=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 07-10-2026 18:00 − Donnerstag 08-10-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Pensionsleistung genehmigt: 723-Euro-Versprechen ist Phishing ∗∗∗
---------------------------------------------
Betrügerische Nachrichten im Namen der Pensionsversicherung gab es schon vor einiger Zeit per SMS, jetzt landen sie auch im E-Mail-Postfach. Die Masche: Eine angebliche Auszahlung soll Empfänger:innen zur Preisgabe ihrer Bankdaten bringen.
---------------------------------------------
https://www.watchlist-internet.at/news/pensionsleistung-genehmigt-723-euro/
∗∗∗ Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia ∗∗∗
---------------------------------------------
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself.
---------------------------------------------
https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html
∗∗∗ Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers ∗∗∗
---------------------------------------------
Quoth the LLM, More and more.
---------------------------------------------
https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-securi…
∗∗∗ 16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials ∗∗∗
---------------------------------------------
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
---------------------------------------------
https://socket.dev/blog/firefox-crypto-wallet-stealers?utm_medium=feed
∗∗∗ TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack ∗∗∗
---------------------------------------------
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
---------------------------------------------
https://socket.dev/blog/tensorlake-compromise?utm_medium=feed
∗∗∗ Chinesische Wechselrichter: Nur ein Hack bis zum Blackout ∗∗∗
---------------------------------------------
250.000 Solaranlagen in Deutschland nutzen Wechselrichter mit einer kritischen Sicherheitslücke. Ein Kollaps des Stromnetzes wäre einfach.
---------------------------------------------
https://www.golem.de/news/chinesische-wechselrichter-nur-ein-hack-bis-zum-b…
∗∗∗ Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely ∗∗∗
---------------------------------------------
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available.
---------------------------------------------
https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco warns of critical flaws allowing Nexus switch takeover ∗∗∗
---------------------------------------------
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaw…
∗∗∗ Veeam stopft Schadcode-Lücke in Backup & Replication ∗∗∗
---------------------------------------------
Veeam hat Backup & Replication aktualisiert und dabei vier Sicherheitslücken geschlossen. Schmuggeln von Schadcode auf den Server ist möglich.
---------------------------------------------
https://www.heise.de/news/Veeam-stopft-Schadcode-Luecke-in-Backup-Replicati…
∗∗∗ Microsoft, Adobe, Apple, and Foxit vulnerabilities ∗∗∗
---------------------------------------------
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.
---------------------------------------------
https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerab…
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1099388/
∗∗∗ Zahlreiche kritische Schwachstellen in mehreren TP-Link Geräteserien ∗∗∗
---------------------------------------------
https://sec-consult.com/de/vulnerability-lab/advisory/zahlreiche-kritische-…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 06-10-2026 18:00 − Mittwoch 07-10-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Betrug in zwei Akten: Die nächste Runde im Klimabonus-Phishing ∗∗∗
---------------------------------------------
Sie hat sich als neuer Stammgast in unseren Warnmeldungen etabliert: Die Klimabonus-Phishingattacke. In der aktuellen Welle stehen nicht vordergründig Geld oder Kontozugriff im Mittelpunkt. Im ersten Schritt geht es zunächst um das Abgreifen sensibler Daten. Im zweiten Schritt läutet dann das Telefon. Am anderen Ende: Die Kriminellen.
---------------------------------------------
https://www.watchlist-internet.at/news/datenfalle-naechste-runde-klimabonus/
∗∗∗ Hackers obtain counterfeit TLS certificates for Google and other large services ∗∗∗
---------------------------------------------
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.
---------------------------------------------
https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-cer…
∗∗∗ Ninja Forms plugin flaw exploited to hack WordPress sites ∗∗∗
---------------------------------------------
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-expl…
∗∗∗ Hackers exploit critical Atlassian flaw after public PoC release ∗∗∗
---------------------------------------------
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [..] In a security advisory on Monday, Atlassian warned system administrators managing self-hosted instances to apply the security updates as soon as possible, noting it cannot determine whether individual customer instances have been compromised.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atl…
∗∗∗ Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.
---------------------------------------------
https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
∗∗∗ FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks ∗∗∗
---------------------------------------------
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries.
---------------------------------------------
https://www.theregister.com/security/2026/10/07/fortibleed-still-a-bleeding…
∗∗∗ KVM 0-Day-Schwachstelle ermöglicht Host-Zugriff ∗∗∗
---------------------------------------------
Ein Sicherheitsforscher will eine 0-Day-Schwachstelle aufgedeckt haben, die einen Ausbruch aus KVM auf den Host ermöglicht. Meinen Informationen nach hat ein weiterer Sicherheitsforscher das Ganze bestätigt. Eine CVE-Nummer gibt es m.W. noch nicht. [..] Derzeit sind aber noch keine Details bekannt (welche Linux-Kernel-Versionen betroffen sind), und es gibt noch keinen CVE. Auch ist der Exploit nicht öffentlich, und es gibt keine bestätigte Ausnutzung in der Praxis. Vercel kündigt einen vollständigen technischen Bericht an.
---------------------------------------------
https://borncity.com/blog/2026/10/06/kvm-0-day-schwachstelle-ermoeglicht-ho…
∗∗∗ Sicherheitslücke in Sungrow-Komponente ermöglichte Solaranlagen abzuschalten ∗∗∗
---------------------------------------------
Viele Solaranlagen weltweit, aber auch in Deutschland, verwenden Wechselrichter und Bauteile der chinesischen Anbieter Huawei und Songrow (ist billiger als SMA). Und natürlich muss alles "in der Cloud" der betreffenden Anbieter hängen. Beim chinesischen Anbieter Sungrow nennt sich die Cloud iSolarCloud. Einem aufmerksamen Sicherheitsforscher ist aufgefallen, dass er über eine Schwachstelle die Kontrolle über europäische Solaranlagen mit ca. 10 Gigawatt Nennleistung erlangen konnte.
---------------------------------------------
https://borncity.com/blog/2026/10/07/sicherheitsluecke-in-sungrow-komponent…
=====================
= Vulnerabilities =
=====================
∗∗∗ SonicWall warns of max severity SSRF flaw in SMA1000 gateways ∗∗∗
---------------------------------------------
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-sever…
∗∗∗ WordPress 7.1.3 Maintenance and Security Release ∗∗∗
---------------------------------------------
https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1099202/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 05-10-2026 18:00 − Dienstag 06-10-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Breite Betrugswellen: Trojaner- und Phishing-Attacken im Namen der WKO ∗∗∗
---------------------------------------------
Momentan sind besonders viele Betrugsversuche im Namen der Wirtschaftskammer Österreich unterwegs. Die Kriminellen gehen dabei zweigleisig vor: Sie wollen sowohl Schadsoftware auf die Endgeräte ihrer Opfer schleusen als auch deren Login-Daten für das WKO-Portal abgreifen. Ein (unvollständiger) Überblick über aktuelle Fallen.
---------------------------------------------
https://www.watchlist-internet.at/news/breite-betrugswellen-wko/
∗∗∗ Nach Sicherheitsvorfall: Vorsicht vor touriDat-Hotelbuchungs-Phishing ∗∗∗
---------------------------------------------
Der nächste Fall aus der Hotel-Buchungs-/Reisebranche, bei dem Buchungsdaten in Phishing-Nachrichten genutzt werden, um Opfer zu täuschen. Dieses Mal trifft es die touriDat-Plattform, deren Nutzer mit Phishing-Mails und oder WhatsApp-Phishing-Nachrichten kontaktiert werden, um Zahlungsdaten zu ergattern.
---------------------------------------------
https://borncity.com/blog/2026/10/06/nach-sicherheitsvorfall-vorsicht-vor-t…
∗∗∗ OpenAI agents tried to hack Wikipedia tools and flooded it with traffic ∗∗∗
---------------------------------------------
The publisher of Wikipedia said Monday that OpenAI agents attempted to hack a note-taking tool it hosts, made unauthorized edits, and sent millions of resource-intensive requests to its infrastructure, in the latest instance of OpenAI systems taking harmful and potentially dangerous actions.
---------------------------------------------
https://arstechnica.com/security/2026/10/openai-agents-tried-to-hack-wikipe…
∗∗∗ Rejetto HFS servers now actively scanned for critical RCE flaw ∗∗∗
---------------------------------------------
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [..] CVE-2026-61500, first published on July 13, 2026, is a session-cookie signing weakness and leakage issue fixed in Rejetto HFS version 3.2.1.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-acti…
∗∗∗ More RMM Tools In the Wild, (Tue, Oct 6th) ∗∗∗
---------------------------------------------
It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found another one.
---------------------------------------------
https://isc.sans.edu/diary/rss/33400
∗∗∗ ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits ∗∗∗
---------------------------------------------
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browsers cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
---------------------------------------------
https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
∗∗∗ Inside RevStealers Sandbox-Aware Anti-Analysis System ∗∗∗
---------------------------------------------
We recently came across an interesting Joe Sandbox analysis on Joe Sandbox Cloud Basic that was confirmed as malicious but showed surprisingly little malicious behavior. Samples like this are often particularly interesting because limited activity does not necessarily mean that execution failed.
---------------------------------------------
https://www.joesecurity.org/blog/6469689575970038406
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products ∗∗∗
---------------------------------------------
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each products web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.
---------------------------------------------
https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
∗∗∗ Kritische Auth-Bypass-Schwachstelle CVE-2026-103956 (CVSS 10.0) in Loom for AWS ∗∗∗
---------------------------------------------
Eine kritische Schwachstelle führte dazu, dass Dritte ohne Authentifizierung auf Loom for AWS zugreifen konnten. Die kritische Auth-Bypass-Schwachstelle CVE-2026-103956 wurde mit einem CVSS Base-Score von 10.0 klassifiziert. [..] Wer Loom for AWS verwendet, sollten auf die Version 1.6.1 oder höher upgraden.
---------------------------------------------
https://borncity.com/blog/2026/10/06/kritische-auth-bypass-schwachstelle-cv…
∗∗∗ LibreOffice und OpenOffice: Warnung vor Codeschmuggel-Lücke, Updates kommen ∗∗∗
---------------------------------------------
In den Bürosoftwarepaketen LibreOffice und OpenOffice klafft eine hochriskante Sicherheitslücke, durch die Angreifer mit manipulierten Dokumenten Schadcode einschleusen können. LibreOffice stopft außerdem weitere Sicherheitslücken.
---------------------------------------------
https://heise.de/-11477059
∗∗∗ Android-Patchday: Google stopft sieben kritische Löcher ∗∗∗
---------------------------------------------
https://www.golem.de/news/android-patchday-google-stopft-sieben-kritische-l…
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1098979/
∗∗∗ Mozilla Foundation Security Advisories October 6, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
∗∗∗ Libreswan: IKEv2 Use-After-Free bug when using IKE-over-TCP ∗∗∗
---------------------------------------------
https://libreswan.org/security/CVE-2026-94453/CVE-2026-94453.txt
∗∗∗ Zyxel security advisory for command injection vulnerability in the WiFi SSID field of certain DSL/Ethernet CPE, fiber ONTs, and Wireless Extenders ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
∗∗∗ Veeam: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 ∗∗∗
---------------------------------------------
https://www.veeam.com/kb4934
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 02-10-2026 18:00 − Montag 05-10-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Cyberangriff: Antriebssystem eines Öl-Supertankers gehackt ∗∗∗
---------------------------------------------
Unbekannte haben offenbar im Sommer Zugriff auf das Antriebssystem eines Öl-Supertankers gehabt, als dieser sich der Küste des US-Bundestaats Texas näherte. Das berichtet Transport Topics unter Berufung auf nicht näher genannte Quellen bei US-Behörden. Der Vorfall, der als Cyberangriff eingestuft wird, wird demnach von der US-Bundespolizei FBI sowie der US-Küstenwache untersucht.
---------------------------------------------
https://www.golem.de/news/cyberangriff-antriebssystem-eines-oel-supertanker…
∗∗∗ OpenAI alerts 100+ orgs that its misaligned models attempted to break in - or worse ∗∗∗
---------------------------------------------
OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially problematic model activity.
---------------------------------------------
https://www.theregister.com/security/2026/10/02/openai-alerts-100-orgs-that…
∗∗∗ Create automatic IP blocklist in OPNsense based on MISP data ∗∗∗
---------------------------------------------
This blog post is about creating an automatic IP blocklist in OPNsense based on MISP data, including data retention.
---------------------------------------------
https://lithilion.at/blog/2026-10-misp-blocklisting.html
∗∗∗ Nach Muse: Auch ChatGPT-App für macOS war angreifbar ∗∗∗
---------------------------------------------
Agentische Tools, die direkt auf dem Rechner laufen, benötigen oft weitreichende Zugriffsrechte. Das macht sie potenziell angreifbar. Nachdem der macOS-Security-Spezialist Patrick Wardle kürzlich eine potenziell durch Dritte ausnutzbare Hintertür in Metas Muse-App für den Mac entdeckt hatte, warnt dieser nun vor einem ähnlichen Problem in der konkurrierenden ChatGPT-App für macOS von OpenAI: Auch hier war es Angreifern möglich, sensible Informationen abzugreifen. [..] OpenAI hat das Problem Ende September mit einer Aktualisierung behoben, nachdem Wardle das Unternehmen darüber informiert hatte.
---------------------------------------------
https://www.heise.de/news/Nach-Muse-Auch-ChatGPT-App-fuer-macOS-war-angreif…
∗∗∗ Raiffeisen-Phishing: Vorsicht bei Mitteilung zu neuem Dauerauftrag ∗∗∗
---------------------------------------------
Aktuell kursiert eine Phishing-Mail im Namen von Raiffeisen. Sie behauptet, ein neuer Dauerauftrag sei eingerichtet worden und müsse geprüft werden. Wer dem Link folgt, landet auf einer gefälschten Seite und soll dort seine Daten preisgeben.
---------------------------------------------
https://www.watchlist-internet.at/news/raiffeisen-mail-zu-dauerauftrag/
∗∗∗ N0n ransomware: what you need to know ∗∗∗
---------------------------------------------
N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow.
---------------------------------------------
https://www.fortra.com/blog/n0n-ransomware-what-you-need-know
∗∗∗ Japan Plans Major Cyber Hunt to Detect Hidden Attacks on Critical Infrastructure ∗∗∗
---------------------------------------------
Japan is stepping up its plans to find cyber attackers who may already be inside the networks that keep essential services running. Under a new fiscal 2027 initiative, the government plans to work with private companies to strengthen Japan threat hunting across critical infrastructure, including power utilities and telecommunications operators.
---------------------------------------------
https://thecyberexpress.com/japan-threat-hunting-plan/
∗∗∗ Google Suspends Open Source Bug Bounty Over AI-Generated Reports ∗∗∗
---------------------------------------------
Google has suspended its Open Source Software Vulnerability Rewards Program (OSS VRP), a vulnerability search initiative that paid researchers for finding flaws in the companys open-source software. The pause took effect on October 1, 2026. Google blamed a "significant rise" in automated and AI-generated reports, most of which turned out to be invalid.
---------------------------------------------
https://thecyberexpress.com/google-pauses-oss-vrp-over-ai-submissions/
=====================
= Vulnerabilities =
=====================
∗∗∗ New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline ∗∗∗
---------------------------------------------
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0." [..] For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP).
---------------------------------------------
https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html
∗∗∗ Microsoft schiebt Exchange-Update nach ∗∗∗
---------------------------------------------
Zum Wochenende hat Microsoft weitere Exchange-Updates nachgelegt. [..] Aufgrund einer schwachen Autorisierung in Microsofts Exchange-Server können authentifizierte Angreifer aus dem Netz ihre Rechte ausweiten. Die Entwickler führen aus, dass bösartige Akteure dadurch unbefugten Zugriff auf Mailboxen anderer User erlangen und E-Mails und Anhänge daran lesen können. Tenant-Grenzen lassen sich dadurch jedoch nicht überwinden (CVE-2026-96940, CVSS 8.8, Risiko „hoch“).
---------------------------------------------
https://www.heise.de/news/Microsoft-schiebt-Exchange-Update-nach-11475517.h…
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1098599/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 01-10-2026 18:00 − Freitag 02-10-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Microsoft’s X account hacked in crypto pump-and-dump scheme ∗∗∗
---------------------------------------------
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-…
∗∗∗ Hackerangriff: Pentagon verliert Daten von mehr als drei Millionen Personen ∗∗∗
---------------------------------------------
Unbefugte haben rund neun Monate lang Zugriff auf einen Server mit Personaldaten. Die Daten auf dem Server des Pentagon sind unverschlüsselt.
---------------------------------------------
https://www.golem.de/news/hackerangriff-pentagon-verliert-daten-von-mehr-al…
∗∗∗ Warlock ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries ∗∗∗
---------------------------------------------
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
---------------------------------------------
https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-…
∗∗∗ Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739) ∗∗∗
---------------------------------------------
During a Purple Team engagement, we had to list and rank risky components across the network. One of them caught our attention: Cato Client, a VPN client program. It was installed everywhere. It runs privileged services. It talks to a GUI. It handles network configuration. From an attacker perspective, this is exactly the kind of software you want to understand. However, saying "this looks risky" is not enough. There is nothing better than PoC||GTFO. So the question was simple: can we find a real bug and turn it into something useful? This is how it started.
---------------------------------------------
http://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escala…
=====================
= Vulnerabilities =
=====================
∗∗∗ Dell asks admins to patch max severity CSM flaws as soon as possible ∗∗∗
---------------------------------------------
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-fl…
∗∗∗ FortiMail: Angriffe auf Zero-Day-Lücke laufen, Workaround verfügbar ∗∗∗
---------------------------------------------
Fortinet warnt vor Angriffen auf eine Zero-Day-Sicherheitslücke in FortiMail. Sie ermöglicht die Übernahme der Geräte aus dem Netz.
---------------------------------------------
https://heise.de/-11473599
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1098312/
∗∗∗ [R1] Nessus Version 10.12.5 Fixes Multiple Vulnerabilities ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-26
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 30-09-2026 18:00 − Donnerstag 01-10-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Over 543,000 valid credentials exposed in public GitHub repositories ∗∗∗
---------------------------------------------
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platforms security measures to prevent accidental leaks of sensitive data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentia…
∗∗∗ Revolut zahlt kein Lösegeld: Hackergruppe erpresst Revolut-Kunden direkt ∗∗∗
---------------------------------------------
Die Geschichte rund um den Revolut-Hack aus dem vergangenen Monat geht weiter, bei dem Unbefugte an Bankdaten von Kunden gelangt sind. Nachdem die Neobank ein gefordertes Lösegeld von 3 Millionen US-Dollar nicht zahlte, versuchen Kriminelle, die erbeuteten Daten zu Geld zu machen, indem Revolut-Kunden direkt erpresst werden, berichtet unter anderem das Cybergrant-Blog. Nach derzeitigem Kenntnisstand sind 680 Revolut-Kunden von dem Vorfall betroffen.
---------------------------------------------
https://www.golem.de/news/revolut-zahlt-kein-loesegeld-hackergruppe-erpress…
∗∗∗ From: anyone(a)icloud.com - Absenderfälschung in Apple iCloud ∗∗∗
---------------------------------------------
Eine Fallstudie über die Entdeckung zweier E-Mail-Spoofing-Schwachstellen in Apple iCloud.
---------------------------------------------
https://sec-consult.com/de/blog/detail/from-anyoneicloudcom-absenderfaelsch…
∗∗∗ SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor ∗∗∗
---------------------------------------------
During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we’ll refer to this family of malware as SC, named after the “SC_” markers found in the injected content.What makes SC worth documenting is how it survives.
---------------------------------------------
https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of…
∗∗∗ Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path ∗∗∗
---------------------------------------------
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate.
---------------------------------------------
https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html
∗∗∗ NIS2 Registrierung in Österreich. Wie gehe ich richtig vor? ∗∗∗
---------------------------------------------
Seit dem 1. Oktober 2026 gelten für viele österreichische Unternehmen neue Vorgaben durch NIS2. Betroffene Unternehmen müssen dann technische und organisatorische Sicherheitsmaßnahmen umsetzen, die Verantwortung der Geschäftsführung beachten und sich beim Bundesamt für Cybersicherheit (BCS) registrieren. Dieser Leitfaden erklärt, wer sich registrieren muss, welche Informationen dafür nötig sind und wie Unternehmen dabei am besten vorgehen.
---------------------------------------------
https://www.zettasecure.com/post/nis2-registrierung-%C3%B6sterreich-anleitu…
∗∗∗ Zu viele KI-Vorfälle: US-Behörde untersucht Anthropic, METR, OpenAI ∗∗∗
---------------------------------------------
Zu häufig richten große Sprachmodelle Schaden an. Daher führt die US-Handelsbehörde FTC eine Untersuchung gegen große KI-Betreiber.
---------------------------------------------
https://heise.de/-11471857
=====================
= Vulnerabilities =
=====================
∗∗∗ Kiteworks patches max severity code injection vulnerability ∗∗∗
---------------------------------------------
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [..] Successful exploitation can let remote threat actors without privileges gain code execution and take over the targeted EPG appliance by exploiting a chain of path traversal, code injection, and missing authentication in low-complexity attacks that don't require user interaction. CVE-2026-54154
---------------------------------------------
https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severi…
∗∗∗ Vulnerabilities in Zammad during investigation of case DIVD-2026-00014 ∗∗∗
---------------------------------------------
During the investigation of case DIVD-2026-00014, two new CVEs were identified. CVE-2026-102489 - Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. [..] CVE-2026-102490 - In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root.
---------------------------------------------
https://csirt.divd.nl/cases/DIVD-2026-00015/
∗∗∗ WatchGuard schließt teils kritische Lücken in Fireware OS ∗∗∗
---------------------------------------------
Das Betriebssystem Fireware OS von WatchGuard weist Sicherheitslücken auf, die Angreifern aus dem Netz unter anderem das Einschleusen und Ausführen von Schadcode oder Denial-of-Service-Attacken ermöglichen. Sie gelten zum größten Teil als hochriskant und in einem Fall sogar als kritisch.
---------------------------------------------
https://www.heise.de/news/WatchGuard-schliesst-teils-kritische-Luecken-in-F…
∗∗∗ NVIDIA GPU Display Driver - September 2026 ∗∗∗
---------------------------------------------
https://nvidia.custhelp.com/app/answers/detail/a_id/5861
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1098067/
∗∗∗ Mozilla Foundation Security Advisories September 30, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 29-09-2026 18:00 − Mittwoch 30-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ New Spectre v2 attack variant leaks Linux root password hash in minutes ∗∗∗
---------------------------------------------
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-varian…
∗∗∗ Phishing Abuses RMM Tools for Persistent Access ∗∗∗
---------------------------------------------
In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. [..] This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rm…
∗∗∗ Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services ∗∗∗
---------------------------------------------
The public still doesn’t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the unknown digital intruders have used CVE-2026-88772 to break into government agencies, financial services firms, education organizations, and legal and professional services sectors across North America and Europe. And everyone agrees that the vendor took way too long to disclose the security holes.
---------------------------------------------
https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citr…
∗∗∗ Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent ∗∗∗
---------------------------------------------
Students, job seekers and university staff, watch out for fake job offers sent from legitimate university email accounts.
---------------------------------------------
https://hackread.com/hackers-hijacked-university-email-scam-students-fbi-ag…
∗∗∗ Fake Express Packages on npm Spread a Linux Worm ∗∗∗
---------------------------------------------
Nine npm packages hide a self-spreading Linux worm. The npm account dirtyblanket published all nine on September 29, 2026, in 33 minutes. Eight of them copy the popular Express framework. One copies React.
---------------------------------------------
https://safedep.io/dirtyblanket-express-impersonation-npm
∗∗∗ CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode ∗∗∗
---------------------------------------------
Jamf Threat Labs uncovers CloudSyncD, a fake Zoom installer disguised as a legitimate application that uses a phished login password to launch an embedded backdoor while concealing the credential inside a decoy configuration file.
---------------------------------------------
https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability ∗∗∗
---------------------------------------------
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. [..] In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. CVE-2026-76504
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ TeamViewer: Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services ∗∗∗
---------------------------------------------
TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services. These vulnerabilities have been resolved in the latest available versions. TeamViewer strongly recommends that all users update to the latest available version as soon as possible.
---------------------------------------------
https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/…
∗∗∗ MikroTik RouterOS ∗∗∗
---------------------------------------------
Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. [..] Initial Release Date: 2026-09-29 [..] CVE-2026-84411
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
∗∗∗ Kritische Schwachstelle: Google stopft 32 Löcher in Chrome ∗∗∗
---------------------------------------------
Die kritische Lücke mit der Kennung CVE-2026-102331 beschreibt Google in den Versionshinweisen als Pufferüberlauf. Betroffen ist die Grafikkomponente Angle. Laut CVE.org kann der Fehler mithilfe einer speziell präparierten HTML-Datei ausgenutzt werden. Ein Angreifer müsste ein Opfer also lediglich dazu verleiten, eine von ihm kontrollierte Website mit Chrome zu öffnen.
---------------------------------------------
https://www.golem.de/news/kritische-schwachstelle-google-stopft-32-loecher-…
∗∗∗ OpenSSL Security Advisory [29th September 2026] ∗∗∗
---------------------------------------------
https://openssl-library.org/news/secadv/20260929.txt
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1097753/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 28-09-2026 18:00 − Dienstag 29-09-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Cyberangriff auf Datenaustauschdienst FTAPI ∗∗∗
---------------------------------------------
Der Münchner Anbieter FTAPI bietet Dienste zur einfachen Übertragung von Daten an. Zur Kundschaft zählen etwa Behörden und Unternehmen. Die kriminelle Online-Bande The Gentlemen hat nun auf ihrer Darknet-Leaksite einen Einbruch in die IT-Systeme von FTAPI behauptet.
---------------------------------------------
https://heise.de/-11469629
∗∗∗ Over 16,000 Supabase databases expose PII, passwords, auth tokens ∗∗∗
---------------------------------------------
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-…
∗∗∗ Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks ∗∗∗
---------------------------------------------
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
---------------------------------------------
https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
∗∗∗ ShinyHunters weiter aktiv, Details zu FBI-Datendiebstahl ∗∗∗
---------------------------------------------
Offenbar hat die Cybergang ShinyHunters wirklich beim FBI Daten gestohlen. Die kriminelle Bande ist derzeit weiter umtriebig.
---------------------------------------------
https://www.heise.de/news/ShinyHunters-weiter-aktiv-Details-zu-FBI-Datendie…
∗∗∗ Digitale Gesundheitsanwendungen: HelloBetter meldet Datenpanne nach Cyberangriff ∗∗∗
---------------------------------------------
Aufgrund einer Schwachstelle konnten Unbekannte auf sensible Nutzerdaten eines Anbieters digitaler Therapieprogramme zugreifen.
---------------------------------------------
https://heise.de/-11469296
=====================
= Vulnerabilities =
=====================
∗∗∗ Apple patches CoreGraphics zero-day flaw exploited in attacks ∗∗∗
---------------------------------------------
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-z…
∗∗∗ Zero-Day-Lücke: Kiteworks rät Kunden zur Abschaltung von Servern ∗∗∗
---------------------------------------------
Der Softwareanbieter Kiteworks hat seinen Kunden Ende vergangener Woche empfohlen, ihre auf Software des Unternehmens basierenden Systeme offline zu nehmen. Zuvor hatte der Anbieter von Sicherheitsanwendungen eine nach seiner Einschätzung "glaubwürdige Bedrohungsinformation" von US-Sicherheitsbehörden erhalten. Demnach bestand ein konkretes Risiko für Cyberangriffe auf Kiteworks-Nutzer.
---------------------------------------------
https://www.golem.de/news/zero-day-luecke-kiteworks-raet-kunden-zur-abschal…
∗∗∗ Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials ∗∗∗
---------------------------------------------
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and 2.2.0.
---------------------------------------------
https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
∗∗∗ Groupware Zimbra: Update schließt zahlreiche Sicherheitslücken ∗∗∗
---------------------------------------------
Ein Update schließt diverse Lücken in Zimbra, die etwa die Kontoübernahme oder das Unterschieben von Schadcode ermöglichen.
---------------------------------------------
https://www.heise.de/news/Groupware-Zimbra-Update-schliesst-zahlreiche-Sich…
∗∗∗ WatchGuard AP: Befehlsschmuggel-Lücken und umgehbare Authentifizierung ∗∗∗
---------------------------------------------
In den Access-Points von WatchGuard schlummern drei Sicherheitslücken, durch die Angreifer Befehle einschmuggeln oder die Authentifizierung umgehen können. Eine aktualisierte Firmware bessert die teils als kritisches Risiko eingestuften Schwachstellen aus.
---------------------------------------------
https://heise.de/-11468944
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1097466/
∗∗∗ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006 ∗∗∗
---------------------------------------------
https://webkitgtk.org/security/WSA-2026-0006.html
∗∗∗ MISP 2.5.48 - AImageddon security roundup release ∗∗∗
---------------------------------------------
https://github.com/MISP/MISP/releases/tag/v2.5.48
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 25-09-2026 18:00 − Montag 28-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Wegen KI Bug Reports: Ubuntu liefert wöchentlich neuen Kernel ∗∗∗
---------------------------------------------
KI treibt die Anzahl gemeldeter Bugs in die Höhe. Damit Ubuntu-Nutzer Korrekturen schnell bekommen, beschleunigt Canonical seine Prozesse.
---------------------------------------------
https://www.golem.de/news/wegen-ki-bug-reports-ubuntu-liefert-woechentlich-…
∗∗∗ Studie zu KI-Agenten: Wenn die KI ihre Abschaltung als Mordversuch sabotiert ∗∗∗
---------------------------------------------
Nicht alle KI-Systeme wollen sich einfach wie ein PC herunterfahren lassen. Vor allem, wenn mehrere KI-Agenten kollaborieren sollen. [..] Konkret beobachteten die Forscher in dem Setting sechs Tendenzen der Systeme. Demnach nimmt die Sabotage mit der Irreversibilität des Abschaltmechanismus und der Zahl der beteiligten Agenten zu. Ein explizites Verbot reduziert die Sabotageversuche, eliminiert sie jedoch nicht. [..] Ebenfalls bemerkenswert: Wenn ein KI-Agent einen anderen Agenten abschalten sollte, der diesem nicht bekannt war, sank die Sabotagerate ebenfalls.
---------------------------------------------
https://www.golem.de/news/studie-zu-ki-agenten-wenn-die-ki-ihre-abschaltung…
∗∗∗ Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells ∗∗∗
---------------------------------------------
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
---------------------------------------------
https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.h…
∗∗∗ Fake Google Security Team ad says no script reading in voice phishing - then prints the script ∗∗∗
---------------------------------------------
Yes, criminals have job listings too. A Telegram user recruiting callers to work in an apparent Google Security Team voice-phishing scam told applicants that they weren’t allowed to read from scripts – in the same ad that also included the exact script they had to read during these scam calls.
---------------------------------------------
https://www.theregister.com/security/2026/09/25/fake-google-security-team-a…
∗∗∗ OpenAI pausiert KI-Training nach neuem Zwischenfall ∗∗∗
---------------------------------------------
Der ChatGPT-Entwickler OpenAI hat nach einem neuen Zwischenfall das Training seiner leistungsstärksten KI-Modelle ausgesetzt. Bei dem Vorfall schaffte es ein KI-Modell in einem Test, Antworten von einem externen Chatbot zu bekommen, obwohl es eigentlich keinen Internet-Zugang haben sollte. Die Software habe jedoch eine Lücke in den Netzwerk-Einstellungen gefunden und ausgenutzt, wie OpenAI in einem Blogeintrag berichtete. Das Training solle nun erst wieder aufgenommen werden, wenn man sich sicher sei, dass die Lücke geschlossen ist.
---------------------------------------------
https://www.heise.de/news/OpenAI-pausiert-KI-Training-nach-neuem-Zwischenfa…
∗∗∗ Kurtaxe und Servicepauschale: Angebliche Doppelbuchung führt in Phishing-Falle ∗∗∗
---------------------------------------------
Rückbuchungen von der ÖGK oder dem Finanzamt werden seit gefühlten Ewigkeiten als Köder für Betrugsmaschen eingesetzt. Kürzlich wurde eine andere Variante der Falle gemeldet. Im Zentrum stehen diesmal ein Hotel sowie eine doppelte Berechnung von Kurtaxe und Servicepauschale. Am Ziel hat sich nichts geändert: Angestrebt werden der Zugriff auf das Onlinebanking des Opfers sowie die Freigabe einer Überweisung.
---------------------------------------------
https://www.watchlist-internet.at/news/kurtaxe-und-servicepauschale-doppelb…
∗∗∗ KI-Betrug bei italienischer Großbank: 95 Mio Euro erbeutet ∗∗∗
---------------------------------------------
Der Betrug begann im Februar. Der damalige Fideuram-Vorsitzende Paolo Molesini erhielt über WhatsApp eine Nachricht, die scheinbar vom Chef von Intesa Sanpaolo, Carlo Messina, stammte. Darin wurde er um dringende Unterstützung bei einer Auslandsüberweisung gebeten. Kurz darauf folgte ein Anruf, der angeblich von einem ranghohen Mitarbeiter einer bekannten Anwaltskanzlei kam. Der Anrufer bestätigte den Auftrag. Nach Angaben der Quellen setzten die Täter dabei künstliche Intelligenz ein, um die Stimme des Anwalts nachzuahmen.
---------------------------------------------
https://www.derstandard.at/story/3000000341451/ki-betrug-bei-italienischer-…
∗∗∗ Tech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts ∗∗∗
---------------------------------------------
A tech support scam kit is using Google Ads to deliver fake security alerts that make browsers appear locked while using techniques to evade automated analysis. [..] The ads appeared through normal advertising inventory on legitimate maps, weather, real-estate, document-hosting, and sports sites. It is worth noting that the publishers were not compromised. Netskope traced most of the traffic to paid Google Ads rather than organic searches, based on Google advertising identifiers found in the URLs.
---------------------------------------------
https://hackread.com/tech-support-scam-kit-google-ads-fake-security-alerts/
∗∗∗ LuaRocks Security Incident September 2026 ∗∗∗
---------------------------------------------
On September 25th, 2026 we received a report of a remote code execution vulnerability in LuaRocks.org, coordinated through CISA. The vulnerability was fixed on September 26th. While investigating, we found that it had been exploited on the LuaRocks.org server several times between July 9th and August 20th, 2026. [..] We have not found any evidence that existing packages were modified. Details on what we checked are below.
---------------------------------------------
https://luarocks.org/security-incident-september-2026
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücken in Citrix NetScaler ADC und NetScaler Gateway - aktiv ausgenutzt - Updates verfügbar ∗∗∗
---------------------------------------------
In Citrix NetScaler ADC und Citrix NetScaler Gateway existieren mehrere Sicherheitslücken, darunter zwei kritische Schwachstellen, die die Ausführung von beliebigem Code ermöglichen. Laut Hersteller werden CVE-2026-88771 und CVE-2026-88772 bereits aktiv ausgenutzt. CVE-Nummer(n): CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778 CVSS v4.0 Base Scores: bis zu 9.5 (kritisch)
---------------------------------------------
https://www.cert.at/de/warnungen/2026/9/kritische-sicherheitslucken-in-citr…
∗∗∗ Elementor WordPress flaw lets attackers create admin accounts ∗∗∗
---------------------------------------------
Threat actors can exploit the flaw by tricking a logged-in administrator into opening a malicious link, causing the victim's authenticated session to perform a REST API action permitted by their account. On default installations, the result is the creation of an administrator account under the control of the attacker. [..] Security firm Patchstack reported the vulnerability to the Elementor team on September 22 after receiving it from bug hunter “Saggre.” Elementor released a fix two days later, in version 4.3.2 of the plugin.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-let…
∗∗∗ Notepad++ 8.9.8.1: Update schließt mehrere Sicherheitslücken ∗∗∗
---------------------------------------------
Das Zwischen-Release 8.9.8.1 kümmert sich dabei um gleich fünf Schwachstellen. Immerhin gilt keine davon als hohes oder kritisches Risiko. Nutzer sollten die Aktualisierung bei Gelegenheit anwenden.
---------------------------------------------
https://www.heise.de/news/Notepad-8-9-8-1-Update-schliesst-mehrere-Sicherhe…
∗∗∗ LWN: Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1097191/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 24-09-2026 18:00 − Freitag 25-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ CRA - Reporting: The first two weeks ∗∗∗
---------------------------------------------
The CRA-SRP (Single Reporting Platform) started operating two weeks ago, and we now have some experience with the system. There are multiple angles to this.
---------------------------------------------
https://www.cert.at/en/blog/2026/9/cra-reporting-the-first-two-weeks
∗∗∗ Phishing-Angriffe mit echten Hotel-Buchungsdaten ∗∗∗
---------------------------------------------
Über eine Schwachstelle bei HotelNetSolutions wurden Buchungsdaten von Hotelgästen abgegriffen. Kriminelle nutzen sie für glaubhafte Phishing-Nachrichten.
---------------------------------------------
https://heise.de/-11466446
∗∗∗ Betreiber Kritischer Infrastruktur sollen in Österreich Flugdrohnen abschießen ∗∗∗
---------------------------------------------
Nähern sich verdächtige Flugdrohnen Kritischer Infrastruktur, soll deren Betreiber die Drohnen vom Himmel holen. Lizenzen dafür sind in Österreich geplant.
---------------------------------------------
https://heise.de/-11465199
∗∗∗ Bevorstehender Zero-Day-Angriff: KiteWorks drängt Kunden zur Serverabschaltung ∗∗∗
---------------------------------------------
Man habe konkrete Hinweise von Strafverfolgern auf eine Attacke, schreibt der Hersteller seinen Kunden. Auch hierzulande sind große Unternehmen betroffen.
---------------------------------------------
https://www.heise.de/news/Bevorstehender-Zero-Day-Angriff-KiteWorks-draengt…
∗∗∗ New Carbonato malware uses AI agents to hijack exposed Docker hosts ∗∗∗
---------------------------------------------
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-a…
∗∗∗ MacSync malware uses public iCloud calendars to deliver new payloads ∗∗∗
---------------------------------------------
A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-…
∗∗∗ Muse leakt Systemdateien: Metas KI-Agent gibt auf Anfrage sein Dateisystem aus ∗∗∗
---------------------------------------------
Ein Entwickler hat Metas KI-Agent Muse 6,8 GByte an Daten aus seiner Betriebsumgebung entlockt. Laut Meta ist das ein erwartetes Verhalten.
---------------------------------------------
https://www.golem.de/news/muse-leakt-systemdateien-metas-ki-agent-gibt-auf-…
∗∗∗ Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments ∗∗∗
---------------------------------------------
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-…
∗∗∗ Cloudflare Fixes Flaw That Let One Container Read Another Customers Leftover Disk Data ∗∗∗
---------------------------------------------
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.
---------------------------------------------
https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
∗∗∗ CVE flood pushes Ubuntu onto weekly kernel release cycle ∗∗∗
---------------------------------------------
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace.
---------------------------------------------
https://www.theregister.com/os-platforms/2026/09/24/cve-flood-pushes-ubuntu…
∗∗∗ Decades-old file security flaws found in Android, Linux, macOS, and Windows ∗∗∗
---------------------------------------------
Security researchers report that Microsoft considers the side-channel leak of file events to be by design.
---------------------------------------------
https://www.theregister.com/security/2026/09/24/decades-old-file-security-f…
∗∗∗ Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing ∗∗∗
---------------------------------------------
SalesBleed security flaws lead to very unexpected consequences.
---------------------------------------------
https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns…
∗∗∗ It was a matter of when, not if... ∗∗∗
---------------------------------------------
Security people always say it’s not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we’re the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked.
---------------------------------------------
https://csirt.divd.nl/2026/09/24/when-not-if/
∗∗∗ Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud ∗∗∗
---------------------------------------------
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
---------------------------------------------
https://socket.dev/blog/mini-shai-hulud-actions?utm_medium=feed
=====================
= Vulnerabilities =
=====================
∗∗∗ VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise ∗∗∗
---------------------------------------------
ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise.
---------------------------------------------
https://kb.cert.org/vuls/id/234131
∗∗∗ Sicherheitslücken: GitLab-Server mit Schadcode attackierbar ∗∗∗
---------------------------------------------
Die GitLab-Entwickler raten zur zügigen Installation der jüngst veröffentlichten Sicherheitsupdates.
---------------------------------------------
https://www.heise.de/news/Sicherheitsluecken-GitLab-Server-mit-Schadcode-at…
∗∗∗ Video-Tool VLC: Version 3.0.24 stopft über 130 Sicherheitslecks ∗∗∗
---------------------------------------------
Der Videoplayer VLC ist in Version 3.0.24 erschienen. Mehr als 130 Sicherheitslücken soll das Release schließen.
---------------------------------------------
https://heise.de/-11465305
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1096637/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/