=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 24-09-2026 18:00 − Freitag 25-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ CRA - Reporting: The first two weeks ∗∗∗
---------------------------------------------
The CRA-SRP (Single Reporting Platform) started operating two weeks ago, and we now have some experience with the system. There are multiple angles to this.
---------------------------------------------
https://www.cert.at/en/blog/2026/9/cra-reporting-the-first-two-weeks
∗∗∗ Phishing-Angriffe mit echten Hotel-Buchungsdaten ∗∗∗
---------------------------------------------
Über eine Schwachstelle bei HotelNetSolutions wurden Buchungsdaten von Hotelgästen abgegriffen. Kriminelle nutzen sie für glaubhafte Phishing-Nachrichten.
---------------------------------------------
https://heise.de/-11466446
∗∗∗ Betreiber Kritischer Infrastruktur sollen in Österreich Flugdrohnen abschießen ∗∗∗
---------------------------------------------
Nähern sich verdächtige Flugdrohnen Kritischer Infrastruktur, soll deren Betreiber die Drohnen vom Himmel holen. Lizenzen dafür sind in Österreich geplant.
---------------------------------------------
https://heise.de/-11465199
∗∗∗ Bevorstehender Zero-Day-Angriff: KiteWorks drängt Kunden zur Serverabschaltung ∗∗∗
---------------------------------------------
Man habe konkrete Hinweise von Strafverfolgern auf eine Attacke, schreibt der Hersteller seinen Kunden. Auch hierzulande sind große Unternehmen betroffen.
---------------------------------------------
https://www.heise.de/news/Bevorstehender-Zero-Day-Angriff-KiteWorks-draengt…
∗∗∗ New Carbonato malware uses AI agents to hijack exposed Docker hosts ∗∗∗
---------------------------------------------
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-a…
∗∗∗ MacSync malware uses public iCloud calendars to deliver new payloads ∗∗∗
---------------------------------------------
A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-…
∗∗∗ Muse leakt Systemdateien: Metas KI-Agent gibt auf Anfrage sein Dateisystem aus ∗∗∗
---------------------------------------------
Ein Entwickler hat Metas KI-Agent Muse 6,8 GByte an Daten aus seiner Betriebsumgebung entlockt. Laut Meta ist das ein erwartetes Verhalten.
---------------------------------------------
https://www.golem.de/news/muse-leakt-systemdateien-metas-ki-agent-gibt-auf-…
∗∗∗ Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments ∗∗∗
---------------------------------------------
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-…
∗∗∗ Cloudflare Fixes Flaw That Let One Container Read Another Customers Leftover Disk Data ∗∗∗
---------------------------------------------
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.
---------------------------------------------
https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
∗∗∗ CVE flood pushes Ubuntu onto weekly kernel release cycle ∗∗∗
---------------------------------------------
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace.
---------------------------------------------
https://www.theregister.com/os-platforms/2026/09/24/cve-flood-pushes-ubuntu…
∗∗∗ Decades-old file security flaws found in Android, Linux, macOS, and Windows ∗∗∗
---------------------------------------------
Security researchers report that Microsoft considers the side-channel leak of file events to be by design.
---------------------------------------------
https://www.theregister.com/security/2026/09/24/decades-old-file-security-f…
∗∗∗ Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing ∗∗∗
---------------------------------------------
SalesBleed security flaws lead to very unexpected consequences.
---------------------------------------------
https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns…
∗∗∗ It was a matter of when, not if... ∗∗∗
---------------------------------------------
Security people always say it’s not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we’re the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked.
---------------------------------------------
https://csirt.divd.nl/2026/09/24/when-not-if/
∗∗∗ Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud ∗∗∗
---------------------------------------------
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
---------------------------------------------
https://socket.dev/blog/mini-shai-hulud-actions?utm_medium=feed
=====================
= Vulnerabilities =
=====================
∗∗∗ VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise ∗∗∗
---------------------------------------------
ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise.
---------------------------------------------
https://kb.cert.org/vuls/id/234131
∗∗∗ Sicherheitslücken: GitLab-Server mit Schadcode attackierbar ∗∗∗
---------------------------------------------
Die GitLab-Entwickler raten zur zügigen Installation der jüngst veröffentlichten Sicherheitsupdates.
---------------------------------------------
https://www.heise.de/news/Sicherheitsluecken-GitLab-Server-mit-Schadcode-at…
∗∗∗ Video-Tool VLC: Version 3.0.24 stopft über 130 Sicherheitslecks ∗∗∗
---------------------------------------------
Der Videoplayer VLC ist in Version 3.0.24 erschienen. Mehr als 130 Sicherheitslücken soll das Release schließen.
---------------------------------------------
https://heise.de/-11465305
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1096637/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 23-09-2026 18:00 − Donnerstag 24-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Theres a new way to break RSA thats faster than anything weve seen before ∗∗∗
---------------------------------------------
The world has known for decades that the RSA cryptosystem’s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold. The practical risk is limited, but still significant.
---------------------------------------------
https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-that…
∗∗∗ Hackers now exploit critical Roundcube flaw in code injection attacks ∗∗∗
---------------------------------------------
In May, the Roundcube security team patched the flaw (tracked as CVE-2026-48842), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-…
∗∗∗ A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You ∗∗∗
---------------------------------------------
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored by you.
---------------------------------------------
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
∗∗∗ Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure ∗∗∗
---------------------------------------------
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).
---------------------------------------------
https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html
∗∗∗ OpenAI-Agent knackt australisches Regierungsportal ∗∗∗
---------------------------------------------
Eine KI sollte Gesundheitsstatistiken suchen – und knackte dabei ein australisches Regierungsportal. Die Empörung ist groß.
---------------------------------------------
https://heise.de/-11463920
∗∗∗ Bypassing EDR with Local AI ∗∗∗
---------------------------------------------
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
---------------------------------------------
https://projectblack.io/blog/bypassing-edr-with-local-ai/
=====================
= Vulnerabilities =
=====================
∗∗∗ Foxit: Security updates available in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 ∗∗∗
---------------------------------------------
Foxit has released Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8, which addresses potential security and stability issues.
---------------------------------------------
https://www.foxit.com/support/security-bulletins.html
∗∗∗ Drupal Security Advisories 2026-September-23 ∗∗∗
---------------------------------------------
Drupal released 36 new security advisories (5x critical).
---------------------------------------------
https://www.drupal.org/security
∗∗∗ Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted ∗∗∗
---------------------------------------------
In SolarWinds Observability Self-Hosted 2026.2.3 haben die Entwickler eigenen Angaben zufolge zwei Schwachstellen geschlossen (CVE-2026-28324 „kritisch“ CVE-2026-28325, „hoch“). In beiden Fällen können Angreifer unter den jeweils genannten Bedingungen ohne Authentifizierung an den Schwachstellen ansetzen und Schadcode ausführen – bei CVE-2026-28324 übers Netz, bei CVE-2026-28325 nur aus einem benachbarten Netzsegment. Die Ursachen unterscheiden sich jedoch: Bei CVE-2026-28324 sind Integritätsprüfungen unzureichend; CVE-2026-28325 betrifft die Verarbeitung nicht vertrauenswürdiger Daten durch Deserialisierung. Hinweise auf laufende Attacken gibt es bislang nicht.
---------------------------------------------
https://heise.de/-11464112
∗∗∗ Imprivata Enterprise Access Management (EAM) does not rotate RSA keys ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/273940
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1096407/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 22-09-2026 18:00 − Mittwoch 23-09-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Ab 1.10: Meldepflicht für IT-Vorfälle in Österreich ∗∗∗
---------------------------------------------
Die NIS-2-Richtlinie beschert Österreich Registrierungspflichten für Unternehmen und Behörden. Diese erhalten Zuwachs: Das neue Bundesamt für Cybersicherheit.
---------------------------------------------
https://www.heise.de/news/Ab-1-10-Meldepflicht-fuer-IT-Vorfaelle-in-Oesterr…
∗∗∗ Gefälschter FinanzOnline-Mail: 3.612 Euro Steuererstattung versprochen ∗∗∗
---------------------------------------------
Mit einer neuen Variante des bekannten FinanzOnline-Phishings versuchen Kriminelle derzeit, an Bankdaten von Österreicher:innen zu gelangen. In einer gefälschten E-Mail wird eine Steuererstattung von 3.612 Euro versprochen.
---------------------------------------------
https://www.watchlist-internet.at/news/gefaelschter-finanzonline-mail/
∗∗∗ Hacker dringen in Systeme von Fresenius Medical Care ein ∗∗∗
---------------------------------------------
Medizinische Geräte, Patientenversorgung, Produktion und laufender Geschäftsbetrieb sollen laut Konzern nicht beeinträchtigt sein.
---------------------------------------------
https://www.derstandard.at/story/3000000340976/hacker-dringen-in-systeme-vo…
∗∗∗ Microsoft: September Windows updates break Always On VPN connections ∗∗∗
---------------------------------------------
Microsoft has notified IT administrators that users may experience Always On VPN connection issues after installing the September 2026 Windows 11 security updates.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-wi…
∗∗∗ Absturzgefahr: Exploit lässt Angreifer DJI-Drohnen mitten im Flug kapern ∗∗∗
---------------------------------------------
Mehrere Drohnenmodelle des Herstellers DJI sind anfällig für eine gefährliche Sicherheitslücke, die eine vollständige Kontrollübernahme ermöglicht. Nutzer sollten nach korrigierten Firmware-Versionen Ausschau halten.
---------------------------------------------
https://www.golem.de/news/per-bluetooth-exploit-laesst-angreifer-dji-drohne…
∗∗∗ Macfinger ClickFix campaign, (Tue, Sep 22nd) ∗∗∗
---------------------------------------------
I've found several legitimate websites with injected script for a campaign using the ClickFix social engineering technique. This particular ClickFix campaign was documented earlier this month on the Ransom-ISAC Blog, but it doesn't appear to have a nickname yet. Since this campaign is targeting macOS environments through a fingerprinting process, I'm calling it the "Macfinger ClickFix" campaign. No, this is not related to the MacFinger utility from decades ago. Instead, think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore.
---------------------------------------------
https://isc.sans.edu/diary/rss/33360
∗∗∗ Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape ∗∗∗
---------------------------------------------
A use-after-free in the Linux kernels AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases.
---------------------------------------------
https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html
∗∗∗ Recent Increase of Hybrid Attacks Against Defense Sector in Europe ∗∗∗
---------------------------------------------
Recently, a wave of sabotage attacks has been reported in Europe. In most cases Russia is suspected to be responsible. These events follow a broader pattern of hybrid activity directed at European infrastructure, logistics networks, and organizations supporting Ukraine.
---------------------------------------------
https://www.truesec.com/hub/blog/recent-increase-of-hybrid-attacks-against-…
∗∗∗ Iranian Cyber Espionage Campaign ∗∗∗
---------------------------------------------
An Iranian threat actor is conducting a cyber espionage campaign targeting Iranian nationals abroad. The attacker reaches out to the victim on various messaging apps, like Telegram or Whatsapp. The actor often claims to be an individual previously known to the target or technical support from the social messaging platform.
---------------------------------------------
https://www.truesec.com/hub/blog/iranian-cyber-espionage-campaign
=====================
= Vulnerabilities =
=====================
∗∗∗ Cyberangriffe auf F5 BIG-IP, Check Point Security und Arista VeloCloud ∗∗∗
---------------------------------------------
IT-Verantwortliche müssen rasch handeln, um bereitgestellte Aktualisierungen zu installieren. Mehrere IT-Sicherheitsbehörden warnen vor derzeit laufenden Angriffen auf Sicherheitslücken in F5 BIG-IP, Check Point Security Gateway und Management sowie Arista VeloCloud Orchestrator On-Premise.
---------------------------------------------
https://heise.de/-11462590
∗∗∗ Patchday: Adobe Connect ist unter Android, macOS und Windows verwundbar ∗∗∗
---------------------------------------------
Es sind wichtige Sicherheitsupdates für verschiedene Adobe-Anwendungen erschienen.
---------------------------------------------
https://heise.de/-11462802
∗∗∗ NetBSD 10.2 stopft einige Sicherheitslücken ∗∗∗
---------------------------------------------
NetBSD ist jüngst als Point-Release 10.2 erschienen. Die Entwickler schließen damit einige Sicherheitslücken.
---------------------------------------------
https://heise.de/-11463028
∗∗∗ Gleich noch ein Sicherheitsupdate für WordPress ∗∗∗
---------------------------------------------
Angreifer können WordPress dazu bringen, nicht vorgesehene .php-Dateien aufzurufen. Das kann zur Ausführung von Code führen.
---------------------------------------------
https://heise.de/-11462385
∗∗∗ Ubiquiti schließt Denial-of-Service-Lücken in Firewalls und Gateways ∗∗∗
---------------------------------------------
In UniFi-Firewalls und -Gateways klaffen hochriskante Denial-of-Service-Lücken. Aktualisierte Firmware stopft die Lecks.
---------------------------------------------
https://heise.de/-11463176
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1096191/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 21-09-2026 18:00 − Dienstag 22-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ "Bundesamt für Cybersicherheit" geht mit Oktober an den Start ∗∗∗
---------------------------------------------
Leiter Markus Kasinger war zuvor bei Austrian Power Grid. Zu den Aufgaben gehört die Weiterentwicklung der nationalen Cybersicherheitsstrategie.
---------------------------------------------
https://www.derstandard.at/story/3000000340881/bundesamt-fuer-cybersicherhe…
∗∗∗ New Windows Defender zero-day blocks Microsoft antivirus updates ∗∗∗
---------------------------------------------
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-da…
∗∗∗ Politik: EU-Kommission will Europol-Datenbefugnisse ausweiten ∗∗∗
---------------------------------------------
Ein Verordnungsentwurf sieht den Abbau von Schutzmechanismen bei Europol vor, um KI-Systeme anlasslos mit Daten zu speisen.
---------------------------------------------
https://www.golem.de/news/politik-eu-kommission-will-europol-datenbefugniss…
∗∗∗ Smart-TVs: Youtuber entfernt WLAN-Modul aus neuem LG-TV ∗∗∗
---------------------------------------------
Nach Berichten über Spionagefunktionen entfernt ein Youtuber Hardwarekomponenten aus seinem LG OLED G6. Der Fernseher funktioniert weiterhin.
---------------------------------------------
https://www.golem.de/news/smart-tvs-youtuber-entfernt-wlan-modul-aus-neuem-…
∗∗∗ Unmasking EvilTokens: Getting to the root of device code phishing ∗∗∗
---------------------------------------------
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltoke…
∗∗∗ Microsoft wirft SMS-basierte Authentifizierung aus Entra ID raus ∗∗∗
---------------------------------------------
Microsofts Identitätsverwaltung und Login-Lösung Entra ID erlaubt die Authentifizierung mit SMS. Das soll bald ein Ende haben.
---------------------------------------------
https://heise.de/-11461055
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdates: Click2Shell-Lücke zum Kompromittieren von WordPress-Websites ∗∗∗
---------------------------------------------
Aufgrund mehrerer Sicherheitslücken raten die WordPress-Entwickler zu einem zügigen Update. Bislang gibt es keine Hinweise auf Attacken.
---------------------------------------------
https://heise.de/-11460973
∗∗∗ Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access ∗∗∗
---------------------------------------------
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow
vulnerability that could result in arbitrary operating system (OS) command execution.
---------------------------------------------
https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html
∗∗∗ D-Link warns of max severity zero-day bug in DIR-822A routers ∗∗∗
---------------------------------------------
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity…
∗∗∗ New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups ∗∗∗
---------------------------------------------
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed. As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July.
---------------------------------------------
https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1096022/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 18-09-2026 18:00 − Montag 21-09-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Cyberangriff trifft Universität: LMU München bestätigt Abfluss von Studentendaten ∗∗∗
---------------------------------------------
Ein Angreifer ist an persönliche Daten von Studenten der Ludwig-Maximilians-Universität München gelangt. Auch Bankdaten sollen betroffen sein.
---------------------------------------------
https://www.golem.de/news/cyberangriff-trifft-universitaet-lmu-muenchen-bes…
∗∗∗ Hackerangriff auf die GUTcert; Kundendaten abgeflossen ∗∗∗
---------------------------------------------
Unschöne Nachricht für Kunden, die sich über die GUTcert einer Zertifizierung unterzogen haben. Der Anbieter ist Opfer eines Hackerangriffs geworden, bei dem auch Kundendaten abgeflossen sind. Betroffene scheinen vom Unternehmen gerade informiert zu werden, wie ein Leser mir heute mitteilte.
---------------------------------------------
https://borncity.com/blog/2026/09/20/hackerangriff-auf-die-gutcert-kundenda…
∗∗∗ Gyazo server flaw exploited to steal 23.6 million user records ∗∗∗
---------------------------------------------
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-…
∗∗∗ ShinyHunters hacks Clop leak site, threatens to extort ransomware gang ∗∗∗
---------------------------------------------
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operations data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak…
∗∗∗ North Korean WaterPlum hackers infected 30,000 devices worldwide ∗∗∗
---------------------------------------------
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hacke…
∗∗∗ Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO ∗∗∗
---------------------------------------------
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.
---------------------------------------------
https://securelist.com/tr/payload-ransomware-via-group-policy/121335/
∗∗∗ CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories ∗∗∗
---------------------------------------------
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
---------------------------------------------
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
∗∗∗ TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
---------------------------------------------
https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
∗∗∗ Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation ∗∗∗
---------------------------------------------
GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable intrusions we observed including the theft of more than 18,000 sensitive records from a western government.
---------------------------------------------
https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-gover…
∗∗∗ EU prüft OpenAI nach nicht gemeldetem Sicherheitsvorfall ∗∗∗
---------------------------------------------
Nach einem Vorfall beim Software-Register RubyGems meldete OpenAI diesen nicht der EU. Die europäischen Behörden prüfen nun die Einhaltung des AI Acts.
---------------------------------------------
https://heise.de/-11458971
∗∗∗ Cisco Zero-Day Highlights API Endpoint Authentication Issues ∗∗∗
---------------------------------------------
The authentication bypass flaw CVE-2026-76460 impacts Ciscos Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
---------------------------------------------
https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endp…
=====================
= Vulnerabilities =
=====================
∗∗∗ Behörde warnt: Angriffe auf Lücken im Linux-Kernel beobachtet ∗∗∗
---------------------------------------------
Die Cisa warnt vor laufenden Angriffen auf Linux-Systeme über drei gefährliche Sicherheitslücken in Kernel-Komponenten. Korrekturen sind verfügbar.
---------------------------------------------
https://www.golem.de/news/behoerde-warnt-angriffe-auf-luecken-im-linux-kern…
∗∗∗ Synology warnt: Kritische NAS-Lücken ermöglichen Datenklau ∗∗∗
---------------------------------------------
Angreifer können durch mehrere Sicherheitslücken lesend und schreibend auf NAS-Geräte von Synology zugreifen. Patches sind verfügbar.
---------------------------------------------
https://www.golem.de/news/synology-warnt-kritische-nas-luecken-ermoeglichen…
∗∗∗ Werbeblocker Pi-hole: Update stopft Codeschmuggel-Lücken ∗∗∗
---------------------------------------------
Ein Update für den DNS-basierten Werbeblocker Pi-hole schließt teils hochriskante Codeschmuggel-Lücken.
---------------------------------------------
https://www.heise.de/news/Werbeblocker-Pi-hole-Update-stopft-Codeschmuggel-…
∗∗∗ Fremdzugriffe auf SolarWinds Access Rights Manager vorstellbar ∗∗∗
---------------------------------------------
Ein Sicherheitspatch schließt eine Schwachstelle in SolarWinds Access Rights Manager. Bislang gibt es keine Hinweise auf Attacken.
---------------------------------------------
https://heise.de/-11459978
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1095702/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 17-09-2026 18:00 − Freitag 18-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Schockanrufe: Wenn Angst und Zeitdruck zur Falle werden ∗∗∗
---------------------------------------------
In einer bundesweiten Kampagne informiert das Bundeskriminalamt gemeinsam mit Partnerorganisationen über die zunehmende Gefahr sogenannter Schockanrufe. Dabei werden nicht nur die Methoden organisierter Tätergruppen näher beleuchtet, zusätzlich gibt es auch Tipps, wie Sie Schockanrufe frühzeitig erkennen und richtig reagieren. Ziel der Kampagne ist es, insbesondere ältere Menschen sowie deren Angehörige für die Methoden organisierter Tätergruppen zu sensibilisieren.
---------------------------------------------
https://www.watchlist-internet.at/news/schockanrufe/
∗∗∗ New RatHat Android malware uses AI to automate device control ∗∗∗
---------------------------------------------
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-u…
∗∗∗ Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer ∗∗∗
---------------------------------------------
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-…
∗∗∗ Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files ∗∗∗
---------------------------------------------
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.
---------------------------------------------
https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
∗∗∗ Researchers find way to listen in on headphones from afar ∗∗∗
---------------------------------------------
Eves dropping in on Alice and Bob
---------------------------------------------
https://www.theregister.com/security/2026/09/17/researchers-find-way-to-lis…
∗∗∗ Supply-Chain-Angriff: Quellcode von CrowdSec durch Unbekannte ausgeleitet ∗∗∗
---------------------------------------------
Vor vier Monaten gelangten über dreihundert Repositories in fremde Hände. Doch die Auswirkungen des Angriff von Mai schätzt der WAF-Hersteller als gering ein.
---------------------------------------------
https://www.heise.de/news/Supply-Chain-Angriff-Quellcode-von-CrowdSec-durch…
∗∗∗ Nordkoreanische Cybergruppe bestiehlt IT-Fachleute auf Jobsuche ∗∗∗
---------------------------------------------
Sicherheitsbehörden warnen vor einer Cybergruppe aus Nordkorea, die gezielt IT-Spezialisten angreift. Was hinter der Kampagne „Contagious Interview“ steckt.
---------------------------------------------
https://heise.de/-11458275
∗∗∗ Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation ∗∗∗
---------------------------------------------
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.
---------------------------------------------
https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
=====================
= Vulnerabilities =
=====================
∗∗∗ Root-Sicherheitslücke gefährdet Check Point Security Management and Log Servers ∗∗∗
---------------------------------------------
Ein Sicherheitsupdate schließt eine kritische Schadcode-Schwachstelle in Check Point Security Management and Log Servers.
---------------------------------------------
https://www.heise.de/news/Root-Sicherheitsluecke-gefaehrdet-Check-Point-Sec…
∗∗∗ Jetzt aktualisieren: Angreifer konnten beliebige Daten von Synology-NAS auslesen ∗∗∗
---------------------------------------------
Gleich auf drei verschiedenen Wegen konnten Angreifer Daten von Synology-NAS klauen. Der Hersteller behebt mit einem Flicken auch weniger dringende Lücken.
---------------------------------------------
https://www.heise.de/news/Jetzt-aktualisieren-Angreifer-konnten-beliebige-D…
∗∗∗ 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS ∗∗∗
---------------------------------------------
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.
---------------------------------------------
https://www.wordfence.com/blog/2026/09/100000-wordpress-sites-exposed-to-re…
∗∗∗ Atlassian: Angreifer können Confluence Data Center ausspionieren ∗∗∗
---------------------------------------------
Atlassian hat zahlreiche Sicherheitslücken in Bitbucket, Jira & Co. geschlossen. Admins sollten die verfügbaren Sicherheitspatches zeitnah
installieren.
---------------------------------------------
https://heise.de/-11458267
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1095219/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 16-09-2026 18:00 − Donnerstag 17-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Fake-Webseiten: Kriminelle kopieren den Online-Auftritt echter Hotels ∗∗∗
---------------------------------------------
Die Absicht ist klar, die momentane Häufung hingegen ein wenig ungewöhnlich. In den letzten Wochen wurden besonders viele Fake-Webseiten gemeldet, die gezielt den Onlineauftritt von (Familien-)Hotels kopieren. Kriminelle wollen damit vorrangig an Kontaktdaten ihrer Opfer gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-webseiten-echte-hotels/
∗∗∗ Cisco warns of max severity ISE zero-day exploited in attacks ∗∗∗
---------------------------------------------
The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration. [..] Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-serv…
∗∗∗ EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats ∗∗∗
---------------------------------------------
European Commission President Ursula von der Leyen has proposed an Emergency Security Protocol that would allow any European Union member state to trigger a coordinated response to security incidents including cyberattacks, sabotage and drone incursions. [..] Under the proposed Emergency Security Protocol, a single member state could trigger the mechanism, prompting all 27 EU governments to convene. The proposed framework would be designed to coordinate a European response, deter further escalation and mitigate the consequences of an incident.
---------------------------------------------
https://thecyberexpress.com/eu-emergency-security-protocol-targets-threats/
∗∗∗ OpenAI führt Framework zur Meldung von KI-Sicherheitsvorfällen ein ∗∗∗
---------------------------------------------
OpenAI will dem Fehlverhalten seiner eigenen KI-Modelle systematischer auf den Grund gehen. Hierzu wurde jetzt ein neues Framework vorgestellt, das solche Fälle systematisch verfolgen, untersuchen und offenlegen soll. Bislang hatte das US-Unternehmen solche Sicherheitsvorfälle nur auf Ad-hoc-Basis bekanntgegeben. Im dazugehörigen Blogpost bekräftigt OpenAI zugleich Forderungen nach einer Verlangsamung der KI-Weiterentwicklung, wie sie zuletzt auch vom Rivalen Anthropic erhoben wurden, um den Sicherheitsrisiken Rechnung zu tragen, die aus den Fortschritten in der KI erwachsen.
---------------------------------------------
https://www.heise.de/news/OpenAI-fuehrt-Framework-zur-Meldung-von-KI-Sicher…
∗∗∗ The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents ∗∗∗
---------------------------------------------
During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper. This report details the new crimeware campaign that began with the mass infection of users via compromised torrent tracker file storage. [..] Further analysis of the attack revealed that the threat actors did not compromise the torrent trackers themselves. Instead, they compromised a widely used public repository of torrent files — itorrents[.]org.
---------------------------------------------
https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/
∗∗∗ Revolut phishing texts appear days after data breach ∗∗∗
---------------------------------------------
Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.
---------------------------------------------
https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-tex…
∗∗∗ Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilins AI use ∗∗∗
---------------------------------------------
In Japan, The Gentlemen was the most active ransomware group in the first half of 2026. Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year.
---------------------------------------------
https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-fir…
∗∗∗ GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk ∗∗∗
---------------------------------------------
GitHub has added cache-mode to GitHub Actions, a new setting that limits how workflows and jobs can access the Actions cache. It targets cache poisoning, the technique attackers used to compromise the Ultralytics PyPI package in 2024 and the TanStack npm packages in May 2026.
---------------------------------------------
https://socket.dev/blog/github-actions-cache-mode
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone ∗∗∗
---------------------------------------------
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. CVE-2026-81642
---------------------------------------------
https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.ht…
∗∗∗ BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS ∗∗∗
---------------------------------------------
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature.
---------------------------------------------
https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.ht…
∗∗∗ Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2026-013
∗∗∗ Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2022-005
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094962/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 15-09-2026 18:00 − Mittwoch 16-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Account-Takeover: Tanz-Voting-Masche hat wieder WhatsApp-Konten im Visier ∗∗∗
---------------------------------------------
Eine aus dem Vorjahr bekannte Falle wird aktuell verstärkt ausgespielt. Kriminelle versenden über gehackte WhatsApp-Accounts Nachrichten, die zur Teilnahme an einem Voting drängen. Ziel ist die Übernahme weiterer Konten, die später für den Versand verschiedenster Phishing-Messages missbraucht werden. Was ein Zahnarztbesuch mit der ganzen Sache zu tun hat, verrät der Artikel.
---------------------------------------------
https://www.watchlist-internet.at/news/account-takeover-whatsapp-konten/
∗∗∗ Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites ∗∗∗
---------------------------------------------
Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites. After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-p…
∗∗∗ Windows Server 2022 reaches end of mainstream support next month ∗∗∗
---------------------------------------------
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches…
∗∗∗ Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works ∗∗∗
---------------------------------------------
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.
---------------------------------------------
https://www.wired.com/story/hackers-flock-camera-data-shows-how-system-work…
∗∗∗ Atomic macOS (AMOS) Stealer Activity ∗∗∗
---------------------------------------------
This article reviewed an Atomic stealer malware infection from early August 2026. The resulting analysis includes behavior from the infected macOS host, malware samples, post-infection artifacts and traffic patterns that indicate the types of information collected by this malware.
---------------------------------------------
https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/
∗∗∗ Securing the unpatchable in an age of AI-driven vulnerabilities ∗∗∗
---------------------------------------------
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.
---------------------------------------------
https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai…
∗∗∗ Angreifer attackieren Acronis Backup für cPanel/WHM und Plesk ∗∗∗
---------------------------------------------
Aufgrund von laufenden Attacken müssen Admins Acronis Backup für cPanel/WHM und Plesk aktualisieren.
---------------------------------------------
https://heise.de/-11454681
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco Security Advisories 2026 Sep 16 ∗∗∗
---------------------------------------------
Cisco has release 13 new CRITICAL security advisories for Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard.
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/publicationListing.x
∗∗∗ Oracle Critical Security Patch Update Advisory - September 2026 ∗∗∗
---------------------------------------------
This Critical Security Patch Update contains 673 new security patches across the product families listed below.
---------------------------------------------
https://www.oracle.com/security-alerts/cspusep2026.html
∗∗∗ Google Pixel owners urged to patch actively exploited modem flaw ∗∗∗
---------------------------------------------
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
---------------------------------------------
https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094720/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 14-09-2026 18:00 − Dienstag 15-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Eine Phishing-Mail, vier Fallen, drei Sprachen – Wenn Kriminelle schlampig arbeiten ∗∗∗
---------------------------------------------
Betrugsmaschen im Namen von FinanzOnline gehören zu den absoluten Dauerbrennern und werden laufend gemeldet. Weil den Kriminellen bei der Erstellung einer aktuellen Masche aber einige Fehler unterlaufen sind, bleiben die dazugehörigen Erfolgsaussichten relativ gering. Analyse eines betrügerischen Hoppalas.
---------------------------------------------
https://www.watchlist-internet.at/news/wenn-kriminelle-schlampig-arbeiten/
∗∗∗ Twitch extension with 30K installs exposes users’ OAuth tokens ∗∗∗
---------------------------------------------
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users Twitch OAuth session tokens to a commercial bot service.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-in…
∗∗∗ Confidential Computing gebrochen: DDRop-Angriff ermöglicht Datenklau in der Cloud ∗∗∗
---------------------------------------------
Damit DDRop erfolgreich ausgeführt werden kann, ist ein physischer Zugriff auf die Serverhardware erforderlich, um das von den Forschern entwickelte Interposer-Gerät zu installieren. [..] Hinter DDRop steckt ein Team aus neun Sicherheitsforschern von Google, der ETH Zürich, der KU Leuven sowie der Durham University. Sie entwickelten ein Gerät, das für den Angriff erforderlich ist. [..] Wie die Forscher auf einer Informationsseite zu DDRop schildern, kann das Gerät Schreibvorgänge im Arbeitsspeicher "verschwinden lassen", indem es absichtlich einen Paritätsfehler einschleust. Dadurch soll das Speichermodul die Schreibbefehle verwerfen, wovon der Prozessor aber wohl nichts mitbekommt.
---------------------------------------------
https://www.golem.de/news/confidential-computing-gebrochen-ddrop-angriff-er…
∗∗∗ The Ghost in the Chat: how a bot that isn't in your group steals messages from Telegram HTML exports ∗∗∗
---------------------------------------------
A stored XSS in Telegram Desktop's HTML export pipeline lets a bot that never joins your group plant invisible JavaScript in an inline keyboard button. The payload sleeps in message history for months and detonates the moment a participant exports the chat and opens the HTML file — every message rendered in that document can be shipped to the attacker's server, and the page itself can be rewritten. [..] Telegram shipped a fix in July, but the app update does not update files exported with earlier versions, so old HTML exports can still carry the script.
---------------------------------------------
https://expatch.com/writeups/telegram-html-export-xss.html
∗∗∗ HBO Max Reddit account compromised to serve ClickFix attacks ∗∗∗
---------------------------------------------
Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max.
---------------------------------------------
https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-c…
∗∗∗ Angriff auf Verschlüsselung: Netzrechtler fordern EU-Eingreifen gegen Kanada ∗∗∗
---------------------------------------------
Ein internationales Bündnis aus Zivilgesellschaft und Datenschutzorganisationen wendet sich in einem offenen Brief an die EU-Spitze. Anlass ist Kanadas umstrittener Gesetzentwurf C-22 (Lawful Access Act), der vor dem Beschluss im Senat steht. Was wie eine nationale Angelegenheit wirkt, entpuppt sich laut dem Schreiben als extraterritorialer Zugriff auf die digitale Sicherheit auch in Europa. [..] Besonders alarmierend ist laut der Allianz die Gefährdung der Ende-zu-Ende-Verschlüsselung – ähnlich wie bei der in der EU diskutierten Chatkontrolle.
---------------------------------------------
https://heise.de/-11452910
∗∗∗ LG äußert sich zu Vorwürfen bezüglich Smart-TV-Tracking ∗∗∗
---------------------------------------------
LG hat auf die Untersuchung von Gamers Nexus zu Smart-TVs reagiert. Der Hersteller erläutert die ACR-Funktion, bleibt bei vielen Vorwürfen jedoch vage.
---------------------------------------------
https://heise.de/-11452996
∗∗∗ 1.1.1.1 prüft DNS jetzt mit Post-Quanten-Kryptografie ∗∗∗
---------------------------------------------
Cloudflare hat ML-DSA-44-Validierung für seinen DNS-Resolver 1.1.1.1 aktiviert. [..] Mit der Resolver-Validierung ist noch keine vollständige Post-Quanten-DNSSEC-Kette verfügbar. Dafür müssten autoritative Nameserver Zonen mit ML-DSA-44 signieren, Registrare die passenden DS-Records annehmen und Registries sie in den übergeordneten Zonen veröffentlichen. Schließlich müsste auch die Root-Zone den Algorithmus unterstützen und ihr Post-Quanten-Schlüssel als Vertrauensanker in Resolvern hinterlegt sein.
---------------------------------------------
https://heise.de/-11453315
∗∗∗ Revolut-Datenleck: Hacker nutzen echte Behörden-Domain für Diebstahl ∗∗∗
---------------------------------------------
Ein raffinierter Betrug trifft die Neobank Revolut: Über eine verifizierte Regierungs-Domain erbeuteten Hacker sensible Kundendaten und erpressen nun Opfer.
---------------------------------------------
https://heise.de/-11453866
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar ∗∗∗
---------------------------------------------
In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461
---------------------------------------------
https://www.cert.at/de/warnungen/2026/9/kritische-sicherheitslucke-in-cisco…
∗∗∗ Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Apple Updates Everything, (Mon, Sep 14th) ∗∗∗
---------------------------------------------
https://isc.sans.edu/diary/rss/33336
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094469/
∗∗∗ Mozilla Foundation Security Advisories September 15, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 11-09-2026 18:00 − Montag 14-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent ∗∗∗
---------------------------------------------
On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118. [..] The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-po…
∗∗∗ Security through obscurity is dead, and AI delivered the fatal blow ∗∗∗
---------------------------------------------
The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. [..] During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS).
---------------------------------------------
https://www.theregister.com/security/2026/09/13/security-through-obscurity-…
∗∗∗ Perfect-10 GitLab bug under attack days after patch lands ∗∗∗
---------------------------------------------
CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10.
---------------------------------------------
https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under…
∗∗∗ Wie ein Wiener eine KI-Spionagesoftware von Anthropic stoppte ∗∗∗
---------------------------------------------
Künstliche Intelligenz lud Schadsoftware auf eine Plattform mit Millionen Nutzern. Ein Cybersicherheitsforscher aus Österreich verhinderte, dass sie sich weiter verbreiten konnte.
---------------------------------------------
https://www.derstandard.at/story/3000000339589/wie-ein-wiener-eine-ki-spion…
∗∗∗ Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection ∗∗∗
---------------------------------------------
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
---------------------------------------------
https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-iden…
∗∗∗ Webseite BGP.Exchange kompromittiert (12. Sept. 2026) ∗∗∗
---------------------------------------------
Der Anbieter der Seite BGP.Exchange ist gehackt worden, die Webseite ist kompromittiert. Zum 12. September 2026 zeigt die Webseite ein "Defacement" und es wird wohl auch "Schund" über deren Mail-System verschickt.
---------------------------------------------
https://borncity.com/blog/2026/09/12/webseite-bgp-exchange-kompromittiert-1…
∗∗∗ Datenleck: Revolut gibt sensible Nutzerdaten an Angreifer ∗∗∗
---------------------------------------------
ie Bank ist auf eine gefälschte Datenanforderung einer angeblichen Behörde hereingefallen und hat sensible Kundendaten (Ausweiskopien etc.) an Betrüger herausgegeben. [..] Die potenziell offengelegten Daten umfassen Kopien von Pässen und Führerscheinen, Selfies zur Identitätsprüfung sowie persönliche Informationen (Namen, Geburtsdaten, Berufe, Postadressen, E-Mail-Adressen und Telefonnummern). Auch finanzielle Daten (IBAN, Kontoauszüge und vollständige Transaktionshistorien, einschließlich Bitcoin-Operationen) sind angeblich betroffen.
---------------------------------------------
https://borncity.com/blog/2026/09/13/datenleck-revolut-gibt-sensible-nutzer…
∗∗∗ The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37] ∗∗∗
---------------------------------------------
Until May 2025, I liked PGP, and the GNU Privacy Guard. I poked at it in my free time a lot. One day, that suddenly changed, when I flew too close to the sun and ended up uncovering a vulnerability that allows you to easily spoof a PGP signature when opened naively with the GPG tool. [..] I disclosed these a few weeks before 39c3 in December 2025. And while some of the vulnerabilities - like the memory corruption in the message parser - got addressed properly, this was not the case for all of them.
---------------------------------------------
https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-discl…
=====================
= Vulnerabilities =
=====================
∗∗∗ LWN: Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1094211/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/