiche zum unerlaubten Austausch von Nachrichten verwendet.
---------------------------------------------
https://www.heise.de/news/OpenAI-Agenten-haben-auf-mehr-als-10-weiteren-Web…
∗∗∗ Vierter Hacking-Vorfall: Weiteres Anthropic-Modell bricht aus Testumgebung aus ∗∗∗
---------------------------------------------
In einem aktuellen Blog-Beitrag meldet Anthropic einen weiteren Hacking-Vorfall, der sich im Januar mit einer Vorabversion von Claude Opus 4.6 ereignet haben soll. Es ist der vierte Vorfall dieser Art.
---------------------------------------------
https://www.heise.de/news/Vierter-Hacking-Vorfall-Weiteres-Anthropic-Modell…
∗∗∗ Scans for Proxmox Servers, (Wed, Sep 9th) ∗∗∗
---------------------------------------------
About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
---------------------------------------------
https://isc.sans.edu/diary/rss/33324
∗∗∗ Active exploitation of Cisco Secure Firewall Management Center vulnerabilities ∗∗∗
---------------------------------------------
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account. [..] IOCs for these threat clusters are also available on our GitHub repository here.
---------------------------------------------
https://blog.talosintelligence.com/fmc-ongoing-exploitation/
∗∗∗ Sicherheitslücken: 36.000 Plex-Media-Server-Instanzen potenziell angreifbar ∗∗∗
---------------------------------------------
In aktuellen Versionen von Plex Media Server und Plex Desktop wurden mehrere Schwachstellen geschlossen. Weltweit sind zehntausende Instanzen angreifbar.
---------------------------------------------
https://heise.de/-11448584
∗∗∗ Safe word: What is it and why do you need one? ∗∗∗
---------------------------------------------
AI scams are now hyper-realistic. But there’s one simple way to see through them.
---------------------------------------------
https://www.welivesecurity.com/en/cybersecurity/safe-word-what-why-need-one/
∗∗∗ Passkey-themed social engineering leads to identity and cloud compromise ∗∗∗
---------------------------------------------
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-soc…
∗∗∗ Threat matrix: Mapping threats across cloud web applications ∗∗∗
---------------------------------------------
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapp…
∗∗∗ SloppyRAT: A New Tool For Ransomware Attacks ∗∗∗
---------------------------------------------
In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques. [..] In the following sections, ThreatLabz provides a technical analysis of SloppyRAT, including its infection vector, anti-analysis techniques, network protocol, and command execution functionality.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomwa…
∗∗∗ The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE ∗∗∗
---------------------------------------------
This research demonstrates post-exploitation techniques that could allow an attacker with root access on a compromised Kubernetes node to misuse an open standard and reference implementation for machine identity known as SPIFFE/SPIRE to impersonate co-located workloads and harvest SPIFFE Verifiable Identity Documents (SVIDs).
---------------------------------------------
https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofi…
∗∗∗ Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise ∗∗∗
---------------------------------------------
How default keys, unauthenticated MCP sessions, and custom code guardrails expose cloud AI infrastructure to root-level remote code execution and IAM theft.
---------------------------------------------
https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypa…
=====================
= Vulnerabilities =
=====================
∗∗∗ Palo Alto Networks Security Advisories 09.09.2026 ∗∗∗
---------------------------------------------
Palo Alto released 10 new security advisories (2x high severity).
---------------------------------------------
https://security.paloaltonetworks.com/
∗∗∗ Drupal Security Advisories 2026-September-09 ∗∗∗
---------------------------------------------
Drupal released 20 new security advisories (9x critical severity).
---------------------------------------------
https://www.drupal.org/security
∗∗∗ Checkpoint: CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN ∗∗∗
---------------------------------------------
Product: Security Gateway, Spark Firewall (Centrally Managed), Spark Firewall (Locally Managed). Issue: Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway. This issue received the ID CVE-2026-85102 with CVSS: 9.8.
---------------------------------------------
https://support.checkpoint.com/results/sk/sk1000117/
∗∗∗ Checkpoint: CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution ∗∗∗
---------------------------------------------
Product: Security Gateway, Security Management Server, Spark Firewall (Centrally Managed), Spark Firewall (Locally Managed). Issue: A heap overflow in the VPN certificate ASN.1 decoding flow may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway. This issue received the ID CVE-2026-85103 with CVSS: 9.8.
---------------------------------------------
https://support.checkpoint.com/results/sk/sk1000118/
∗∗∗ ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-657/
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1093566/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/