=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 03-09-2026 18:00 − Freitag 04-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Critical Citrix NetScaler auth bypass now leveraged in attacks ∗∗∗
---------------------------------------------
Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. [..] While the company has yet to flag the vulnerability as actively exploited in its August 19 security advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Thursday that attackers have begun targeting CVE-2026-19490 in the wild after a "credible" proof-of-concept exploit was published online.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-target-critical-citr…
∗∗∗ ASCII smuggling crosses over from AI prompt injection to phishing evasion ∗∗∗
---------------------------------------------
Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-cr…
∗∗∗ Jetzt patchen! Angreifer führen Schadcode in der Sandbox von Chrome aus ∗∗∗
---------------------------------------------
Google hat mehrere Sicherheitslücken im Webbrowser Chrome geschlossen. [..] Die derzeit ausgenutzte Schwachstelle (CVE-2026-85046 „hoch“) ist eine Type-Confusion-Lücke in der JavaScript-Engine V8, führen die Entwickler in einer Warnmeldung aus. Bei dieser Art von Schwachstellen kommt es bei der Verarbeitung von inkompatiblen Objekten zu Speicherfehlern, über die Schadcode auf Systeme gelangt. In diesem konkreten Fall müssen entfernte Angreifer Opfer auf eine von ihnen präparierte Website locken.
---------------------------------------------
https://www.heise.de/news/Jetzt-patchen-Angreifer-fuehren-Schadcode-in-der-…
∗∗∗ Free streaming boxes may be routing criminal traffic through your home ∗∗∗
---------------------------------------------
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/09/free-streaming-boxes-may-be-…
∗∗∗ Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin ∗∗∗
---------------------------------------------
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026 [..]
---------------------------------------------
https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critic…
∗∗∗ Reproducing CVE-2026-75604: Next.js Path Traversal to RCE on Windows ∗∗∗
---------------------------------------------
Vulnerability research: CVE-2026-75604 A single un-escaped backslash in the Next.js incremental cache lets an unauthenticated attacker read and write files on Windows hosts, and, on the right versions and app shape, run commands. Here is the whole chain, reproduced end to end.
---------------------------------------------
https://fortbridge.co.uk/research/next-js-path-traversal-to-rce/
=====================
= Vulnerabilities =
=====================
∗∗∗ VU#889462: Casdoor authentication server is vulnerable to authorization bypass ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/889462
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1092659/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 02-09-2026 18:00 − Donnerstag 03-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Critical Elementor Pro flaw exploited to take over WordPress sites ∗∗∗
---------------------------------------------
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-…
∗∗∗ Impersonating IT support: how threat actors turn a remote session into enterprise-wide access ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-s…
∗∗∗ Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon ∗∗∗
---------------------------------------------
"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," [..] The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with Crowdstrike Falcon.
---------------------------------------------
https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
∗∗∗ This Is Flock’s AI Search Tool for Cops ∗∗∗
---------------------------------------------
WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description. [..] Police officers have already used Flock’s software to track people for reasons unrelated to police work. At least 50 officers in the US have recently been charged with or accused of misusing license plate readers, according to The Washington Post.
---------------------------------------------
https://www.wired.com/story/flock-ai-search-user-interface/
∗∗∗ WhatsApp-Sicherheitslücke: Zugriff auf Fotos bei gesperrtem Android-Handy ∗∗∗
---------------------------------------------
Die WhatsApp-App unter Android hat offenbar eine Schwachstelle. Unbefugte Nutzerinnen und Nutzer können auf einigen Geräten bei einem eingehenden Videoanruf im gesperrten Zustand auf private Fotoordner zugreifen. Meta hat nach eigenen Angaben inzwischen begonnen, einen Fix zu verteilen. Bis dieser flächendeckend ankommt, gibt es eine Übergangslösung.
---------------------------------------------
https://www.heise.de/news/WhatsApp-Sicherheitsluecke-Zugriff-auf-Fotos-bei-…
∗∗∗ WordPress All-in-One WP Migration: Angreifer können Admin-Falle auslegen ∗∗∗
---------------------------------------------
Das WordPress-Plug-in All-in-One WP Migration and Backup ist verwundbar und Angreifer können im schlimmsten Fall die volle Kontrolle über mit dem CMS erstellte Websites erlangen. [..] Die Sicherheitsforscher geben an, dass die Entwickler von All-in-One WP Migration and Backup Mitte August von der Schwachstelle erfahren haben. Der Sicherheitspatch war fünf Tage später fertig und steht seit dem 20. August 2026 zum Download bereit.
---------------------------------------------
https://www.heise.de/news/WordPress-All-in-One-WP-Migration-Angreifer-koenn…
∗∗∗ Why your data is safer than you think on public Wi-Fi ∗∗∗
---------------------------------------------
The coffee shop hacker Public Wi-Fi has acquired a slightly theatrical reputation. Join the network in a coffee shop, we are told, and a hacker in the corner can immediately steal your passwords and empty your bank account. It makes for good VPN advertising. It is not a particularly accurate picture of how the modern web works.
---------------------------------------------
https://www.pentestpartners.com/security-blog/why-your-data-is-safer-than-y…
∗∗∗ Analyse: Umfassendes Fake-Netzwerk aus Insolvenzverwaltern, IT-Anbietern, Unternehmensberatern und Zeitungen ∗∗∗
---------------------------------------------
Um den Anschein von Seriosität zu verstärken, bauen Kriminelle umfangreiche Onlinemagazine. In der dortigen Flut an angeblich realen Geschichten platzieren sie Artikel, die über vermeintlich seriöse Insolvenzverwalter, IT-Anbietern und Unternehmensberater berichten. Die gesamte Konstruktion ist auf Vorschussbetrug und das Sammeln von Daten ausgelegt.
---------------------------------------------
https://www.watchlist-internet.at/news/analyse-umfassendes-fake-netzwerk/
∗∗∗ Chamilo LMS... Its raining 0days, hallelujah, its raining 0days ∗∗∗
---------------------------------------------
Chamilo is an open source Learning Management System (LMS) widely deployed in schools and enterprises around the world. In this blogpost we explain how we were able to identify multiple vulnerabilities including a full unauthenticated Remote Code Execution chain in the latest version.
---------------------------------------------
http://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-rain…
=====================
= Vulnerabilities =
=====================
∗∗∗ VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) ∗∗∗
---------------------------------------------
VMware Workstation and Fusion contain an integer-overflow vulnerability. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. CVE-2026-59346, CVE-2026-59347
---------------------------------------------
https://support.broadcom.com/web/ecx/support-content-notification/-/externa…
∗∗∗ HPE: HPESBNW05133 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer ∗∗∗
---------------------------------------------
Remote: Access Restriction Bypass, Authentication Bypass, Escalation of Privilege
---------------------------------------------
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&doc…
∗∗∗ HPE: HPESBNW05134 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX) ∗∗∗
---------------------------------------------
Local: Access Restriction Bypass
---------------------------------------------
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&doc…
∗∗∗ Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Drupal Security Advisories 2026-September-02 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1092419/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 01-09-2026 18:00 − Mittwoch 02-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Hackers abuse Faronics Deploy admin tool to install ScreenConnect ∗∗∗
---------------------------------------------
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deplo…
∗∗∗ Bei Sandboxing-Tests: KI-Agent bricht mehrfach aus VM aus ∗∗∗
---------------------------------------------
Ein Forscher hat getestet, ob sich moderne KI-Modelle mit Virtualisierung sinnvoll isolieren lassen. Die KI ist mehrfach aus einer VM entkommen. [..] Der Forscher hatte die KI zwar explizit dazu angewiesen aus der VM auszubrechen, jedoch sind entsprechende Ausbrüche auch in anderen Situationen denkbar. [..] Zudem rät Dinaburg, für die Virtualisierung auf minimalistische Lösungen umzusteigen, die eine geringere Angriffsfläche bieten.
---------------------------------------------
https://www.golem.de/news/bei-sandboxing-tests-ki-agent-bricht-mehrfach-aus…
∗∗∗ Counterfeit installers to system compromise: Tracking a deceptive software download campaign ∗∗∗
---------------------------------------------
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-instal…
∗∗∗ Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials ∗∗∗
---------------------------------------------
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026.
---------------------------------------------
https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html
∗∗∗ OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities ∗∗∗
---------------------------------------------
The company will give select partners early access to its Astra AI model—so they have time to shore up their defenses.
---------------------------------------------
https://www.wired.com/story/openai-astra-first-ai-model-with-critical-cyber…
∗∗∗ Fremde Dropbox-Konten über Lenovo-ID zugänglich ∗∗∗
---------------------------------------------
Eine erstaunliche Sicherheitslücke ist Inhabern von rund 5.000 Dropbox-Konten zum Verhängnis geworden, die auf die Einrichtung von Zwei-Faktor-Authentifizierung (2FA) verzichtet hatten: Unbefugte haben sich mittels frisch angelegter Lenovo-Konten Zugriff verschafft.
---------------------------------------------
https://www.heise.de/news/Fremde-Dropbox-Konten-ueber-Lenovo-ID-zugaenglich…
∗∗∗ The Vulnpocalypse Is Repricing the Bug Bounty Economy ∗∗∗
---------------------------------------------
The shape of the market may be changing, but there's no indication that the bug bounty as we know it is going away. Of the dozen executives, security experts and researchers Dark Reading spoke to, not one believed that the vulnpocalypse was an existential crisis for independent security research. It would challenge the ecosystem, reshape it, and could perhaps act as a reckoning for those companies that release insecure software, but this moment would be more akin to a storm that will pass.
---------------------------------------------
https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing…
∗∗∗ Passkeys erklärt: wie sicher die Anmeldung ohne Passwort ist ∗∗∗
---------------------------------------------
Immer öfter erscheint beim Anmelden auf einer Website ein Fenster mit der Frage, ob Sie einen Passkey erstellen möchten. Viele klicken es weg, weil sie nicht wissen, was das eigentlich ist. Dahinter steckt eine Technologie, die das Potenzial hat, das Anmelden im Internet grundlegend sicherer zu machen.
---------------------------------------------
https:\/\/www.zettasecure.com\/post\/sind-passkeys-sicher
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar ∗∗∗
---------------------------------------------
In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Authentifizierung, die Appliance dazu zu bringen, serverseitig Anfragen an eigentlich nicht erreichbare interne Endpunkte zu senden (Server-Side Request Forgery). Laut SonicWall PSIRT werden die in diesem Advisory beschriebenen Schwachstellen bereits aktiv ausgenutzt. CVE-2026-83548, CVE-2026-83549
---------------------------------------------
https://www.cert.at/de/warnungen/2026/9/erneut-kritische-sicherheitslucken-…
∗∗∗ Plex: Important Security Update for Plex Media Server v1.43.2 and earlier ∗∗∗
---------------------------------------------
We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible. CVEs have been requested and we’ll reply to this thread with more details once they’re published.
---------------------------------------------
https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1092149/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 31-08-2026 18:00 − Dienstag 01-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Hackers push malicious Virtualizor update in BGP hijacking attack ∗∗∗
---------------------------------------------
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtu…
∗∗∗ The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st) ∗∗∗
---------------------------------------------
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
---------------------------------------------
https://isc.sans.edu/diary/rss/33298
∗∗∗ Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity ∗∗∗
---------------------------------------------
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user.
---------------------------------------------
https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.h…
∗∗∗ OpenClaw 2.0 pours glitter on slow-burning security dumpster fire ∗∗∗
---------------------------------------------
OpenClaw has unveiled what its makers call its largest ever update – large enough to earn a 2.0 moniker – with usability taking center stage, along with some security updates that critics are suggesting will be insufficient.
---------------------------------------------
https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-…
∗∗∗ Password spraying campaign targets AWS root user accounts across 150+ organizations ∗∗∗
---------------------------------------------
Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campai…
∗∗∗ 13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds ∗∗∗
---------------------------------------------
Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them. The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware.
---------------------------------------------
https://socket.dev/blog/packagist-themes-ios-spyware
∗∗∗ EncryptedSharedPreferences is Dead: Here’s What You Should Use Instead ∗∗∗
---------------------------------------------
In this post we’ll explore why persisting data to disk introduces unnecessary risk, dissect the mechanics of storage systems on Android, and provide you with proven methods to safeguard your application data. Furthermore, we’ll cover common misconceptions and misunderstandings with a focus on Android, including Google’s current stance that unencrypted internal app storage is not a concern due to reliance on OS protections such as device encryption and sandboxing, alongside recommended alternatives such as Jetpack DataStore coupled with Google Tink for encryption.
---------------------------------------------
https://blog.includesecurity.com/2026/08/encryptedsharedpreferences-is-dead…
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdates für Hoymiles-Wechselrichter (30.8. 2026) ∗∗∗
---------------------------------------------
Im Juli 2026 hatte der Chaos Computer Club (CCC) vor gravierenden Schwachstellen im DTU-Protokoll des Herstellers Hoymiles gewarnt. Nun hat der Anbieter Firmware-Updates für verschiedene Modelle bereitgestellt, die die Schwachstellen schließen.
---------------------------------------------
https://borncity.com/blog/2026/09/01/sicherheitsupdates-fuer-hoymiles-wechs…
∗∗∗ VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/456290
∗∗∗ Mozilla Security Advisories September 1, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1091919/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 28-08-2026 18:00 − Montag 31-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Anthropic warns infostealer malware is hijacking Claude sessions to drain usage ∗∗∗
---------------------------------------------
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.
---------------------------------------------
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-war…
∗∗∗ Virenschutz angeblich aus: Microsoft Defender spielt falsche Warnmeldung aus ∗∗∗
---------------------------------------------
Einige Windows-Nutzer erhalten seit Wochen Warnmeldungen vom Microsoft Defender, dass der Virenschutz inaktiv sei. Das ist jedoch ein Anzeigefehler.
---------------------------------------------
https://www.golem.de/news/virenschutz-angeblich-aus-microsoft-defender-spie…
∗∗∗ ValleyRAT masquerading as adware ∗∗∗
---------------------------------------------
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
---------------------------------------------
https://securelist.com/valleyrat-backdoor-adware/121175/
∗∗∗ TerminalFix campaign deploys a reverse tunnel through multistage intrusion ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campai…
∗∗∗ The Linux Kernel Is Approaching 2,000 CVEs Per Release ∗∗∗
---------------------------------------------
Phoronix reports on Greg Kroah-Hartmans recent slide from his upcoming talk in Paris at Kernel Recipes 2026 (September 21 to 23):With the proliferation of AI/LLM models analyzing the Linux kernels vast codebase, there has been a surge in the number of CVEs per kernel release. After typically being around 500 CVEs fixed per release, we are now approaching ..
---------------------------------------------
https://linux.slashdot.org/story/26/08/29/0547248/the-linux-kernel-is-appro…
∗∗∗ China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs ∗∗∗
---------------------------------------------
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor ..
---------------------------------------------
https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
∗∗∗ Microsoft Teams Has Become a Haven for Scammers in China ∗∗∗
---------------------------------------------
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.
---------------------------------------------
https://www.wired.com/story/microsoft-teams-is-becoming-a-haven-for-chinese…
∗∗∗ ATM Flaws Reveal Key Weaknesses in the Software Supply Chain ∗∗∗
---------------------------------------------
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
---------------------------------------------
https://www.wired.com/story/atm-flaws-reveal-key-weaknesses-in-the-software…
∗∗∗ 30 Bitcoin oder Leak – Ransomware-Bande erpresst Berlin ∗∗∗
---------------------------------------------
Die Gruppe „Rhysida“ will 30 Bitcoin von Berlin, oder vertrauliche Daten veröffentlichen. Die Stadt will nicht zahlen, sagte Kai Wegner.
---------------------------------------------
https://www.heise.de/news/30-Bitcoin-oder-Leak-Ransomware-Bande-erpresst-Be…
∗∗∗ Exchange-Sicherheitslücke: 85 Prozent der On-Prem-Server in Deutschland anfällig ∗∗∗
---------------------------------------------
Ein Proof-of-Concept-Exploit für eine hochriskante Exchange-Lücke ist öffentlich. 85 Prozent der On-Premises-Server sind anfällig.
---------------------------------------------
https://www.heise.de/news/Exchange-Sicherheitsluecke-85-Prozent-der-On-Prem…
∗∗∗ Root-Sicherheitslücke bedroht cPanel/WHM ∗∗∗
---------------------------------------------
In aktuellen Versionen haben die Entwickler der Webhosting-Control-Panel-Software cPanel/WHM eine Schwachstelle geschlossen.
---------------------------------------------
https://www.heise.de/news/Root-Sicherheitsluecke-bedroht-cPanel-WHM-1143489…
∗∗∗ WatchGuard Security-Appliances: Schadcode-Lücken in Firebox OS geschlossen ∗∗∗
---------------------------------------------
Firewalls und VPN-Technik von WatchGuard sind attackierbar. Reparierte Versionen von Firebox OS sind verfügbar.
---------------------------------------------
https://www.heise.de/news/WatchGuard-Security-Appliances-Schadcode-Luecken-…
∗∗∗ Überwachungs-Schnittstellen in weltweit verkauften Routern aus China entdeckt ∗∗∗
---------------------------------------------
"EndlessDoors", "DarkLantern" und "SpeakingStone" geben Zugriff, wo keiner sein sollte. Die Router von ZBT werden unter verschiedenen Marken angeboten
---------------------------------------------
https://www.derstandard.at/story/3000000337615/ueberwachungs-schnittstellen…
∗∗∗ "Gravierende Sicherheitslücke": Mobilfunknetze plaudern bei Anruf sensible Daten aus ∗∗∗
---------------------------------------------
Teilweise konnten sowohl die eindeutige Gerätekennung IMEI als auch Details zur Betriebssystemversion erfasst werden. Heimische Provider wiegeln weitgehend ab
---------------------------------------------
https://www.derstandard.at/story/3000000337719/gravierende-sicherheitslueck…
∗∗∗ Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams ∗∗∗
---------------------------------------------
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.
---------------------------------------------
https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
∗∗∗ PaperCut warns of hackers using printer management software flaw in attacks ∗∗∗
---------------------------------------------
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
---------------------------------------------
https://therecord.media/papercut-warns-of-hackers-using-printer-management-…
∗∗∗ Omarchy: Any User Process Can Escalate to Root ∗∗∗
---------------------------------------------
A security issue in Omarchy’s default Docker configuration meant that essentially every program running in the user’s desktop session could escalate to root without a password, sudo, or a privilege prompt.
---------------------------------------------
https://0xcc.io/posts/omarchy-root-creds/
∗∗∗ curl: a CVE dispute ∗∗∗
---------------------------------------------
A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE or not. No more bogus ..
---------------------------------------------
https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/
∗∗∗ OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack ∗∗∗
---------------------------------------------
Ten malicious versions were published with valid npm provenance after a threat actor abused a comment-triggered GitHub Actions publishing workflow, with the latest release still compromised at the time of writing.The Socket Threat Research Team is investigating an ongoing Mini Shai-Hulud compromise, affecting the npm package @7nohe/openapi-react-query-codegen. On August 28, ..
---------------------------------------------
https://socket.dev/blog/openapi-react-query-codegen-npm-compromise
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 27-08-2026 18:00 − Freitag 28-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ PaperCut warns of NG, MF flaw exploited in zero-day attacks ∗∗∗
---------------------------------------------
PaperCut is warning that hackers are actively exploiting a
vulnerability in all versions of its PaperCut NG and PaperCut MF print
management software in zero-day attacks.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw…
∗∗∗ Over 8,300 Gitea servers vulnerable to code execution attacks ∗∗∗
---------------------------------------------
Over 8,300 Internet-exposed Gitea instances are still unpatched against
a critical security flaw exploited in ongoing remote code execution
attacks, according to cybersecurity watchdog Shadowserver.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vul…
∗∗∗ Patch-Defizit in Deutschland: Exploit gefährdet 85 Prozent aller
Exchange-Server ∗∗∗
---------------------------------------------
Auf Github ist ein Exploit für eine gefährliche Exchange-Lücke
aufgetaucht. Einen Patch gibt es zwar, doch den haben in Deutschland
nur wenige installiert.
---------------------------------------------
https://www.golem.de/news/patch-defizit-in-deutschland-exploit-gefaehrdet-8…
change-server-2608-212397.html
∗∗∗ APT28-Linked HOOKEDGE Backdoor Targets European Government and
Diplomatic Organizations ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a fresh set of campaigns
targeting government and diplomatic organizations in Romania, Spain,
and Türkiye between late September 2025 and early April 2026.These
campaigns, per Recorded Future Insikt Group, ..
---------------------------------------------
https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.ht…
∗∗∗ Critical cPanel Flaw Could Let One Hosting Customer Take Root
Control of a Whole Server ∗∗∗
---------------------------------------------
cPanel has released patches for a security flaw affecting domain
parking and addon domain functionality in cPanel and WebHost Manager
(WHM), which could allow code execution as the root user.The
vulnerability, assigned the CVE identifier CVE-2026-65643, ..
---------------------------------------------
https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
∗∗∗ Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated
Attackers Execute Code and SQL ∗∗∗
---------------------------------------------
ServiceNow has released patches for four security flaws impacting the
ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring
system and exploitable, in certain circumstances, by an unauthenticated
attacker.The company said it deployed a ..
---------------------------------------------
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
∗∗∗ 19 Chrome and Edge Extensions Found With Wallet-Stealing and
Crypto-Draining Code ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered a cluster of 18 Google Chrome
and one Microsoft Edge extensions that were published over the last six
months and harbored wallet secret stealing and cryptocurrency draining
capabilities.The extensions, per ..
---------------------------------------------
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
∗∗∗ AI girlfriend review sites secrets were exposed to the world for
three weeks ∗∗∗
---------------------------------------------
Even testing and staging sites need protection from prying eyes.
---------------------------------------------
https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-…
∗∗∗ CRPx0 hacking service for dummies claims victim count more than
quintupled ∗∗∗
---------------------------------------------
Its built to be operated by a human with no technical background.
---------------------------------------------
https://www.theregister.com/cyber-crime/2026/08/27/crpx0-hacking-service-fo…
∗∗∗ TeamViewer schließt hochriskante Lücken in Clients ∗∗∗
---------------------------------------------
Die TeamViewer-Clients können Angreifern das Ausführen von Schadcode
ermöglichen. Updates stopfen die hochriskanten Sicherheitslücken.
---------------------------------------------
https://www.heise.de/news/TeamViewer-stopft-Codeschmuggel-Leck-11432840.html
∗∗∗ Google macht Android 17 sicherer: ECH-Unterstützung und
2G-Abschaltung ∗∗∗
---------------------------------------------
Mit Android 17 führt Google neue Netzwerksicherheitsfunktionen ein.
Diese sollen Verbindungen absichern und die Privatsphäre im heimischen
WLAN schützen.
---------------------------------------------
https://www.heise.de/news/2G-Abschaltung-und-ECH-Support-Android-17-erhoeht…
∗∗∗ „Begrenztes Zeitfenster“: Mehr als 100 Unternehmen warnen vor
KI-Cyberangriffen ∗∗∗
---------------------------------------------
Führende KI-Labore sowie mehr als 100 Organisationen warnen in einem
offenen Brief vor einer baldigen Zunahme KI-gestützter Cyberangriffe.
---------------------------------------------
https://www.heise.de/news/Begrenztes-Zeitfenster-Mehr-als-100-Unternehmen-w…
∗∗∗ Zwei kritische Lücken in Next.js – Remote-Code-Ausführung unter
Windows ∗∗∗
---------------------------------------------
Die zwei kritischen von Vercel gemeldeten Lücken im
JavaScript-Framework Next.js ermöglichen es Angreifern, Code
auszuführen.
---------------------------------------------
https://www.heise.de/news/Zwei-kritische-Luecken-in-Next-js-Remote-Code-Aus…
∗∗∗ (OEM-)China-Router von ZBT mit Backdoors ∗∗∗
---------------------------------------------
IT-Forscher haben Router vom OEM-Hersteller ZBT untersucht, die
weltweit von Anbietern verkauft werden. Darin fanden sie Backdoors.
---------------------------------------------
https://www.heise.de/news/OEM-China-Router-von-ZBT-mit-Backdoors-11433072.h…
∗∗∗ Disruptive cyber activity highlights risk from internet-exposed
systems and edge devices ∗∗∗
---------------------------------------------
Targeting of operational technology reinforces the need for
organisations to understand what is exposed to the internet, address
avoidable vulnerabilities, and build long-term cyber resilience.
---------------------------------------------
https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from…
∗∗∗ Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to
Target Credentials and Secrets ∗∗∗
---------------------------------------------
GreyNoise is observing automated scanners posing as the web crawlers of
OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged
user agents while requesting the files where misconfigured web servers
frequently leak secrets and credentials.
---------------------------------------------
https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers
∗∗∗ Inside 90 days of attacks on AI infrastructure ∗∗∗
---------------------------------------------
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers,
and AI frameworks through RCE, blind prompt injection, and memory
credential theft.
---------------------------------------------
https://www.wiz.io/blog/ai-infrastructure-honeypot
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 26-08-2026 18:00 − Donnerstag 27-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ New GPUThor attack defeats NVIDIA ECC protection for root access ∗∗∗
---------------------------------------------
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-n…
∗∗∗ ATF confirms “major incident” after recent Qilin breach claims ∗∗∗
---------------------------------------------
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-…
∗∗∗ Carhartt data breach exposes information of 12.9 million accounts ∗∗∗
---------------------------------------------
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes…
∗∗∗ Sicherheitslücke beim Mobilfunk: Angreifer konnten per Anruf Gerätedaten ausspähen ∗∗∗
---------------------------------------------
Reporter haben eine Sicherheitslücke in den Mobilfunknetzen mehrerer Provider entdeckt. Angreifer konnten ohne Nutzerinteraktion Gerätedaten abgreifen.
---------------------------------------------
https://www.golem.de/news/sicherheitsluecke-beim-mobilfunk-angreifer-haben-…
∗∗∗ Threat landscape for industrial automation systems. Q2 2026 ∗∗∗
---------------------------------------------
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
---------------------------------------------
https://securelist.com/industrial-threat-report-q2-2026/121159/
∗∗∗ When AI infrastructure becomes the target: Securing gateways and control points ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastruc…
∗∗∗ What We Still Don’t Know About OpenAI’s Hugging Face Hack ∗∗∗
---------------------------------------------
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didnt see this fiasco coming.
---------------------------------------------
https://www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-q…
∗∗∗ Berliner Landesnetz: Sensible Daten bei Cyberangriff womöglich doch betroffen ∗∗∗
---------------------------------------------
Eine Cyberattacke traf vor knapp zwei Wochen zwei Berliner Senatsverwaltungen. Bislang hieß es, es seien nur frei verfügbare Geodaten abgeflossen.
---------------------------------------------
https://www.heise.de/news/Sensible-Daten-bei-Cyberangriff-womoeglich-doch-b…
∗∗∗ Angreifer können an rund 550 Lücken in Dell PowerProtect Cyber Recovery ansetzen ∗∗∗
---------------------------------------------
Dells IT-Sicherheitslösung PowerProtect Cyber Recovery bietet viele Angriffspunkte. Admins sollten ihre Instanzen zeitnah über Updates absichern.
---------------------------------------------
https://www.heise.de/news/Sicherheitspatches-Rund-550-Luecken-gefaehrden-De…
∗∗∗ Hugging-Face-Angriff: OpenAI-Abschlussbericht liefert neue Erkenntnisse ∗∗∗
---------------------------------------------
OpenAIs Bericht zum Hugging-Face-Vorfall zeigt, dass riskante Verhaltensmuster schon beim Training auftraten und Warnsignale nicht ausreichend eskaliert wurden.
---------------------------------------------
https://www.heise.de/news/OpenAI-Abschlussbericht-Rund-700-Agenten-griffen-…
∗∗∗ Two Alleged ‘TeamPCP’ Hackers Arrested in Australia ∗∗∗
---------------------------------------------
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands ..
---------------------------------------------
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in…
∗∗∗ Microsoft Exchange: Exploit-Code veröffentlicht (CVE-2026-62911) ∗∗∗
---------------------------------------------
Wie Heise berichtet, wurde auf Github Exploit-Code für eine Sicherheitslücke in Microsoft Exchange veröffentlicht. Microsoft hat im Rahmen seines regulären Patchzykluses Fixes für diese Sicherheitslücke veröffentlicht, betroffen sind demnach die Versionen Microsoft Exchange Server 2019, 2016 und die Subscription Edition RTM. Für die Version 2016 stellt Microsoft die Fixes nur über sein Extended-Security-Updates-Programm zur Verfügung. Wir teilen ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/8/microsoft-exchange-exploit-code-ver…
∗∗∗ CISA Urges SharePoint Hardening After New Exploitations ∗∗∗
---------------------------------------------
Update August 26, 2026:CISA has updated this Alert to clarify guidance on avoiding the direct exposure of SharePoint Servers to the internet.Update August 18, 2026:CISA has updated this Alert to reflect the addition of CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) Catalog on August 18, 2026. Update July 28, 2026:CISA has updated this Alert to include CVE-2026-50522 and its addition to the KEV Catalog on July 22, 2026.Update July 16, 2026: CISA has updated this Alert to reflect the ..
---------------------------------------------
https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-ha…
∗∗∗ Medical device firm Boston Scientific says cyberattack has disrupted shipment processes ∗∗∗
---------------------------------------------
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
---------------------------------------------
https://therecord.media/boston-scientific-cyberattack-disrupts-shipment-pro…
∗∗∗ Disruptive cyber activity highlights risk from internet-exposed systems and edge devices ∗∗∗
---------------------------------------------
Targeting of operational technology reinforces the need for organisations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience.
---------------------------------------------
https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from…
∗∗∗ Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident ∗∗∗
---------------------------------------------
Two METR staff members (Hjalmar Wijk and Ajeya Cotra) and a Redwood Research staff member contracting with METR (Ryan Greenblatt) worked on premises at OpenAI over a total of six days1 to attempt to form an independent understanding of model behavior observed during the recent incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned “message board.”
---------------------------------------------
https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
∗∗∗ Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation ∗∗∗
---------------------------------------------
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]
---------------------------------------------
https://aws.amazon.com/blogs/security/detecting-multi-stage-attacks-on-aws-…
=====================
= Vulnerabilities =
=====================
∗∗∗ CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-105
∗∗∗ Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-111
∗∗∗ Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-110
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 25-08-2026 18:00 − Mittwoch 26-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Hackers abuse npm mirrors to host phishing redirect pages ∗∗∗
---------------------------------------------
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to…
∗∗∗ Ubiquiti patches three max severity security vulnerabilities ∗∗∗
---------------------------------------------
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-s…
∗∗∗ Jetzt updaten: 327 Sicherheitslücken in Google Chrome gepatcht ∗∗∗
---------------------------------------------
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden.
---------------------------------------------
https://www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-ch…
∗∗∗ Viele Softwareprojekte gefährdet: Hacker schleusen Schadcode auf Gitea-Instanzen ∗∗∗
---------------------------------------------
Eine kritische Sicherheitslücke ermöglicht Schadcode-Attacken auf Gitea-Instanzen. Angreifer nutzen das bereits. Admins sollten zügig patchen.
---------------------------------------------
https://www.golem.de/news/viele-softwareprojekte-gefaehrdet-hacker-schleuse…
∗∗∗ Exploits and vulnerabilities in Q2 2026 ∗∗∗
---------------------------------------------
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
---------------------------------------------
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
∗∗∗ The patch window is collapsing: Why security needs a new control plane ∗∗∗
---------------------------------------------
Organizations need protection that operates in the gap between discovery and remediation.
---------------------------------------------
https://azure.microsoft.com/en-us/blog/the-patch-window-is-collapsing-why-s…
∗∗∗ Boston Scientific discloses global disruption in ongoing cyberattack ∗∗∗
---------------------------------------------
No timeline to restore IT systems as probe remains ongoing
---------------------------------------------
https://www.theregister.com/security/2026/08/26/boston-scientific-discloses…
∗∗∗ WordPress-Plug-in TranslatePress ermöglicht Übernahme bei 400.000 Installationen ∗∗∗
---------------------------------------------
Eine Lücke im Plug-in TranslatePress für WordPress gefährdet 400.000 Instanzen. Angriffe laufen derweil auf miniOrange SAML.
---------------------------------------------
https://www.heise.de/news/WordPress-Plug-in-TranslatePress-ermoeglicht-Uebe…
∗∗∗ Spyware-Masche gegen Indeed-Nutzer – infizierte Vorstellungsgespräch-Apps ∗∗∗
---------------------------------------------
IT-Forscher beobachten eine globale Malware-Kampagne, bei der die Drahtzieher es auf Nutzer der Indeed-Plattform abgesehen haben.
---------------------------------------------
https://www.heise.de/news/Spyware-Masche-gegen-Indeed-Nutzer-infizierte-Vor…
∗∗∗ Kritische Schadcode-Lücken in Adobe-Anwendungen geschlossen ∗∗∗
---------------------------------------------
Angreifer können mehrere Sicherheitslücken unter anderem in Adobe Campaign Classic, Illustrator und Substance 3D Designer ausnutzen.
---------------------------------------------
https://www.heise.de/news/Kritische-Schadcode-Luecken-in-Adobe-Anwendungen-…
∗∗∗ Verfassungsschutz sieht kein Zero-Day-Problem durch mehr Befugnisse ∗∗∗
---------------------------------------------
Unternehmen sind stark von Cyberangriffen betroffen, so eine Bitkom-Studie. Verfassungsschutzpräsident Selen warnt vor dem Unterschätzen von Abhängigkeiten.
---------------------------------------------
https://www.heise.de/news/Verfassungsschutz-sieht-kein-Zero-Day-Problem-dur…
∗∗∗ Zwei Fallen in einer: Wie Kriminelle ihre Opfer mit Fake-Jobs und Krypto-Investmentbetrug ausnehmen ∗∗∗
---------------------------------------------
Eine Betrugsfalle allein kann bereits großen finanziellen Schaden anrichten. Werden zwei Maschen kombiniert, steigert dies die Gefahr nochmals deutlich. Ein vorliegender Fall zeigt, wie Kriminelle ein bereits schwer getroffenes Opfer weiter ausnehmen. Sie erfinden dabei das Rad keineswegs neu, sondern setzen schlicht und einfach sowohl auf Job- als auch auf Krypto-Investmentbetrug.
---------------------------------------------
https://www.watchlist-internet.at/news/zwei-fallen-in-einer/
∗∗∗ Häufung von Betrugsversuchen durch Business Email Compromise (BEC) ∗∗∗
---------------------------------------------
In den letzten Wochen erreichen uns vermehrt Berichte über Versuche, österreichische Organisationen und Unternehmen mittels Business E-Mail Compromise (BEC) zu schädigen. Bei dieser Betrugsform geben sich Kriminelle als vertrauenswürdige Person aus (wie beispielsweise als Geschäftsführung, bekannter Lieferant, Kolleg:in aus der Personalabteilung, ...), um ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/8/vermehrt-betrugsversuche-durch-busi…
∗∗∗ UK government seeks powers to secretly block risky tech suppliers ∗∗∗
---------------------------------------------
The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — and to potentially do so in secret.
---------------------------------------------
https://therecord.media/uk-technology-national-security
∗∗∗ From Mayhem to Atlantis: how AI is changing capture the flag and what this means for cybersecurity ∗∗∗
---------------------------------------------
Ten years after DARPAs first all-machine hacking tournament, AI agents are solving live CTF challenges, competing with human teams and pushing cybersecurity toward an AI-versus-AI future. Read on to discover how this future can affect your cybersecurity.
---------------------------------------------
https://www.jamf.com/blog/from-mayhem-to-atlantis-ai-is-changing/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 24-08-2026 18:00 − Dienstag 25-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Police arrests dozens of suspects in global cybercrime crackdown ∗∗∗
---------------------------------------------
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/police-arrests-dozens-of-sus…
∗∗∗ Hackers breached over 270 Zimbra servers in ongoing attacks ∗∗∗
---------------------------------------------
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zi…
∗∗∗ Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk ∗∗∗
---------------------------------------------
Third-party scripts are common on websites. They help with analytics, ads, live chat, social media, video, payments, and many other features. While not all are risky, every external tag, pixel, widget, or embed adds to your website’s vulnerability. These tools can read page content, collect visitor data, change what users see, and connect ..
---------------------------------------------
https://blog.sucuri.net/2026/08/third-party-script-security-how-tags-pixels…
∗∗∗ Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access ∗∗∗
---------------------------------------------
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including ..
---------------------------------------------
https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.ht…
∗∗∗ Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows ∗∗∗
---------------------------------------------
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor ..
---------------------------------------------
https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
∗∗∗ E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands ∗∗∗
---------------------------------------------
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.While threat actors are ..
---------------------------------------------
https://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.h…
∗∗∗ A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw ∗∗∗
---------------------------------------------
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.The findings were ..
---------------------------------------------
https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html
∗∗∗ You dont want this Sleepwalker backdoor on your Windows machine ∗∗∗
---------------------------------------------
Its own command language, 23 instructions - signs point to well-resourced operation rather than an opportunistic one
---------------------------------------------
https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwal…
∗∗∗ Crooks push Mac malware through fake OpenAI Codex ads ∗∗∗
---------------------------------------------
Sponsored search results lead developers straight into a ClickFix malware trap
---------------------------------------------
https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-thr…
∗∗∗ CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw ∗∗∗
---------------------------------------------
Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
---------------------------------------------
https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-thr…
∗∗∗ Kriminalisierung: Informatiker verlangen Freipass für IT-Sicherheitsforscher ∗∗∗
---------------------------------------------
Die Gesellschaft für Informatik fordert die Bundesregierung auf, ethische Hacker endlich wirksam vor Strafverfolgung zu schützen.
---------------------------------------------
https://www.heise.de/news/Kriminalisierung-Informatiker-verlangen-Freipass-…
∗∗∗ Angreifer nehmen Oracle Weblogic und HTTP-Server ins Visier ∗∗∗
---------------------------------------------
Angreifer missbrauchen eine Sicherheitslücke in Oracle HTTP-Server und Weblogic Server, die komplette Kompromittierung ermöglicht.
---------------------------------------------
https://www.heise.de/news/Attacken-auf-Oracle-Weblogic-und-HTTP-Server-beob…
∗∗∗ Zugriffsverwaltung Keycloak: Kontoübernahme durch Passwort-Rücksetzfunktion ∗∗∗
---------------------------------------------
In dem Identitäts- und Zugriffssteuerungssystem Keycloak können Angreifer einen Fehler beim Passwort-Rücksetzen missbrauchen, um Konten zu übernehmen.
---------------------------------------------
https://www.heise.de/news/Zugriffsverwaltung-Keycloak-Kontouebernahme-durch…
∗∗∗ WhatsApp führt mehrere Passkeys ein und ersetzt PINs ∗∗∗
---------------------------------------------
WhatsApp verbessert die Kontosicherheit durch die Unterstützung mehrerer Passkeys, stärkere Passwörter und Kontextinformationen bei unbekannten Anrufen.
---------------------------------------------
https://www.heise.de/news/WhatsApp-Mehr-Passkeys-und-verbesserte-Sicherheit…
∗∗∗ Phishing-Versuch greift Login-Daten für Onlinebroker ab ∗∗∗
---------------------------------------------
Eine SMS-Nachricht, ein Login-Portal – und fertig ist die Phishing-Falle. Kriminelle versenden aktuell im Namen des Onlinebrokers „flatex“ Warnungen vor dem Ablaufen der für Überweisungen benötigten iTAN-Card. Über die Fake-Anmeldeseite wollen sie an Benutzername und Passwort ihrer Opfer gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-login-daten-onlinebroker/
∗∗∗ The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution ∗∗∗
---------------------------------------------
To assess the impact of AI-enabled malware, we collected and analyzed over 400 malware samples that integrate AI in some capacity, from brand impersonation and large language model (LLM)-generated code to agentic execution loops. Our central finding was that the AI malware space is currently overwhelmingly composed of ..
---------------------------------------------
https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
∗∗∗ Large DDoS attack knocks Norwegian public services offline ∗∗∗
---------------------------------------------
The Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.
---------------------------------------------
https://therecord.media/norway-cyberattack-ddos-government
∗∗∗ A Tale of Two SOCs: Insights From Two Red Team Assessments ∗∗∗
---------------------------------------------
The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but ..
---------------------------------------------
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
∗∗∗ ToxNetV2: An AI-Assisted Botnet Controller ∗∗∗
---------------------------------------------
ToxNetV2 is an AArch64 Linux peer-to-peer botnet that integrates an LLM into the operational workflow of its controller. As uncovered in the Joe Reverser analysis, the controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval. The resulting ..
---------------------------------------------
https://www.joesecurity.org/blog/6764463444623599134
∗∗∗ Open VSX Unblocks Extension IDs Used in Malware Campaign ∗∗∗
---------------------------------------------
Over a five-day period from August 16 through August 20, the registry unblocked AlDuncanson.react-hooks-snippets, magne-sjaastad.opm-flow-editor-support, and rumbledb.jsoniq-vscode. All three IDs had been used by impostors in the 77-extension evil-twin campaign documented by Manifold Security earlier this month. Legitimate versions of the OPM and RumbleDB ..
---------------------------------------------
https://socket.dev/blog/open-vsx-unblocks-malicious-extension-ids
=====================
= Vulnerabilities =
=====================
∗∗∗ TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr) ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025
∗∗∗ TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt) ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023
∗∗∗ TYPO3-EXT-SA-2026-021: Broken Access Control in extension "Forum" (pforum) ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 21-08-2026 18:00 − Montag 24-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ How an Emerging Industrial Protocol Family Could Put OT at Risk ∗∗∗
---------------------------------------------
New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes.
---------------------------------------------
https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protoco…
∗∗∗ Nach Hackerangriff: Berliner Senat überrascht über Größe des IT-Systems ∗∗∗
---------------------------------------------
Nach einem Hackerangriff sind zwei Berliner Verwaltungen wieder am Netz. Es gibt jedoch weiter Verdachtsmomente für eine Infiltration.
---------------------------------------------
https://www.golem.de/news/nach-hackerangriff-berliner-senat-ueberrascht-ueb…
∗∗∗ Missbrauch von Passkeys: Phishing-Toolkit soll Passwort-Reset umgehen können ∗∗∗
---------------------------------------------
Ein ab 10.000 US-Dollar gehandeltes Phishing-Toolkit soll Angreifern über Passkeys einen dauerhaften Zugriff etwa auf gekaperte Google-Konten verleihen.
---------------------------------------------
https://www.golem.de/news/missbrauch-von-passkeys-phishing-toolkit-soll-pas…
∗∗∗ Security vets rally around $4 paper password books for sale in Australia ∗∗∗
---------------------------------------------
Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026
---------------------------------------------
https://www.theregister.com/security/2026/08/24/security-vets-rally-around-…
∗∗∗ AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a devs headphones ∗∗∗
---------------------------------------------
Sawtooth waves you cant hear still mess with your Bluetooth. Firefox and Brave say theyve got you covered
---------------------------------------------
https://www.theregister.com/security/2026/08/24/aliexpress-accused-of-finge…
∗∗∗ The curious case of the effortful fraud ∗∗∗
---------------------------------------------
How what looked like a generic phishing site seemingly turned out to be a put-some-effort-into it, targeted fraud.
---------------------------------------------
https://bytesandborscht.com/the-curious-case-of-the-effortful-fraud/
∗∗∗ Britische Regierung bestätigt Cyberattacke auf Kraftwerk ∗∗∗
---------------------------------------------
Für vier Tage haben Angreifer in Großbritannien ein Kraftwerk abgeschaltet. Die Behörden warnen und besänftigten zugleich.
---------------------------------------------
https://www.heise.de/news/Britische-Regierung-bestaetigt-Cyberattacke-auf-K…
∗∗∗ Microsoft stopft zahlreiche Cloud-Schwachstellen ∗∗∗
---------------------------------------------
Microsoft dokumentiert 18 teils kritische Sicherheitslücken in Cloud-Produkten, die die Entwickler geschlossen haben.
---------------------------------------------
https://www.heise.de/news/Microsoft-stopft-zahlreiche-Cloud-Schwachstellen-…
∗∗∗ „GTA 6“-ISO: Vermeintliche Leak-Abbilddatei voller Malware ∗∗∗
---------------------------------------------
Bösartige Akteure bieten das vermeintlich geleakte ISO von „GTA 6“ im Netz an. Die 113 GByte enthalten aufgepumpte Virendaten.
---------------------------------------------
https://www.heise.de/news/GTA-6-ISO-Vermeintliche-Leak-Abbilddatei-voller-M…
∗∗∗ Notepad++ v8.9.8 stopft 14 Sicherheitslücken ∗∗∗
---------------------------------------------
Am Sonntag hat Don Ho Version 8.9.8 des beliebten Editors Notepad++ herausgegeben. Sie schließt etwa Codeschmuggellücken.
---------------------------------------------
https://www.heise.de/news/Notepad-v8-9-8-stopft-14-Sicherheitsluecken-11423…
∗∗∗ And then the men with guns tell you to do it anyway ∗∗∗
---------------------------------------------
Perhaps you can think of a way to design an alerting system which cannot be abused - but I can't.
---------------------------------------------
https://shkspr.mobi/blog/2026/08/and-then-the-men-with-guns-tell-you-to-do-…
∗∗∗ Everything I own, owned ∗∗∗
---------------------------------------------
Over the past couple weeks I’ve been doing agent-driven reverse engineering of peripherals that happen to be within arm’s reach. From those devices, I’ve come away with a full plaintext command shell inside my microphone, a webcam whose activity LED I can switch off while it records, and a key light that hands out memory writes to anyone on the WiFi.
---------------------------------------------
https://schlarp.com/posts/everything-i-own-owned/
∗∗∗ Building certgrep.sh: a free certificate transparency search engine ∗∗∗
---------------------------------------------
Certificate transparency is one of the best public datasets in security. Every certificate issued by a publicly trusted certificate authority lands in an append-only, cryptographically verifiable log, usually before the certificate is ever used. For anyone hunting malicious infrastructure, that makes certificate transparency (CT) one of the earliest ..
---------------------------------------------
https://haveibeensquatted.com/blog/building-certgrep
=====================
= Vulnerabilities =
=====================
The Fabrik Fiasco: Announced, Restricted, Relabelled
---------------------------------------------
https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/
Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
---------------------------------------------
https://mysites.guru/blog/fabrik-4-7-2-security-release/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/