=====================
= End-of-Day report =
=====================
Timeframe: Freitag 20-02-2026 18:00 − Montag 23-02-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Incident Reporting: EU-Wide Statistics ∗∗∗
---------------------------------------------
At the last CSIRTs Network meeting we got treated to a powerpoint versions of the statistics that ENISA publishes under https://ciras.enisa.europa.eu/ The mathematician inside me was not impressed, and as I’m prone to do, I did not withhold my opinion. This blog post explains why I’m so unhappy with ENISA’s analysis.
---------------------------------------------
https://www.cert.at/en/blog/2026/2/incident-reporting-eu-wide-statistics
∗∗∗ Predator spyware hooks iOS SpringBoard to hide mic, camera activity ∗∗∗
---------------------------------------------
US-sanctioned surveillance firm Intellexa developed the Predator commercial spyware and delivered it in attacks that exploited Apple and Chrome zero-day flaws and through 0-click infection mechanisms. [..] The malware does not exploit any iOS vulnerability but leverages previously obtained kernel-level access to hijack system indicators that would otherwise expose its surveillance operation.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/predator-spyware-hooks-ios-s…
∗∗∗ Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks ∗∗∗
---------------------------------------------
A new report by CJ Moses, CISO of Amazon Integrated Security, says that the hacking campaign occurred between January 11 and February 18, 2026, and did not rely on any exploits to breach Fortinet firewalls. Instead, the threat actor targeted exposed management interfaces and weak credentials that lacked MFA protection, then used AI to help automate access to other devices on the breached network.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/amazon-ai-assisted-hacker-br…
∗∗∗ CarGurus: Have I Been Pwned integriert Daten von 12,5 Millionen Kunden ∗∗∗
---------------------------------------------
Have I Been Pwned ist um 12,5 Millionen Einträge von CarGurus-Nutzern und -Nutzerinnen reicher. Die haben ShinyHunters geklaut. [..] Zudem sind Nutzerkonten-IDs enthalten, Daten aus finanziellen Vorprüfungen, Händlerkonten sowie Abo-Informationen. Hunt führt weiter aus, dass auch Namen, Telefonnummern, Anschriften und IP-Adressen sowie der Ausgang von Finanzierungsanfragen betroffen sind.
---------------------------------------------
https://www.heise.de/news/CarGurus-ShinyHunters-kopieren-Datensaetze-von-12…
∗∗∗ ‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA ∗∗∗
---------------------------------------------
Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and security firms. But a stealthy new phishing-as-a-service offering lets customers sidestep both of these pitfalls: It uses cleverly disguised links to load the target brand’s real website, and then acts as a relay between the victim and the legitimate site — forwarding the victim’s username, password and multi-factor authentication (MFA) code to the legitimate site and returning its responses.
---------------------------------------------
https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-rea…
∗∗∗ Hackers Hide Pulsar RAT Inside PNG Images in New NPM Supply Chain Attack ∗∗∗
---------------------------------------------
Cybersecurity researchers at Veracode reveal a typosquatting attack that disguises Pulsar RAT as images to bypass Windows security and antivirus programs.
---------------------------------------------
https://hackread.com/hackers-pulsar-rat-png-images-npm-supply-chain-attack/
∗∗∗ Roundcube Webmail: Angriffe auf Sicherheitslücken laufen ∗∗∗
---------------------------------------------
Die zweite Sicherheitslücke wurde kurz vor Weihnachten bekannt. Sie ermöglicht Cross-Site-Scripting-Angriffe. Die Schwachstelle betrifft die Verarbeitung des „Animate“-Tag in SVG-Dateien. [..] IT-Verantwortliche sollten ihre Systeme absichern, indem sie zumindest auf die fehlerkorrigierten Versionen 1.5.12 und 1.6.12 installieren.
---------------------------------------------
https://heise.de/-11185535
∗∗∗ SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains ∗∗∗
---------------------------------------------
An active Shai-Hulud-like supply chain worm campaign spreads via typosquatting and AI toolchain poisoning, across at least 19 malicious npm packages and linked to two npm aliases. The sample retains Shai-Hulud hallmarks and adds GitHub API exfiltration with DNS fallback, hook-based persistence, SSH propagation fallback, MCP server injection with embedded prompt injection targeting AI coding assistants, and LLM API Key harvesting.
---------------------------------------------
https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning
=====================
= Vulnerabilities =
=====================
∗∗∗ Pi-hole: Update schließt Sicherheitslücken und liefert mehr Performance ∗∗∗
---------------------------------------------
Zum einen hätten als Admin angemeldete Angreifer eine „Stored HTML-Injection“-Schwachstelle missbrauchen können, um HTML-Code einzuschleusen, der bei der Anzeige der DNS-Eintragstabelle angezeigt wird (CVE-2026-26952, CVSS 5.4, Risiko „mittel“). Zum anderen gelingt dies auch auf der API-Einstellungswebseite (CVE-2026-26953, CVSS 5.4, Risiko „mittel“).
---------------------------------------------
https://heise.de/-11185637
∗∗∗ LWN: Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1059864/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 19-02-2026 18:00 − Freitag 20-02-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT RAT ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a new ClickFix campaign that abuses compromised legitimate sites to deliver a previously undocumented remote access trojan (RAT) called MIMICRAT (aka AstarionRAT).
---------------------------------------------
https://thehackernews.com/2026/02/clickfix-campaign-abuses-compromised.html
∗∗∗ PromptSpy läutet mit GenAI die Ära der Android-Bedrohungen ein ∗∗∗
---------------------------------------------
ESET-Forscher entdecken PromptSpy, die erste bekannte Android-Malware, die generative KI in ihrem Ausführungsablauf nutzt.
---------------------------------------------
https://www.welivesecurity.com/de/eset-research/promptspy-lautet-mit-genai-…
∗∗∗ Windows-Editor: Details zur Markdown-Sicherheitslücke ∗∗∗
---------------------------------------------
Die Patchday-Updates schließen eine Lücke im Windows-Editor, die das Einschleusen von Schadcode erlaubt. Nun gibt es Details zum Leck.
---------------------------------------------
https://heise.de/-11183516
∗∗∗ Crims create fake remote management vendor that actually sells a RAT ∗∗∗
---------------------------------------------
Researchers at Proofpoint late last month uncovered what they describe as a "weird twist" on the growing trend of criminals abusing remote monitoring and management software (RMM) as their preferred attack tools.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/02/19/rmm_rat_trus…
∗∗∗ VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731) ∗∗∗
---------------------------------------------
On Feb. 6, 2026, BeyondTrust released a security advisory regarding CVE-2026-1731. BeyondTrust is an identity and access management platform. This specific vulnerability involves a pre-authentication remote code execution (RCE) issue within BeyondTrust remote support software. It could allow attackers to execute operating system commands in the context of the site user, which may lead to system compromise, including unauthorized access, data exfiltration and service disruption.
---------------------------------------------
https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/
=====================
= Vulnerabilities =
=====================
∗∗∗ Atlassian-Sicherheitsupdates: Bamboo und Confluence sind verwundbar ∗∗∗
---------------------------------------------
Um zu verhindern, dass Angreifer mehrere Sicherheitslücken in Atlassian Bamboo Data Center and Server, Confluence Data Center and Server sowie Crowd Data Center und Server ausnutzen, sollten Admins die nun verfügbaren Patches umgehend installieren.
---------------------------------------------
https://heise.de/-11183534
∗∗∗ Zahlreiche Kernel-Lücken in Dell PowerProtect Data Manager geschlossen ∗∗∗
---------------------------------------------
Dells Backuplösung PowerProtect Data Manager ist unter anderem für Schadcode-Attacken anfällig. Sicherheitspatches stehen zum Download bereit.
---------------------------------------------
https://heise.de/-11184164
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1059638/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 18-02-2026 18:00 − Donnerstag 19-02-2026 18:00
Handler: Guenes Holler
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Lawful access to encrypted data: General Considerations ∗∗∗
---------------------------------------------
Last week, I wrote a blog post on why the problem of lawful access to encrypted data is so tricky, this week I want to continue with a discussion on the general considerations you should keep in mind when thinking about this topic. Important note: I think LE is well aware of these considerations and agrees with most of my conclusions.
---------------------------------------------
https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-general-…
∗∗∗ Hackers target Microsoft Entra accounts in device code vishing attacks ∗∗∗
---------------------------------------------
Threat actors are targeting technology, manufacturing, and financial organizations in campaigns that combine device code phishing and voice phishing (vishing) to abuse the OAuth 2.0 Device Authorization flow and compromise Microsoft Entra accounts.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-ent…
∗∗∗ How infostealers turn stolen credentials into real identities ∗∗∗
---------------------------------------------
Infostealer dumps increasingly tie stolen credentials to real identities, linking usernames, cookies, and behavior across personal and enterprise accounts. Specops explains how analyzing 90,000 dumps shows reuse fuels enterprise risk and how continuous AD scanning disrupts that cycle.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/how-infostealers-turn-stolen…
∗∗∗ Arkanix Stealer: a C++ & Python infostealer ∗∗∗
---------------------------------------------
Kaspersky researchers analyze a C++ and Python stealer dubbed "Arkanix Stealer", which was active for several months, targeted wide range of data, was distributed as MaaS and offered referral program to its partners.
---------------------------------------------
https://securelist.com/arkanix-stealer/119006/
∗∗∗ Frankreich: Angreifer griffen auf Daten von 1,2 Millionen Bankkonten zu ∗∗∗
---------------------------------------------
In Frankreich haben sich Angreifer Zugriff auf eine nationale Datenbank verschafft und Daten zu 1,2 Millionen Bankkonten ausgelesen.
---------------------------------------------
https://www.heise.de/news/Frankreich-Angreifer-griffen-auf-Daten-von-1-2-Mi…
∗∗∗ Die Uhr tickt: Frist zur NIS2-Registrierung beim BSI läuft am 6. März 2026 ab ∗∗∗
---------------------------------------------
Der TÜV SÜD warnt, dass in zwei Wochen die Registrierungsfrist beim BSI für NIS2-pflichtige Unternehmen endet. Betroffen sind rund 29.000 deutsche Unternehmen.
---------------------------------------------
https://www.heise.de/news/Die-Uhr-tickt-Frist-zur-NIS2-Registrierung-beim-B…
∗∗∗ Betrugsmasche: Falsche „Gemini“-Chatbots verkaufen falschen „Google Coin“ ∗∗∗
---------------------------------------------
Eine neue Betrugsmasche beruht auf angepassten KI-Chatbots. Diese drängen Opfer dazu, wertlose Kryptowährungen zu kaufen.
---------------------------------------------
https://www.heise.de/news/Betrugsmasche-Falsche-Gemini-Chatbots-verkaufen-f…
∗∗∗ Kubernetes project issues warning on Ingress NGINX retirement ∗∗∗
---------------------------------------------
The Kubernetes project is urging organizations to migrate away from Ingress NGINX before its retirement in March 2026, with new high-severity CVEs underscoring the urgency.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/kubernetes-ingress-nginx-retire…
∗∗∗ Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack ∗∗∗
---------------------------------------------
On February 17, 2026, an unauthorized party used a compromised npm publish token to push cline(a)2.3.0 to the npm registry. Cline is a popular AI coding agent CLI in the developer ecosystem, with around 90,000 weekly downloads from npm. The malicious version contained a modified package.json with an added postinstall script: npm install -g openclaw@latest.
---------------------------------------------
https://socket.dev/blog/cline-cli-npm-package-compromised-via-suspected-cac…
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical infra Honeywell CCTVs vulnerable to auth bypass flaw ∗∗∗
---------------------------------------------
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a critical vulnerability in multiple Honeywell CCTV products that allows unauthorized access to feeds or account hijacking.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cct…
∗∗∗ Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed a critical security flaw in the Grandstream GXP1600 series of VoIP phones that could allow an attacker to seize control of susceptible devices.The vulnerability, tracked as CVE-2026-2329, carries a CVSS score of 9.3 out of a maximum of 10.0.
---------------------------------------------
https://thehackernews.com/2026/02/grandstream-gxp1600-voip-phones-exposed.h…
∗∗∗ Nvidia-KI-Tools Megatron Bridge und NeMo Framework als Einfallstor für Angreifer ∗∗∗
---------------------------------------------
Nvidias Entwickler haben unter anderem Schadcode-Schlupflöcher in Megatron Bridge und NeMo Framework geschlossen.
---------------------------------------------
https://www.heise.de/news/Nvidia-KI-Tools-Megatron-Bridge-und-NeMo-Framewor…
∗∗∗ Mozilla Firefox Issues Emergency Patch for Heap Buffer Overflow in Firefox v147 ∗∗∗
---------------------------------------------
Mozilla has released an out-of-band security update to address a critical vulnerability affecting its browser. The update, issued as Firefox v147.0.4, resolves a high-impact Heap buffer overflow flaw in the libvpx video codec library. The issue is tracked under CVE-2026-2447 and was identified by security researcher jayjayjazz.
---------------------------------------------
https://thecyberexpress.com/firefox-v147-cve-2026-2447/
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1059500/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 17-02-2026 18:00 − Mittwoch 18-02-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Data breach at fintech firm Figure affects nearly 1 million accounts ∗∗∗
---------------------------------------------
Hackers have stolen the personal and contact information of nearly 1 million accounts after breaching the systems of Figure Technology Solutions, a self-described blockchain-native financial technology company.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-…
∗∗∗ Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages ∗∗∗
---------------------------------------------
Microsoft says an Exchange Online issue that mistakenly quarantined legitimate emails last week was triggered by faulty heuristic detection rules designed to block credential phishing campaigns.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-anti-phishing-rul…
∗∗∗ "Keine alltägliche Dimension": AWS kann DDoS-Attacke auf die Bahn nicht abfangen ∗∗∗
---------------------------------------------
Einen Tag lang ist es Hackern gelungen, den DB Navigator und bahn.de lahmzulegen. Die geschäftskritischen Systeme liegen bei Amazon Web Services.
---------------------------------------------
https://www.golem.de/news/die-groessere-kante-aws-kann-ddos-attacke-auf-die…
∗∗∗ Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed that artificial intelligence (AI) assistants that support web browsing or URL fetching capabilities can be turned into stealthy command-and-control (C2) relays, a technique that could allow attackers to blend into legitimate enterprise communications and evade detection.
---------------------------------------------
https://thehackernews.com/2026/02/researchers-show-copilot-and-grok-can.html
∗∗∗ Your AI-generated password isnt random, it just looks that way ∗∗∗
---------------------------------------------
Seemingly complex strings are actually highly predictable, crackable within hours Generative AI tools are surprisingly poor at suggesting strong passwords, experts say.
---------------------------------------------
https://www.theregister.com/2026/02/18/generating_passwords_with_llms/
∗∗∗ Red Vulns Rising: Examining Chinese National Vulnerability Databases ∗∗∗
---------------------------------------------
Learn how the Chinese vulnerability databases (CNVD and CNNVD) compare to CVE, including early disclosures, policy shifts, and data quality differences.
---------------------------------------------
https://www.bitsight.com/blog/chinese-vulnerability-database-analysis-cnvd-…
=====================
= Vulnerabilities =
=====================
∗∗∗ Flaws in popular VSCode extensions expose developers to attacks ∗∗∗
---------------------------------------------
Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-exte…
∗∗∗ Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware ∗∗∗
---------------------------------------------
Notepad++ has released a security fix to plug gaps that were exploited by an advanced threat actor from China to hijack the software update mechanism to selectively deliver malware to targets of interest.
---------------------------------------------
https://thehackernews.com/2026/02/notepad-fixes-hijacked-update-mechanism.h…
∗∗∗ Microsoft warnt vor kritischer Rechteausweitungslücke in Windows Admin Center ∗∗∗
---------------------------------------------
Im Windows Admin Center können Angreifer ihre Rechte ausweiten. Microsoft stuft das als kritisch ein und rät Admins zum Aktualisieren.
---------------------------------------------
https://www.heise.de/news/Microsoft-warnt-vor-kritischer-Rechteausweitungsl…
∗∗∗ From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day ∗∗∗
---------------------------------------------
Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769, with a CVSSv3.0 score of 10.0.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting…
∗∗∗ Multiple Security-Updates for Splunk DB Connect - February 2026 ∗∗∗
---------------------------------------------
https://advisory.splunk.com
∗∗∗ [R2] Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2: SC-202602.1 + SC-202602.2 ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-06
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1059333/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 16-02-2026 18:00 − Dienstag 17-02-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets ∗∗∗
---------------------------------------------
Kaspersky experts have uncovered Keenadu, a sophisticated new backdoor targeting tablet firmware as well as system-level and Google Play apps. They also revealed connections between the worlds most prolific Android botnets.
---------------------------------------------
https://securelist.com/keenadu-android-backdoor/118913/
∗∗∗ IT-Sicherheitsbehörde CISA im Notbetrieb ∗∗∗
---------------------------------------------
Die zum Wochenende ausgelaufene Finanzierung des DHS betrifft auch die IT-Sicherheitsbehörde CISA. Diese befindet sich nun im Notbetrieb.
---------------------------------------------
https://www.heise.de/news/IT-Sicherheitsbehoerde-CISA-im-Notbetrieb-1117913…
∗∗∗ Sicherheitsbedenken: EU-Parlament deaktiviert KI-Tools auf Diensthandys ∗∗∗
---------------------------------------------
EU-Abgeordnete und ihre Angestellte können auf dienstlichen Smartphones und Tablets keine KI-Funktionen mehr nutzen. Man wisse zu wenig zur Datensicherheit.
---------------------------------------------
https://heise.de/-11179064
∗∗∗ Passwortmanager bieten weniger Schutz als versprochen ∗∗∗
---------------------------------------------
Forschende der ETH Zürich haben bei drei populären, cloudbasierten Passwortmanagern gravierende Sicherheitslücken entdeckt. In Tests konnten sie gespeicherte Passwörter einsehen und sogar verändern.
---------------------------------------------
https://ethz.ch/de/news-und-veranstaltungen/eth-news/news/2026/02/passwortm…
=====================
= Vulnerabilities =
=====================
∗∗∗ Mehr als 60 Sicherheitsprobleme in KI-Assistent OpenClaw gelöst ∗∗∗
---------------------------------------------
Angreifer können im Kontext von OpenClaw unter anderem Schadcode auf Systeme schieben und ausführen. Sicherheitspatches sind verfügbar.
---------------------------------------------
https://heise.de/-11179150
∗∗∗ CleanTalk WordPress Plugin Vulnerability Puts 200,000 Sites at Risk ∗∗∗
---------------------------------------------
A WordPress plugin vulnerability has placed as many as 200,000 websites at potential risk, following the disclosure of a severe flaw in the CleanTalk Anti-Spam plugin. The issue, tracked as CVE-2026-1490, carries a CVSS severity rating of 9.8 out of 10 and could allow unauthenticated attackers to install arbitrary plugins, opening the door to remote code execution under certain conditions.
---------------------------------------------
https://thecyberexpress.com/cleantalk-cve-2026-1490/
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1059176/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 13-02-2026 18:00 − Montag 16-02-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps ∗∗∗
---------------------------------------------
Threat actors are abusing Pastebin comments to distribute a new ClickFix-style attack that tricks cryptocurrency users into executing malicious JavaScript in their browser, allowing attackers to hijack Bitcoin swap transactions and redirect funds to attacker-controlled wallets.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/pastebin-comments-push-click…
∗∗∗ Romo: DJI-Staubsaugerroboter gehackt ∗∗∗
---------------------------------------------
Eine Sicherheitslücke im DJI Romo Saugroboter erlaubte den Zugriff auf rund 7.000 Geräte weltweit - inklusive Live-Kameras und Wohnungsgrundrissen.
---------------------------------------------
https://www.golem.de/news/romo-dji-staubsaugerroboter-gehackt-2602-205411.h…
∗∗∗ Gefälschte E-Mail zur Kryptomeldepflicht: Neue Betrugsmasche im Umlauf ∗∗∗
---------------------------------------------
In zahlreichen Postfächern taucht derzeit eine E-Mail auf, die angeblich vom Bundesministerium für Finanzen stammt und eine „dringende Meldepflicht“ für Kryptovermögen ankündigt. Selbst Personen ohne Kryptowährungen sollen demnach ein Formular ausfüllen. Die Nachricht wirkt seriös, ist aber eine gut gemachte Phishing-Falle.
---------------------------------------------
https://www.watchlist-internet.at/news/gefaelschte-e-mail-zur-kryptomeldepf…
∗∗∗ Phishing on the Edge of the Web and Mobile Using QR Codes ∗∗∗
---------------------------------------------
We discuss the extensive use of malicious QR codes using URL shorteners, in-app deep links and direct APK downloads to bypass mobile security.The post Phishing on the Edge of the Web and Mobile Using QR Codes appeared first on Unit 42.
---------------------------------------------
https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitslücke im Browser: Attacken auf Chrome-Nutzer beobachtet ∗∗∗
---------------------------------------------
Eine gefährliche Sicherheitslücke lässt Angreifer Schadcode in Chrome einschleusen. Es reicht der Besuch einer speziell gestalteten Webseite.
---------------------------------------------
https://www.golem.de/news/sicherheitsluecke-im-browser-attacken-auf-chrome-…
∗∗∗ ClickFix-Attacken nutzen Schadcode in DNS-Antworten ∗∗∗
---------------------------------------------
Microsoft hat eine neue Variante der Malware-Verteilung in ClickFix-Angriffen entdeckt. Die Angreifer liefern Schadcode mittels DNS aus.
---------------------------------------------
https://www.heise.de/news/ClickFix-Attacken-nutzen-Schadcode-in-DNS-Antwort…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1058989/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 12-02-2026 18:00 − Freitag 13-02-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Microsoft: New Windows LNK spoofing issues arent vulnerabilities ∗∗∗
---------------------------------------------
Today, at Wild West Hackin Fest, security researcher Wietze Beukema disclosed multiple vulnerabilities in Windows LK shortcut files that allow attackers to deploy malicious payloads.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-new-windows-lnk-s…
∗∗∗ Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy — Again ∗∗∗
---------------------------------------------
A handful of European government agencies have been compromised by hackers in recent weeks, thanks to a new round of critical vulnerabilities in an Ivanti product — and it's another grim reminder of the heyday attackers have been having with edge devices.
---------------------------------------------
https://www.darkreading.com/endpoint-security/ivanti-epmm-zero-day-bugs-exp…
∗∗∗ 37 Millionen Downloads: 287 Chrome-Extensions bei der Spionage erwischt ∗∗∗
---------------------------------------------
Forscher haben den Traffic zahlreicher Chrome-Erweiterungen analysiert. 287 davon spionieren für Datenbroker das Surfverhalten aus.
---------------------------------------------
https://www.golem.de/news/37-millionen-downloads-287-chrome-extensions-bei-…
∗∗∗ Bypassing Administrator Protection by Abusing UI Access ∗∗∗
---------------------------------------------
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exist. I described one of the ways I was able to bypass the feature before it was released. In total I found 9 bypasses during my research that have now all been fixed.In this blog post I wanted to describe the root cause of 5 of those 9 issues, specifically the implementation of UI Access, how this has been a long standing problem with UAC that’s been under-appreciated, and how it’s being fixed now.
---------------------------------------------
https://projectzero.google/2026/02/windows-administrator-protection.html
∗∗∗ IPFire stellt freie Domain-Blockliste DBL vor ∗∗∗
---------------------------------------------
Die IPFire-Entwickler haben mit DBL eine kategorisierte Domain-Blockliste veröffentlicht. Sie soll Malware, Phishing und Tracker blockieren.
---------------------------------------------
https://www.heise.de/news/IPFire-stellt-freie-Domain-Blockliste-DBL-vor-111…
∗∗∗ How to find and remove credential-stealing Chrome extensions ∗∗∗
---------------------------------------------
Researchers have uncovered 30 Chrome extensions stealing user data. Here’s how to check your browser and remove any malicious extensions step by step.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/02/how-to-find-and-remove-crede…
∗∗∗ Vorsicht, Trojaner! Kursierende Nachrichten zu Urheberrechtsverletzungen sind Fakes! ∗∗∗
---------------------------------------------
Mit Phishing-Nachrichten im Namen real existierender Unternehmen versuchen Kriminelle aktuell, Schadsoftware auf die Endgeräte ihrer Opfer zu schummeln. Die erhobenen Anschuldigungen sind natürlich frei erfunden, das angehängte Dokument ist allerdings hochgefährlich.
---------------------------------------------
https://www.watchlist-internet.at/news/vorsicht-trojaner-urheberrechtsverle…
∗∗∗ Urgent warnings from UK and US cyber agencies after Polish energy grid attack ∗∗∗
---------------------------------------------
A coordinated cyberattack that targeted Polands energy infrastructure in late December 2025 has prompted cybersecurity agencies to issue urgent warnings to critical national infrastructure operators on both sides of the Atlantic.
---------------------------------------------
https://www.fortra.com/blog/urgent-warnings-uk-and-us-cyber-agencies-after-…
∗∗∗ Naming and shaming: How ransomware groups tighten the screws on victims ∗∗∗
---------------------------------------------
When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle.
---------------------------------------------
https://www.welivesecurity.com/en/ransomware/naming-shaming-ransomware-grou…
∗∗∗ Lawful access to encrypted data: why is this so hard to do? ∗∗∗
---------------------------------------------
As I am now a member of the EU expert group which is tasked with coming up with a solution, I have been thinking a lot about this problem. An interesting train of thought turned out to be the question “We managed to give Law Enforcement (LE) wiretapping powers in old-style phone networks, but not in modern, Internet-based communication services. Why?”
---------------------------------------------
https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-why-is-t…
∗∗∗ 8,000+ ChatGPT API Keys Left Publicly Accessible ∗∗∗
---------------------------------------------
The rapid integration of artificial intelligence into mainstream software development has introduced a new category of security risk, one that many organizations are still unprepared to manage. According to research conducted by Cyble Research and Intelligence Labs (CRIL), thousands of exposed ChatGPT API keys are currently accessible across public infrastructure, dramatically lowering the barrier for abuse. CRIL identified more than 5,000 publicly accessible GitHub repositories containing
---------------------------------------------
https://thecyberexpress.com/exposed-chatgpt-api-keys-github-websites/
=====================
= Vulnerabilities =
=====================
∗∗∗ Jetzt patchen! Angreifer attackieren BeyondTrust-Fernwartungslösungen ∗∗∗
---------------------------------------------
Angreifer nutzen eine kritische Schadcode-Lücke in BeyondTrust Remote Support und Privileged Remote Access aus. Sicherheitspatches sind verfügbar.
---------------------------------------------
https://www.heise.de/news/Jetzt-patchen-Angreifer-attackieren-BeyondTrust-F…
∗∗∗ Qnap-NAS: Unbefugte Dateisystemzugriffe möglich ∗∗∗
---------------------------------------------
Sicherheitspatches für die NAS-Betriebssysteme QTS und QuTS hero von Qnap schließen mehrere Lücken.
---------------------------------------------
https://www.heise.de/news/Qnap-NAS-Unbefugte-Dateisystemzugriffe-moeglich-1…
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1058642/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 11-02-2026 18:00 − Donnerstag 12-02-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Crazy ransomware gang abuses employee monitoring tool in attacks ∗∗∗
---------------------------------------------
A member of the Crazy ransomware gang is abusing legitimate employee monitoring software and the SimpleHelp remote support tool to maintain persistence in corporate networks, evade detection, and prepare for ransomware deployment.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/crazy-ransomware-gang-abuses…
∗∗∗ Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts ∗∗∗
---------------------------------------------
The AgreeTo add-in for Outlook has been hijacked and turned into a phishing kit that stole more than 4,000 Microsoft account credentials. [..] Office add-ins are just URLs pointing to content loaded into Microsoft products from the developer's server. In the case of AgreeTo, the developer used a Vercel-hosted URL (outlook-one.vercel.app) but abandoned the project, despite the userbase it formed. [..] The case of AgreeTo stands out, though, as it is likely the first to be hosted on Microsoft’s Marketplace.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/microsoft-store-outlook-add-…
∗∗∗ Betrügerische Post-Emails im Umlauf ∗∗∗
---------------------------------------------
Rechnungen von der Post per E-Mail sind häufig Fake. Aktuell kursiert eine Variante, bei der 9,30 Euro für eine Sendung beglichen werden sollen. Ein Klick auf den Button führt auf eine Phishing-Website, auf der Kreditkartendaten gestohlen werden können.
---------------------------------------------
https://www.watchlist-internet.at/news/betruegerische-post-emails-im-umlauf/
∗∗∗ Nation-State Actors Exploit Notepad++ Supply Chain ∗∗∗
---------------------------------------------
Between June and December 2025, the official hosting infrastructure for the text editor Notepad++ was compromised by a state-sponsored threat group known as Lotus Blossom. The attackers breached the shared hosting provider’s environment. [..] We’ve identified additional unreported infrastructure, which is linked to this campaign.
---------------------------------------------
https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/
∗∗∗ Kritische Schwachstellen in diversen Routern von Linksys ∗∗∗
---------------------------------------------
Linksys-Router beinhalten Schwachstellen, die bis zu einer unauthentifizierten und vollständigen Kompromittierung der Geräte über das Internet führen. Der Hersteller Linksys hat für betroffene Geräte ein Update bereitgestellt, welches allerdings nur eine Ausnutzung über das Internet verhindert. [..] Shortly after discovering the vulnerabilities, a “quick” scan of the internet showed about 12.000 vulnerable devices. Around six months after the fix was available, this number shrunk to around 4.000. A reason for this large drop is probably because the Linksys routers support auto-update, which is enabled by default and installs new firmware updates without any user interaction.
---------------------------------------------
https://www.syss.de/pentest-blog/schwachstellen-in-linksys-routern
∗∗∗ US wants cyber partnerships to send ‘coordinated, strategic message’ to adversaries ∗∗∗
---------------------------------------------
National Cyber Director Sean Cairncross told attendees of the Munich Cyber Security Conference that Washington is looking to deepen cooperation with partners rather than act alone.
---------------------------------------------
https://therecord.media/us-wants-cyber-partnerships-to-send-message-to-adve…
∗∗∗ GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use ∗∗∗
---------------------------------------------
In the final quarter of 2025, Google Threat Intelligence Group (GTIG) observed threat actors increasingly integrating artificial intelligence (AI) to accelerate the attack lifecycle, achieving productivity gains in reconnaissance, social engineering, and malware development. This report serves as an update to our November 2025 findings regarding the advances in threat actor usage of AI tools.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/distillation-exper…
∗∗∗ Scary Agent Skills: Hidden Unicode Instructions in Skills ...And How To Catch Them · ∗∗∗
---------------------------------------------
There is a lot of talk about Skills recently, both in terms of capabilities and security concerns. However, so far I haven’t seen anyone bring up hidden prompt injection. So, I figured to demo a Skills supply chain backdoor that survives human review.
---------------------------------------------
https://embracethered.com/blog/posts/2026/scary-agent-skills/
=====================
= Vulnerabilities =
=====================
∗∗∗ Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices ∗∗∗
---------------------------------------------
Apple on Wednesday released iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS updates to address a zero-day flaw that it said has been exploited in sophisticated cyber attacks.
---------------------------------------------
https://thehackernews.com/2026/02/apple-fixes-exploited-zero-day.html
∗∗∗ Dell schließt unzählige Sicherheitslücken in Avamar, iDRAC und NetWorker ∗∗∗
---------------------------------------------
In drei Warnmeldungen listet Dell die nun geschlossenen Sicherheitslücken in Komponenten von Drittanbietern auf, die Avamar und NetWorker betreffen. [..] Darunter fallen Komponenten wie Apache HTTP Server, Expat, OpenSSL und Vim. Der Großteil der geschlossenen Lücken stammt aus dem Jahr 2025. Darunter sind auch „kritische“ Schwachstellen (etwa Samba CVE-2025-10230), über die Schadcode auf Systeme gelangen kann.
---------------------------------------------
https://www.heise.de/news/Dell-schliesst-unzaehlige-Sicherheitsluecken-in-A…
∗∗∗ Fortinet: LDAP authentication bypass in Agentless VPN and FSSO ∗∗∗
---------------------------------------------
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. CVE-2026-22153
---------------------------------------------
https://www.fortiguard.com/psirt/FG-IR-25-1052
∗∗∗ High-Severity RCE Vulnerability Disclosed in next-mdx-remote ∗∗∗
---------------------------------------------
HashiCorp has published HCSEC-2026-01, disclosing a high-severity vulnerability in the popular next-mdx-remote library that can lead to arbitrary code execution when rendering untrusted MDX content on the server. The issue is tracked as CVE-2026-0969 (GHSA-g4xw-jxrg-5f6m) and carries a CVSS 3.1 score of 8.8 (High). [..] It is fixed in version 6.0.0. [..] For clarity, this is not a vulnerability in Next.js itself. It affects applications that use next-mdx-remote to compile untrusted MDX content on the server.
---------------------------------------------
https://socket.dev/blog/high-severity-rce-vulnerability-disclosed-in-next-m…
∗∗∗ Multiple Vulnerabilities in various Solax Power Pocket WiFi models ∗∗∗
---------------------------------------------
https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities…
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1058473/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 10-02-2026 18:00 − Mittwoch 11-02-2026 18:00
Handler: Guenes Holler
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ New Linux botnet SSHStalker uses old-school IRC for C2 comms ∗∗∗
---------------------------------------------
A newly documented Linux botnet named SSHStalker is using the IRC (Internet Relay Chat) communication protocol for command-and-control (C2) operations.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-linux-botnet-sshstalker-…
∗∗∗ In Bypassing MFA, ZeroDayRAT Is Textbook Stalkerware ∗∗∗
---------------------------------------------
With access to SIM, location data, and a preview of recent SMSes, attackers have everything they need for account takeover or targeted social engineering.
---------------------------------------------
https://www.darkreading.com/threat-intelligence/zerodayrat-brings-commercia…
∗∗∗ DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies ∗∗∗
---------------------------------------------
The information technology (IT) workers associated with the Democratic Peoples Republic of Korea (DPRK) are now applying to remote positions using real LinkedIn accounts of individuals theyre impersonating, marking a new escalation of the fraudulent scheme.
---------------------------------------------
https://thehackernews.com/2026/02/dprk-operatives-impersonate.html
∗∗∗ Kimwolf Botnet Swamps Anonymity Network I2P ∗∗∗
---------------------------------------------
For the past week, the massive "Internet of Things" (IoT) botnet known as Kimwolf has been disrupting the The Invisible Internet Project (I2P), a decentralized, encrypted communications network designed to anonymize and secure online communications. I2P users started reporting disruptions in the network around the same time the Kimwolf botmasters began relying on it to evade takedown attempts against the botnets control servers.
---------------------------------------------
https://krebsonsecurity.com/2026/02/kimwolf-botnet-swamps-anonymity-network…
∗∗∗ Shelly IoT door controller config fail: leaving your garage, home and security exposed ∗∗∗
---------------------------------------------
I love my Shelly devices. They are an essential part of my smart home setup. I use them for everything from lights and plugs to garage doors and garden sprinkler control! One of the first Shelly devices I installed about five years ago recently stopped working, so I replaced it with one of their new fourth-generation Shelly 1 devices. That’s when I noticed an issue I hadn’t seen in previous generations.
---------------------------------------------
https://www.pentestpartners.com/security-blog/shelly-iot-door-controller-co…
∗∗∗ Recovery Scam: Wie Betrugsopfer erneut geschädigt werden ∗∗∗
---------------------------------------------
Durch Onlinebetrug verlorenes Geld zurückzuholen, das wünschen sich viele Opfer. Und genau diesen Wunsch versuchen Kriminelle für ihre Zwecke zu nutzen. Mit dem sogenannten „Recovery Scam“ ziehen sie bereits Geschädigten zusätzlich Geld aus der Tasche. Im Beispielfall geht es um angeblich wiedergefundene Krypto-Assets und für die Rücküberweisung notwendige Vorauszahlungen. Der Köder: Die Website betrugsrecht(.)de.
---------------------------------------------
https://www.watchlist-internet.at/news/recovery-scam-erneut-geschaedigt/
∗∗∗ A Peek Into Muddled Libra’s Operational Playbook ∗∗∗
---------------------------------------------
Explore the tools Unit 42 found on a Muddled Libra rogue host. Learn how they target domain controllers and use search engines to aid their attacks.
---------------------------------------------
https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/
∗∗∗ Cybersicherheit Zuhause: Privathaushalte als unterschätzte Angriffsfläche ∗∗∗
---------------------------------------------
Smartphones, Smarthome-Systeme, Cloud-Dienste und vernetzte Haushaltsgeräte sind längst fester Bestandteil des Alltags. Doch während Unternehmen und Behörden auf etablierte Standards, definierte Prozesse und vorhandene Expertise setzen können, bleibt IT-Sicherheit im privaten Umfeld meistens ungeregelt: Unzureichendes Knowhow, geteilte Passwörter und eine unsichere Konfiguration der gemeinsam genutzten Geräte erhöhen in vielen Familien und Wohngemeinschaften das digitale Risiko erheblich.
---------------------------------------------
https://certitude.consulting/blog/de/cybersicherheit-zuhause-privathaushalt…
∗∗∗ Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure ∗∗∗
---------------------------------------------
This joint Cybersecurity Advisory is being published as an addition to the Cybersecurity and Infrastructure Security Agency (CISA) May 6, 2025, joint fact sheet Primary Mitigations to Reduce Cyber Threats to Operational Technology and European Cybercrime Centre’s (EC3) Operation Eastwood, in which CISA, Federal Bureau of Investigation (FBI), Department of Energy (DOE), Environmental Protection Agency (EPA), and EC3 shared information about cyber incidents affecting the operational technology (OT) and industrial control systems (ICS) of critical infrastructure entities in the United States and globally.
---------------------------------------------
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
∗∗∗ Love Is in the Air — and So Are Scammers: Valentine’s Day 2026 Threats to Watch For ∗∗∗
---------------------------------------------
As Valentine’s Day 2026 approaches, people are turning to online shopping, digital dating, and last‑minute gift ideas. Unfortunately, cyber criminals are doing the same. Check Point researchers have identified a sharp rise in Valentine‑themed phishing websites, fraudulent stores, and fake dating platforms designed to steal personal data and payment information.
---------------------------------------------
https://blog.checkpoint.com/research/love-is-in-the-air-and-so-are-scammers…
∗∗∗ Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere ∗∗∗
---------------------------------------------
The GreyNoise Global Observation Grid observed active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, and 83% of that exploitation traces to a single IP address on bulletproof hosting infrastructure that does not appear on widely circulated IOC lists.
---------------------------------------------
https://www.greynoise.io/blog/active-ivanti-exploitation
∗∗∗ Hope Is Not a Security Strategy: Why Secure-by-Default Beats Hardening ∗∗∗
---------------------------------------------
Security has always assumed deterministic behavior. We can’t write policy to prevent bad outcomes when we don’t even know what the agent will do. Sandboxing is the natural answer: everyone is buying Mac Minis to run Moltbot (OpenClaw now), Docker is using microVMs for coding agent sandboxes, and countless projects offer sandboxing tools for AI agents.
---------------------------------------------
https://tuananh.net/2026/02/09/hope-is-not-a-security-strategy/
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitslücken: Attacken auf Windows, Office und den Internet Explorer ∗∗∗
---------------------------------------------
Der Februar fällt im Hinblick auf die Anzahl der zum Microsoft-Patchday geschlossenen Sicherheitslücken wieder etwas milder aus als der Januar. Jedoch befinden sich darunter gleich sechs Lücken, die bereits aktiv ausgenutzt werden. Betroffen sind nicht nur Windows-Systeme, sondern ebenso Microsoft Office und der totgeglaubte Internet Explorer. Nutzer sollten zügig patchen, um sich zu schützen.
---------------------------------------------
https://www.golem.de/news/microsoft-patchday-zero-day-luecken-in-windows-of…
∗∗∗ Patchday bei Adobe: After Effects & Co. für Schadcode-Attacken anfällig ∗∗∗
---------------------------------------------
Sicherheitspatches schließen mehrere Schwachstellen in Anwendungen von Adobe. Bislang gibt es keine Berichte zu Attacken.
---------------------------------------------
https://www.heise.de/news/Patchday-bei-Adobe-After-Effects-Co-fuer-Schadcod…
∗∗∗ 800,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in WPvivid Backup WordPress Plugin ∗∗∗
---------------------------------------------
On January 12th, 2026, we received a submission for an Arbitrary File Upload vulnerability in WPvivid Backup, a WordPress plugin with more than 800,000 active installations. This vulnerability can be used by unauthenticated attackers to upload arbitrary files to a vulnerable site and achieve remote code execution, which is typically leveraged for a complete site takeover.
---------------------------------------------
https://www.wordfence.com/blog/2026/02/800000-wordpress-sites-affected-by-a…
∗∗∗ TP-Link Systems Inc. VIGI Series IP Camera ∗∗∗
---------------------------------------------
Successful exploitation of this vulnerability could result in unauthorized users gaining administrative access to affected closed circuit television cameras.
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-01
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1058265/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 09-02-2026 18:00 − Dienstag 10-02-2026 18:00
Handler: Guenes Holler
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Hackers breach SmarterTools network using flaw in its own software ∗∗∗
---------------------------------------------
SmarterTools confirmed last week that the Warlock ransomware gang breached its network after compromising an email system, but did not impact business applications or account data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-breach-smartertools-…
∗∗∗ ZeroDayRAT malware grants full access to Android, iOS devices ∗∗∗
---------------------------------------------
A new commercial mobile spyware platform dubbed ZeroDayRAT is being advertised to cybercriminals on Telegram as a tool that provides full remote control over compromised Android and iOS devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/zerodayrat-malware-grants-fu…
∗∗∗ Trojaner an Bord: Mit Schadcode verseuchte 7-Zip-Version in Umlauf ∗∗∗
---------------------------------------------
Wer das Packprogramm 7-Zip herunterlädt, sollte dringend auf die korrekte Domain achten. Eine mit Malware verseuchte Version wurde gesichtet.
---------------------------------------------
https://www.golem.de/news/trojaner-an-bord-mit-schadcode-verseuchte-7-zip-v…
∗∗∗ Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact Data ∗∗∗
---------------------------------------------
The Netherlands Dutch Data Protection Authority (AP) and the Council for the Judiciary confirmed both agencies (Rvdr) have disclosed that their systems were impacted by cyber attacks that exploited the recently disclosed security flaws in Ivanti Endpoint Manager Mobile (EPMM), according to a notice sent to the countrys parliament on Friday.
---------------------------------------------
https://thehackernews.com/2026/02/dutch-authorities-confirm-ivanti-zero.html
∗∗∗ Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of an emergent ransomware family dubbed Reynolds that comes embedded with a built-in bring your own vulnerable driver (BYOVD) component for defense evasion purposes within the ransomware payload itself.
---------------------------------------------
https://thehackernews.com/2026/02/reynolds-ransomware-embeds-byovd-driver.h…
∗∗∗ More than 135,000 OpenClaw instances exposed to internet in latest vibe-coded disaster ∗∗∗
---------------------------------------------
By default, the bot listens on all network interfaces, and many users never change it Its a day with a name ending in Y, so you know what that means: Another OpenClaw cybersecurity disaster.
---------------------------------------------
https://www.theregister.com/2026/02/09/openclaw_instances_exposed_vibe_code/
∗∗∗ Introducing Augustus: Open Source LLM Prompt Injection Tool ∗∗∗
---------------------------------------------
Last month we released Julius, a tool that answers the question: “what LLM service is running on this endpoint?” Julius identifies the infrastructure. But identification is only the first step. The natural follow-up: “now that I know what’s running, how do I test whether it’s secure?” That’s what Augustus does.
---------------------------------------------
https://www.praetorian.com/blog/introducing-augustus-open-source-llm-prompt…
∗∗∗ Jetzt patchen! Abermals Attacken auf SolarWinds Web Help Desk beobachtet ∗∗∗
---------------------------------------------
Sicherheitsforschern zufolge nutzen Angreifer derzeit kritische Schadcode-Lücken in SolarWinds Web Help Desk aus.
---------------------------------------------
https://www.heise.de/news/Jetzt-patchen-Abermals-Attacken-auf-SolarWinds-We…
∗∗∗ Archive.today: Betreiber setzt Nutzer für DDoS-Attacke ein ∗∗∗
---------------------------------------------
Der Betreiber von Archive.today setzt Besucher seiner Seite unwissentlich für eine DDoS-Attacke. Betroffener ist ein finnischer Blogger.
---------------------------------------------
https://www.heise.de/news/Archive-today-Betreiber-setzt-Nutzer-fuer-DDoS-At…
∗∗∗ North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam ∗∗∗
---------------------------------------------
The scam involved a ClickFix attack where hackers install malware on a device by having the victim try to resolve fictitious technical issues.
---------------------------------------------
https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix
∗∗∗ Pride Month Phishing Targets Employees via Trusted Email Services ∗∗∗
---------------------------------------------
Attackers are using Pride Month themed phishing emails to target employees worldwide, abusing trusted email platforms like SendGrid to harvest credentials.
---------------------------------------------
https://hackread.com/pride-month-phishing-employees-trusted-email-services/
∗∗∗ New Cybercrime Group 0APT Accused of Faking Hundreds of Breach Claims ∗∗∗
---------------------------------------------
Researchers reveal the new 0APT cyber group is fabricating attacks on large organisations. Learn how they use fake data to trick companies into paying.
---------------------------------------------
https://hackread.com/cybercrime-group-0apt-faking-breach-claims/
∗∗∗ Beyond the Battlefield: Threats to the Defense Industrial Base ∗∗∗
---------------------------------------------
Introduction In modern warfare, the front lines are no longer confined to the battlefield; they extend directly into the servers and supply chains of the industry that safeguards the nation. Today, the defense sector faces a relentless barrage of cyber operations conducted by state-sponsored actors and criminal groups alike.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense…
∗∗∗ Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps ∗∗∗
---------------------------------------------
The purpose of this Alert is to amplify Poland’s Computer Emergency Response Team (CERT Polska’s) Energy Sector Incident Report published on Jan. 30, 2026, and highlight key mitigations for Energy Sector stakeholders.
---------------------------------------------
https://www.cisa.gov/news-events/alerts/2026/02/10/poland-energy-sector-cyb…
∗∗∗ Deep Dive into New XWorm Campaign Utilizing Multiple-Themed Phishing Emails ∗∗∗
---------------------------------------------
FortiGuard Labs recently captured a phishing campaign in the wild delivering a new variant of XWorm. XWorm is a multi-functional Remote Access Trojan (RAT) first identified in 2022 that remains actively distributed, including through Telegram-based marketplaces. Once deployed, it provides attackers with full remote control of compromised Windows systems.
---------------------------------------------
https://feeds.fortinet.com/~/945702296/0/fortinet/blogs~Deep-Dive-into-New-…
∗∗∗ Tech impersonators: ClickFix and MacOS infostealers ∗∗∗
---------------------------------------------
Datadog identified an active campaign employing fake GitHub repositories impersonating software companies and leveraging the ClickFix initial access technique to deliver macOS infostealers.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/tech-impersonators-clickfix-and…
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (fence-agents, firefox, fontforge, freerdp, kernel-rt, keylime, libsoup, libsoup3, nodejs22, nodejs24, opentelemetry-collector, osbuild-composer, python3.12-wheel, qemu-kvm, resource-agents, thunderbird, and util-linux), Debian (kernel, rlottie, shaarli, and usbmuxd), Fedora (asciinema, atuin, bustle, cef, envision, glycin, greetd, helix, java-21-openjdk, java-25-openjdk, java-latest-openjdk, keylime-agent-rust, maturin, mirrorlist-server, ntpd-rs, python3.6, rust-add-determinism, rust-afterburn, rust-ambient-id, rust-app-store-connect, rust-bat, rust-below, rust-btrd, rust-busd, rust-bytes, rust-cargo-c, rust-cargo-deny, rust-coreos-installer, rust-crypto-auditing-agent, rust-crypto-auditing-client, rust-crypto-auditing-event-broker, rust-crypto-auditing-log-parser, rust-dua-cli, rust-eif_build, rust-git-delta, rust-git-interactive-rebase-tool, rust-git2, rust-gst-plugin-dav1d, rust-gst-plugin-reqwest, rust-heatseeker, rust-ingredients, rust-jsonwebtoken, rust-lsd, rust-monitord, rust-monitord-exporter, rust-muvm, rust-nu, rust-num-conv, rust-onefetch, rust-oo7-cli, rust-pleaser, rust-pore, rust-pretty-git-prompt, rust-procs, rust-rbspy, rust-rbw, rust-rd-agent, rust-rd-hashd, rust-redlib, rust-resctl-bench, rust-resctl-demo, rust-routinator, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, rust-sequoia-chameleon-gnupg, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-sq, rust-sevctl, rust-shadow-rs, rust-sigul-pesign-bridge, rust-snpguest, rust-speakersafetyd, rust-tealdeer, rust-time, rust-time-core, rust-time-macros, rust-tokei, rust-weezl, rust-wiremix, rust-ybaas, rustup, sad, tbtools, tuigreet, and uv), Mageia (fontforge and nginx), Oracle (firefox, fontforge, freerdp, kernel, keylime, libsoup, python, thunderbird, and uek-kernel), SUSE (abseil-cpp and kernel), and Ubuntu (freerdp2 and libsoup3).
---------------------------------------------
https://lwn.net/Articles/1057993/
∗∗∗ XSS via back button ∗∗∗
---------------------------------------------
An Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability [CWE-79] in FortiSandbox may allow an unauthenticated attacker to execute commands via crafted requests. FortiSandbox PaaS versions 4.4.8 and 5.0.5 contains the fix for this vulnerability.
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-25-093
∗∗∗ Schwerwiegende Schwachstellen in Google Looker aufgedeckt ∗∗∗
---------------------------------------------
Noch ein kleiner Nachtrag zu einer Information, die mich vor einigen Tagen erreichte. Sicherheitsforscher von Tenable Research habe zwei schwerwiegende Sicherheitslücken in in Google Looker entdeckt und als "LookOut" bezeichnet. Angreifer können ganze Systeme kapern, um Firmengeheimnisse zu stehlen.
---------------------------------------------
https://borncity.com/blog/2026/02/09/schwerwiegende-schwachstellen-in-googl…
∗∗∗ February 2026 Security Update ∗∗∗
---------------------------------------------
Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program.
---------------------------------------------
https://www.ivanti.com/blog/february-2026-security-update
∗∗∗ Roundcube 1.7 RC3 released ∗∗∗
---------------------------------------------
We just published the third release candidate for the next major version 1.7 of Roundcube webmail. This release fixes two security issues, and contains a few more fixes for several issues.
---------------------------------------------
https://roundcube.net/news/2026/02/09/roundcube-1.7-rc3-released
∗∗∗ Attacken auf BeyondTrust Remote Support und Privileged Remote Access möglich ∗∗∗
---------------------------------------------
Zwei Fernwartungslösungen von BeyondTrust sind verwundbar. Sicherheitsupdates schließen eine kritische Lücke.
---------------------------------------------
https://heise.de/-11171444
∗∗∗ SAP Security Patch Day February 2026 ∗∗∗
---------------------------------------------
SAP has released its February 2026 security patch package containing 27 security notes addressing critical vulnerabilities across enterprise SAP environments. This release includes two HotNews vulnerabilities with CVSS ratings up to 9.9, seven High priority issues, sixteen Medium priority fixes, and two Low priority updates.
---------------------------------------------
https://redrays.io/blog/sap-security-patch-day-february-2026/
∗∗∗ Yokogawa FAST/TOOLS ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-01
∗∗∗ AVEVA PI Data Archive ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-03
∗∗∗ ZLAN Information Technology Co. ZLAN5143D ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-041-02
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/