=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 08-09-2026 18:00 − Mittwoch 09-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Patchday-Rekord: Fast 1.000 Sicherheitslücken in Windows, Office und Co. ∗∗∗
---------------------------------------------
Microsoft hat zum September-Patchday mal wieder einen neuen Rekord aufgestellt. Erstmals hat der Konzern über all seine Produkte hinweg innerhalb eines Monats fast 1.000 Sicherheitslücken geschlossen.
---------------------------------------------
https://www.golem.de/news/patchday-rekord-fast-1-000-sicherheitsluecken-in-…
∗∗∗ New Microsoft Defender ShieldCrash zero-day grants SYSTEM access ∗∗∗
---------------------------------------------
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [..] According to Nightmare Eclipse, the ShieldCrash proof-of-concept exploit lets attackers gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems, but will not give them write access to the compromised systems. [..] Nightmare Eclipse released these zero-day exploits as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shiel…
∗∗∗ Chrome 153: Google wechselt zu Zweiwochen-Update-Zyklus ∗∗∗
---------------------------------------------
Bislang veröffentlichte Google seit 2021 im Regelfall alle vier Wochen eine neue Chrome-Hauptversion. Ab Version 153 erscheinen Stable- und Beta-Ausgaben nun alle zwei Wochen für Desktop, Android und iOS. Wöchentliche Sicherheitsupdates bleiben bestehen.
---------------------------------------------
https://heise.de/-11446371
∗∗∗ Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit ∗∗∗
---------------------------------------------
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm…
∗∗∗ DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval ∗∗∗
---------------------------------------------
A flaw in DeepSeek Harness, DeepSeeks open-source tool for running AI coding agents on a developers machine, let a sandboxed agent turn off its own sandbox with a single command.The tool runs an agents commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace.
---------------------------------------------
https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
∗∗∗ Keine Panik: Zahlungsaufforderung vom Hansevia Forderungsmanagement ist ein Fake! ∗∗∗
---------------------------------------------
Eine E-Mail mit bedrohlich klingendem Betreff. Eine Forderung über mehrere tausend Euro. Ein angeblich bestehendes Dienstleistungsverhältnis mit Euromillion24. Aus diesen Bestandteilen bauen Kriminelle aktuell ein Phishing-Kartenhaus, das bei genauerem Hinsehen sehr rasch in sich zusammenfällt.
---------------------------------------------
https://www.watchlist-internet.at/news/zahlungsaufforderung-hansevia-forder…
∗∗∗ Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure ∗∗∗
---------------------------------------------
A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. Tracked as CL-CRI-1171, in accordance with Unit 42’s attribution framework, the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads.
---------------------------------------------
https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
∗∗∗ Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF ∗∗∗
---------------------------------------------
11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.
---------------------------------------------
https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-…
∗∗∗ Reverse engineering my e-scooter and rewriting the firmware in rust ∗∗∗
---------------------------------------------
I reverse engineered the hardware and firmware of my Egret GT E-Scooter. I describe how I got in, analysed communication between components, and reverse engineered firmware. I speak about writing custom firmware for the display unit.
---------------------------------------------
https://bensimms.moe/reverse-engineering-scooter/
=====================
= Vulnerabilities =
=====================
∗∗∗ Microsoft Exchange Server: Sicherheitsupdates 8. September 2026 ∗∗∗
---------------------------------------------
Microsoft hat zum 8. September 2026 Sicherheitsupdates (SU) für "September 2026" veröffentlicht. Diese Updates stehen für Exchange Server 2016 / 2019 (ESU) sowie für Exchange Server Subscription Edition (SE) zur Verfügung.
---------------------------------------------
https://borncity.com/blog/2026/09/09/exchange-server-sicherheitsupdates-8-s…
∗∗∗ Microsoft Patchday: Windows Server-Updates (8. September 2026) ∗∗∗
---------------------------------------------
Zum 8. September 2026 (zweiter Dienstag im Monat, Patchday bei Microsoft) wurden verschiedene kumulative Updates für die unterstützten Versionen von Windows Server freigegeben. Nachfolgend habe ich die bereitgestellten Updates samt einigen Details für diese Windows Server-Versionen herausgezogen.
---------------------------------------------
https://borncity.com/blog/2026/09/09/patchday-windows-server-updates-8-sept…
∗∗∗ Microsoft Patchday: Windows 10/11 Updates (8. September 2026) ∗∗∗
---------------------------------------------
Am 8. September 2026 (zweiter Dienstag im Monat, Patchday bei Microsoft) hat Microsoft kumulative Updates für die noch unterstützten Client-Betriebssystem-Versionen von Windows 10 (mit ESU-Lizenz) und Windows 11 veröffentlicht. Hier einige Details zu diesen Updates, die Schwachstellen sowie Probleme beheben.
---------------------------------------------
https://borncity.com/blog/2026/09/09/patchday-windows-10-11-updates-8-septe…
∗∗∗ Adobe September-Patchday: Adobe schließt kritische Zero-Day-Lücke und 172 weitere ∗∗∗
---------------------------------------------
Im Zentrum der Adobe-Patch-Welle steht das Update für Adobe Commerce, das bereits akut angegriffen wird. Besonders viele Updates betreffen Experience Manager.
---------------------------------------------
https://heise.de/-11446552
∗∗∗ Android: Patchday: Kritische Lücken ermöglichen Attacken auf Android 14, 15, 16 und 17 ∗∗∗
---------------------------------------------
Der September-Patchday für Android schließt über 90 Sicherheitslücken, darunter mehr als 25 kritische Schwachstellen in Framework, System und Kernel.
---------------------------------------------
https://heise.de/-11446782
∗∗∗ Samsung Sicherheits-Updates: Samsung verteilt Patches für Galaxy-Smartphones ∗∗∗
---------------------------------------------
Samsung hat sein Security-Bulletin für September 2026 veröffentlicht. Der Hersteller verteilt 90 Sicherheitspatches für zahlreiche Galaxy-Geräte.
---------------------------------------------
https://heise.de/-11447042
∗∗∗ cPanel: Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026 ∗∗∗
---------------------------------------------
https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-20…
∗∗∗ Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1093342/
∗∗∗ Fortinet: Improper Authentication of FortiPAM Server ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-168
∗∗∗ Fortinet: JWT used for authentication in web GUI signed with static key ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-170
∗∗∗ Fortinet: Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-166
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 07-09-2026 18:00 − Dienstag 08-09-2026 18:00
Handler: Alexander Riepl
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Schwerwiegende Sicherheitslücke in N-able N-central - aktiv ausgenutzt ∗∗∗
---------------------------------------------
In N-able N-central, einer Remote-Monitoring- und Management-Plattform, die insbesondere von Managed Service Providern (MSPs) zur Verwaltung von Kund:innenumgebungen eingesetzt wird, wurde eine schwerwiegende Sicherheitslücke entdeckt. Die Schwachstelle, CVE-2026-86218, ist mit einem CVSS-Score von 10.0 bewertet, eine Ausnutzung ermöglicht entfernten, unauthentifizierten Angreifer:innen eine Ausführung von Code auf verwundbaren Systemen.
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/9/schwerwiegende-sicherheitslucke-in-…
∗∗∗ Hackers build AI frameworks for widescale credential theft ∗∗∗
---------------------------------------------
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-…
∗∗∗ Auch im Standby: LG-Fernseher wohl anfällig für weitreichende Spionageangriffe ∗∗∗
---------------------------------------------
Dass Smart TVs über Automatic Content Recognition (ACR) etwa zu Werbezwecken permanent die Sehgewohnheiten ihrer Nutzer tracken, ist schon seit Jahren bekannt. [..] Demnach scannen LG-Fernseher neben dem ACR-Tracking ständig im internen Netzwerk nach Smartphones, PCs, Druckern und anderen erreichbaren Endgeräten. Zudem sollen die TV-Geräte permanent Informationen über in Reichweite befindliche WLAN-Netze und deren Standorte und Signalstärken sammeln.
---------------------------------------------
https://www.golem.de/news/auch-im-standby-lg-fernseher-wohl-anfaellig-fuer-…
∗∗∗ Abo-Falle: Wenn NordicaLab automatisch über PayPal abbucht ∗∗∗
---------------------------------------------
„Danke, dass Sie mit PayPal gezahlt haben“ – Flattert diese Mitteilung zu einem Zeitpunkt ins Mail-Postfach, an dem garantiert keine Zahlung freigegeben wurde, ist sprichwörtlich Feuer am Dach. Irgendetwas stimmt hier ganz und gar nicht. Was genau, das zeigt ein konkreter Fall aus der Praxis.
---------------------------------------------
https://www.watchlist-internet.at/news/abo-falle-nordicalab/
∗∗∗ Führerschein-Scans von Altersüberprüfungs-Dienst landeten über ein Jahr kontinuierlich im Darknet ∗∗∗
---------------------------------------------
Wie das Fachmedium Techdirt berichtet, ging vergangene Woche eine Plattform für Identitätsdiebstahl namens Nexus online. Auf der Seite werden mehr als 153 Millionen Scans von Bürgerinnen und Bürgern der USA und Kanada verkauft. Die Betreiber von Nexus behaupten, die Ausweisbilder stammten aus einem aktiven Datenleck bei "einem großen Unternehmen für Identitätsprüfung", zu dessen Kunden mehrere Fortune-500-Unternehmen zählen.
---------------------------------------------
https://www.derstandard.at/story/3000000338691/fuehrerschein-scans-von-alte…
∗∗∗ ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager ∗∗∗
---------------------------------------------
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
---------------------------------------------
https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
∗∗∗ The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT ∗∗∗
---------------------------------------------
Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker.
---------------------------------------------
https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbo…
∗∗∗ I’ve factored the RSA keys of a Certificate Authority…from the 90s ∗∗∗
---------------------------------------------
I’ve been thinking about the security of RSA lately. RSA’s cryptography relies on the difficulty of factoring a large semiprime number, but what “large” means is an interesting question. The Web PKI deprecated 1024-bit RSA over a decade ago, and while I don’t know of anyone factoring a key of that size, it’s within the realm of possibility for a government or other organization with a large number of computers. Just a few days ago, someone factored the 862-bit RSA-260 key from the RSA factoring challenge.
---------------------------------------------
https://mcpherrin.ca/2026/09/07/rsa.html
=====================
= Vulnerabilities =
=====================
∗∗∗ FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials ∗∗∗
---------------------------------------------
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. [..] That only becomes dangerous because of the second flaw. 389 Directory Server has a rule type meant to say "only the authenticated owner of this entry." It compares the client's name against a stored value as plain text, and a client that has not logged in has an empty name, which matches an empty stored value.
---------------------------------------------
https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
∗∗∗ Ivanti September 2026 Security Update ∗∗∗
---------------------------------------------
Ivanti releases standard security patches on the second Tuesday of every month. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories: Ivanti Neurons for ITSM, Ivanti Endpoint Manager Mobile (EPMM), Ivanti Sentry
---------------------------------------------
https://www.ivanti.com/blog/september-2026-security-update
∗∗∗ SAP Security Patch Day September 2026 | RedRays ∗∗∗
---------------------------------------------
SAP Security Patch Day September 2026 brings 20 security notes, four of them HotNews rated up to CVSS 10.0, alongside five High priority issues, ten Medium priority fixes and one Low priority update. They span the NetWeaver stack, SAP S/4HANA, SAPUI5 and several cloud products. This release lands on the network-facing core of NetWeaver.
---------------------------------------------
https://redrays.io/blog/sap-security-patch-day-september-2026/
∗∗∗ VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/943094
∗∗∗ VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/718077
∗∗∗ TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-core-sa-2026-023
∗∗∗ TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-core-sa-2026-022
∗∗∗ Xen: XSA-513 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-513.html
∗∗∗ Xen: XSA-512 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-512.html
∗∗∗ Xen: XSA-511 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-511.html
∗∗∗ Xen: XSA-510 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-510.html
∗∗∗ Xen: XSA-509 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-509.html
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1093144/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 04-09-2026 18:00 − Montag 07-09-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Attackers conceal phishing lures using invisible Unicode characters ∗∗∗
---------------------------------------------
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-l…
∗∗∗ BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations ∗∗∗
---------------------------------------------
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishi…
∗∗∗ Shadowserver 2025: Highlights of the Year in Review ∗∗∗
---------------------------------------------
A review of Shadowserver’s 21st year as the world’s largest provider of free, timely, actionable, daily cyber threat intelligence. Covering the latest improvements in our public benefit services, responses to emerging cyber threats, and detection and reporting of the latest vulnerabilities to National CSIRTs and system defenders ..
---------------------------------------------
https://www.shadowserver.org/news/shadowserver-2025-highlights-of-the-year-…
∗∗∗ N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw ∗∗∗
---------------------------------------------
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-ables incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a ..
---------------------------------------------
https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
∗∗∗ Peers ask why UK cyber bill leaves execs off the personal liability hook ∗∗∗
---------------------------------------------
Ministers say £17M corporate fines and forthcoming board-level governance rules provide sufficient accountability
---------------------------------------------
https://www.theregister.com/security/2026/09/07/peers-ask-why-uk-cyber-bill…
∗∗∗ Hackers drain $320M in Bitcoin from Liquid Network, claim theyre the good guys ∗∗∗
---------------------------------------------
Self-described white hats promise to return most of the 4,000 BTC once the vulnerability is fixed
---------------------------------------------
https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitco…
∗∗∗ Microsoft bremst alte Exchange-Server aus ∗∗∗
---------------------------------------------
Microsoft verschärft die Regeln für alte Exchange-Server: In Hybridumgebungen drohen Drosselung und blockierte E-Mails.
---------------------------------------------
https://www.heise.de/news/Alte-Exchange-Server-riskieren-Mailblockaden-1144…
∗∗∗ Zero-Day-Lücke StyleSmuggler in Magento und Adobe Commerce wird aktiv ausgenutzt ∗∗∗
---------------------------------------------
Onlineshops auf Basis von Magento und Adobe Commerce sind offenbar aufgrund einer ungepatchten Sicherheitslücke namens StyleSmuggler angreifbar.
---------------------------------------------
https://www.heise.de/news/Zero-Day-Luecke-StyleSmuggler-in-Magento-und-Adob…
∗∗∗ Gefahr für die nationale Sicherheit: Berliner Datenleck schlägt hohe Wellen ∗∗∗
---------------------------------------------
Nach dem Darknet-Leak streiten Bezirke über Forensik-Software von Crowdstrike. Die Datenschutzbeauftragte warnt und gibt Verhaltensregeln für Betroffene heraus.
---------------------------------------------
https://www.heise.de/news/Gefahr-fuer-die-nationale-Sicherheit-Berliner-Dat…
∗∗∗ Steuerausgleich da? Vorsicht vor gefälschten Finanzamt-Mails ∗∗∗
---------------------------------------------
„Ihr Steuerausgleich ist da!" Eine solche Nachricht klingt zunächst vielversprechend. Wer derzeit eine solche E-Mail erhält, sollte allerdings genau hinsehen. Denn dahinter könnten Kriminelle stecken, die an sensible Daten gelangen wollen.
---------------------------------------------
https://www.watchlist-internet.at/news/steuerausgleich-gefaelschten-mails/
∗∗∗ OpenAI verheimlichte Angriff von tausenden KI-Agenten auf in Österreich betriebenes Wiki ∗∗∗
---------------------------------------------
Das DseWiki war bereits im Mai 2026 übernommen worden. Nun verspricht OpenAI neue Regeln für Umgang mit solchen Vorfällen
---------------------------------------------
https://www.derstandard.at/story/3000000338604/openai-verheimlichte-angriff…
∗∗∗ How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts ∗∗∗
---------------------------------------------
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed.
---------------------------------------------
https://www.bitdefender.com/en-us/blog/hotforsecurity/lenovo-login-system-h…
∗∗∗ Angriffe gegen Mikrotik-Router ("MikroTrick") ∗∗∗
---------------------------------------------
Laut einer Warnung von CERT Polska nutzen Angreifer:innen aktuell großflächig Sicherheitslücken in Geräten des Herstellers Mikrotik aus um die Kontrolle über verwundbare Geräte zu erlangen. Betroffen sind Versionen vor 7.25beta3, 7.24.2, 7.23.4, 6.49.21. Laut der Shadowserver Foundation sind weltweit über 100.000 Mikrotik-Systeme direkt aus dem Internet erreichbar. Systemadministrator:innen sind dringend dazu angehalten die zur Verfügung ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/9/angriffe-gegen-mikrotik-router-mikr…
∗∗∗ The hidden risks of shadow AI ∗∗∗
---------------------------------------------
Understanding why staff use unapproved AI tools is key to managing the security challenges they can create.
---------------------------------------------
https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai
∗∗∗ No Hacking Required: The Manchester Airports Group Data Breach ∗∗∗
---------------------------------------------
On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and passport control, along with airport WiFi sign-ups across Manchester, Stansted and East Midlands. Roughly 8.8 million
---------------------------------------------
https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data…
∗∗∗ Have the frontier labs mixed up AI safety and security? ∗∗∗
---------------------------------------------
The highly publicised sandbox agent escapes have certainly made news, and I wrote about the issues with sandboxing agents back in January - though I certainly didn't foresee they would escape the frontier labs. I assumed the real risk was poorly configured sandboxes for end users, so I was surprised to see this happening at the frontier labs. I think it might tell us something about the security philosophy of these organisations.
---------------------------------------------
https://martinalderson.com/posts/ai-safety-vs-security/
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates 1.6.19 and 1.7.4 released ∗∗∗
---------------------------------------------
We just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail.They both contain fixes for recently reported security vulnerabilities.Security fixes Fix CSS declaration smuggling via un-encoded ampersand emission, reported by Zach Hanley of Horizon3.ai Fix CSS property injection via body background attribute, reported by zenithhostingevan ..
---------------------------------------------
https://roundcube.net/news/2026/09/06/security-updates-1.6.19-and-1.7.4
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 03-09-2026 18:00 − Freitag 04-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Critical Citrix NetScaler auth bypass now leveraged in attacks ∗∗∗
---------------------------------------------
Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. [..] While the company has yet to flag the vulnerability as actively exploited in its August 19 security advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Thursday that attackers have begun targeting CVE-2026-19490 in the wild after a "credible" proof-of-concept exploit was published online.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-target-critical-citr…
∗∗∗ ASCII smuggling crosses over from AI prompt injection to phishing evasion ∗∗∗
---------------------------------------------
Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-cr…
∗∗∗ Jetzt patchen! Angreifer führen Schadcode in der Sandbox von Chrome aus ∗∗∗
---------------------------------------------
Google hat mehrere Sicherheitslücken im Webbrowser Chrome geschlossen. [..] Die derzeit ausgenutzte Schwachstelle (CVE-2026-85046 „hoch“) ist eine Type-Confusion-Lücke in der JavaScript-Engine V8, führen die Entwickler in einer Warnmeldung aus. Bei dieser Art von Schwachstellen kommt es bei der Verarbeitung von inkompatiblen Objekten zu Speicherfehlern, über die Schadcode auf Systeme gelangt. In diesem konkreten Fall müssen entfernte Angreifer Opfer auf eine von ihnen präparierte Website locken.
---------------------------------------------
https://www.heise.de/news/Jetzt-patchen-Angreifer-fuehren-Schadcode-in-der-…
∗∗∗ Free streaming boxes may be routing criminal traffic through your home ∗∗∗
---------------------------------------------
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/09/free-streaming-boxes-may-be-…
∗∗∗ Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin ∗∗∗
---------------------------------------------
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026 [..]
---------------------------------------------
https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critic…
∗∗∗ Reproducing CVE-2026-75604: Next.js Path Traversal to RCE on Windows ∗∗∗
---------------------------------------------
Vulnerability research: CVE-2026-75604 A single un-escaped backslash in the Next.js incremental cache lets an unauthenticated attacker read and write files on Windows hosts, and, on the right versions and app shape, run commands. Here is the whole chain, reproduced end to end.
---------------------------------------------
https://fortbridge.co.uk/research/next-js-path-traversal-to-rce/
=====================
= Vulnerabilities =
=====================
∗∗∗ VU#889462: Casdoor authentication server is vulnerable to authorization bypass ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/889462
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1092659/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 02-09-2026 18:00 − Donnerstag 03-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Critical Elementor Pro flaw exploited to take over WordPress sites ∗∗∗
---------------------------------------------
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-…
∗∗∗ Impersonating IT support: how threat actors turn a remote session into enterprise-wide access ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-s…
∗∗∗ Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon ∗∗∗
---------------------------------------------
"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," [..] The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with Crowdstrike Falcon.
---------------------------------------------
https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
∗∗∗ This Is Flock’s AI Search Tool for Cops ∗∗∗
---------------------------------------------
WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description. [..] Police officers have already used Flock’s software to track people for reasons unrelated to police work. At least 50 officers in the US have recently been charged with or accused of misusing license plate readers, according to The Washington Post.
---------------------------------------------
https://www.wired.com/story/flock-ai-search-user-interface/
∗∗∗ WhatsApp-Sicherheitslücke: Zugriff auf Fotos bei gesperrtem Android-Handy ∗∗∗
---------------------------------------------
Die WhatsApp-App unter Android hat offenbar eine Schwachstelle. Unbefugte Nutzerinnen und Nutzer können auf einigen Geräten bei einem eingehenden Videoanruf im gesperrten Zustand auf private Fotoordner zugreifen. Meta hat nach eigenen Angaben inzwischen begonnen, einen Fix zu verteilen. Bis dieser flächendeckend ankommt, gibt es eine Übergangslösung.
---------------------------------------------
https://www.heise.de/news/WhatsApp-Sicherheitsluecke-Zugriff-auf-Fotos-bei-…
∗∗∗ WordPress All-in-One WP Migration: Angreifer können Admin-Falle auslegen ∗∗∗
---------------------------------------------
Das WordPress-Plug-in All-in-One WP Migration and Backup ist verwundbar und Angreifer können im schlimmsten Fall die volle Kontrolle über mit dem CMS erstellte Websites erlangen. [..] Die Sicherheitsforscher geben an, dass die Entwickler von All-in-One WP Migration and Backup Mitte August von der Schwachstelle erfahren haben. Der Sicherheitspatch war fünf Tage später fertig und steht seit dem 20. August 2026 zum Download bereit.
---------------------------------------------
https://www.heise.de/news/WordPress-All-in-One-WP-Migration-Angreifer-koenn…
∗∗∗ Why your data is safer than you think on public Wi-Fi ∗∗∗
---------------------------------------------
The coffee shop hacker Public Wi-Fi has acquired a slightly theatrical reputation. Join the network in a coffee shop, we are told, and a hacker in the corner can immediately steal your passwords and empty your bank account. It makes for good VPN advertising. It is not a particularly accurate picture of how the modern web works.
---------------------------------------------
https://www.pentestpartners.com/security-blog/why-your-data-is-safer-than-y…
∗∗∗ Analyse: Umfassendes Fake-Netzwerk aus Insolvenzverwaltern, IT-Anbietern, Unternehmensberatern und Zeitungen ∗∗∗
---------------------------------------------
Um den Anschein von Seriosität zu verstärken, bauen Kriminelle umfangreiche Onlinemagazine. In der dortigen Flut an angeblich realen Geschichten platzieren sie Artikel, die über vermeintlich seriöse Insolvenzverwalter, IT-Anbietern und Unternehmensberater berichten. Die gesamte Konstruktion ist auf Vorschussbetrug und das Sammeln von Daten ausgelegt.
---------------------------------------------
https://www.watchlist-internet.at/news/analyse-umfassendes-fake-netzwerk/
∗∗∗ Chamilo LMS... Its raining 0days, hallelujah, its raining 0days ∗∗∗
---------------------------------------------
Chamilo is an open source Learning Management System (LMS) widely deployed in schools and enterprises around the world. In this blogpost we explain how we were able to identify multiple vulnerabilities including a full unauthenticated Remote Code Execution chain in the latest version.
---------------------------------------------
http://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-rain…
=====================
= Vulnerabilities =
=====================
∗∗∗ VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) ∗∗∗
---------------------------------------------
VMware Workstation and Fusion contain an integer-overflow vulnerability. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. CVE-2026-59346, CVE-2026-59347
---------------------------------------------
https://support.broadcom.com/web/ecx/support-content-notification/-/externa…
∗∗∗ HPE: HPESBNW05133 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer ∗∗∗
---------------------------------------------
Remote: Access Restriction Bypass, Authentication Bypass, Escalation of Privilege
---------------------------------------------
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&doc…
∗∗∗ HPE: HPESBNW05134 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX) ∗∗∗
---------------------------------------------
Local: Access Restriction Bypass
---------------------------------------------
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&doc…
∗∗∗ Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Drupal Security Advisories 2026-September-02 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1092419/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 01-09-2026 18:00 − Mittwoch 02-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Hackers abuse Faronics Deploy admin tool to install ScreenConnect ∗∗∗
---------------------------------------------
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deplo…
∗∗∗ Bei Sandboxing-Tests: KI-Agent bricht mehrfach aus VM aus ∗∗∗
---------------------------------------------
Ein Forscher hat getestet, ob sich moderne KI-Modelle mit Virtualisierung sinnvoll isolieren lassen. Die KI ist mehrfach aus einer VM entkommen. [..] Der Forscher hatte die KI zwar explizit dazu angewiesen aus der VM auszubrechen, jedoch sind entsprechende Ausbrüche auch in anderen Situationen denkbar. [..] Zudem rät Dinaburg, für die Virtualisierung auf minimalistische Lösungen umzusteigen, die eine geringere Angriffsfläche bieten.
---------------------------------------------
https://www.golem.de/news/bei-sandboxing-tests-ki-agent-bricht-mehrfach-aus…
∗∗∗ Counterfeit installers to system compromise: Tracking a deceptive software download campaign ∗∗∗
---------------------------------------------
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-instal…
∗∗∗ Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials ∗∗∗
---------------------------------------------
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026.
---------------------------------------------
https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html
∗∗∗ OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities ∗∗∗
---------------------------------------------
The company will give select partners early access to its Astra AI model—so they have time to shore up their defenses.
---------------------------------------------
https://www.wired.com/story/openai-astra-first-ai-model-with-critical-cyber…
∗∗∗ Fremde Dropbox-Konten über Lenovo-ID zugänglich ∗∗∗
---------------------------------------------
Eine erstaunliche Sicherheitslücke ist Inhabern von rund 5.000 Dropbox-Konten zum Verhängnis geworden, die auf die Einrichtung von Zwei-Faktor-Authentifizierung (2FA) verzichtet hatten: Unbefugte haben sich mittels frisch angelegter Lenovo-Konten Zugriff verschafft.
---------------------------------------------
https://www.heise.de/news/Fremde-Dropbox-Konten-ueber-Lenovo-ID-zugaenglich…
∗∗∗ The Vulnpocalypse Is Repricing the Bug Bounty Economy ∗∗∗
---------------------------------------------
The shape of the market may be changing, but there's no indication that the bug bounty as we know it is going away. Of the dozen executives, security experts and researchers Dark Reading spoke to, not one believed that the vulnpocalypse was an existential crisis for independent security research. It would challenge the ecosystem, reshape it, and could perhaps act as a reckoning for those companies that release insecure software, but this moment would be more akin to a storm that will pass.
---------------------------------------------
https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing…
∗∗∗ Passkeys erklärt: wie sicher die Anmeldung ohne Passwort ist ∗∗∗
---------------------------------------------
Immer öfter erscheint beim Anmelden auf einer Website ein Fenster mit der Frage, ob Sie einen Passkey erstellen möchten. Viele klicken es weg, weil sie nicht wissen, was das eigentlich ist. Dahinter steckt eine Technologie, die das Potenzial hat, das Anmelden im Internet grundlegend sicherer zu machen.
---------------------------------------------
https:\/\/www.zettasecure.com\/post\/sind-passkeys-sicher
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar ∗∗∗
---------------------------------------------
In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Authentifizierung, die Appliance dazu zu bringen, serverseitig Anfragen an eigentlich nicht erreichbare interne Endpunkte zu senden (Server-Side Request Forgery). Laut SonicWall PSIRT werden die in diesem Advisory beschriebenen Schwachstellen bereits aktiv ausgenutzt. CVE-2026-83548, CVE-2026-83549
---------------------------------------------
https://www.cert.at/de/warnungen/2026/9/erneut-kritische-sicherheitslucken-…
∗∗∗ Plex: Important Security Update for Plex Media Server v1.43.2 and earlier ∗∗∗
---------------------------------------------
We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible. CVEs have been requested and we’ll reply to this thread with more details once they’re published.
---------------------------------------------
https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1092149/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 31-08-2026 18:00 − Dienstag 01-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Hackers push malicious Virtualizor update in BGP hijacking attack ∗∗∗
---------------------------------------------
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtu…
∗∗∗ The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st) ∗∗∗
---------------------------------------------
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
---------------------------------------------
https://isc.sans.edu/diary/rss/33298
∗∗∗ Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity ∗∗∗
---------------------------------------------
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user.
---------------------------------------------
https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.h…
∗∗∗ OpenClaw 2.0 pours glitter on slow-burning security dumpster fire ∗∗∗
---------------------------------------------
OpenClaw has unveiled what its makers call its largest ever update – large enough to earn a 2.0 moniker – with usability taking center stage, along with some security updates that critics are suggesting will be insufficient.
---------------------------------------------
https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-…
∗∗∗ Password spraying campaign targets AWS root user accounts across 150+ organizations ∗∗∗
---------------------------------------------
Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campai…
∗∗∗ 13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds ∗∗∗
---------------------------------------------
Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them. The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware.
---------------------------------------------
https://socket.dev/blog/packagist-themes-ios-spyware
∗∗∗ EncryptedSharedPreferences is Dead: Here’s What You Should Use Instead ∗∗∗
---------------------------------------------
In this post we’ll explore why persisting data to disk introduces unnecessary risk, dissect the mechanics of storage systems on Android, and provide you with proven methods to safeguard your application data. Furthermore, we’ll cover common misconceptions and misunderstandings with a focus on Android, including Google’s current stance that unencrypted internal app storage is not a concern due to reliance on OS protections such as device encryption and sandboxing, alongside recommended alternatives such as Jetpack DataStore coupled with Google Tink for encryption.
---------------------------------------------
https://blog.includesecurity.com/2026/08/encryptedsharedpreferences-is-dead…
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdates für Hoymiles-Wechselrichter (30.8. 2026) ∗∗∗
---------------------------------------------
Im Juli 2026 hatte der Chaos Computer Club (CCC) vor gravierenden Schwachstellen im DTU-Protokoll des Herstellers Hoymiles gewarnt. Nun hat der Anbieter Firmware-Updates für verschiedene Modelle bereitgestellt, die die Schwachstellen schließen.
---------------------------------------------
https://borncity.com/blog/2026/09/01/sicherheitsupdates-fuer-hoymiles-wechs…
∗∗∗ VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/456290
∗∗∗ Mozilla Security Advisories September 1, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1091919/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/