=====================
= End-of-Day report =
=====================
Timeframe: Freitag 09-01-2026 18:00 − Montag 12-01-2026 18:00
Handler: Felician Fuchs
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Max severity Ni8mare flaw impacts nearly 60,000 n8n instances ∗∗∗
---------------------------------------------
Nearly 60,000 n8n instances exposed online remain unpatched against a maximum-severity vulnerability dubbed "Ni8mare."
---------------------------------------------
https://www.bleepingcomputer.com/news/security/max-severity-ni8mare-flaw-im…
∗∗∗ Spanish energy giant Endesa discloses data breach affecting customers ∗∗∗
---------------------------------------------
Spanish energy provider Endesa and its Energía XXI operator are notifying customers that hackers accessed the companys systems and accessed contract-related information, which includes personal details.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/spanish-energy-giant-endesa-…
∗∗∗ Hidden Telegram proxy links can reveal your IP address in one click ∗∗∗
---------------------------------------------
A single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add warnings to proxy links after researchers demonstrated that such one-click interactions could reveal a Telegram users real IP address.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hidden-telegram-proxy-links-…
∗∗∗ Illicit Crypto Economy Surges Amid Increased Nation-State Activity ∗∗∗
---------------------------------------------
Cybercriminal cryptocurrency transactions totaled billions in 2025, with activity from sanctioned countries like Russia and Iran causing the largest jump.
---------------------------------------------
https://www.darkreading.com/cyber-risk/illicit-crypto-economy-surges-nation…
∗∗∗ Russia’s Fancy Bear APT Doubles Down on Global Secrets Theft ∗∗∗
---------------------------------------------
The notorious state-sponsored group relies on basic techniques that are highly effective, often delivering greater ROI than more complex malware-heavy operations.
---------------------------------------------
https://www.darkreading.com/cyberattacks-data-breaches/russian-apt-credenti…
∗∗∗ Two Separate Campaigns Target Exposed LLM Services ∗∗∗
---------------------------------------------
A total of 91,403 sessions targeted public LLM endpoints to find leaks in organizations use of AI and map an expanding attack surface.
---------------------------------------------
https://www.darkreading.com/endpoint-security/separate-campaigns-target-exp…
∗∗∗ Cybersecurity Act: EU-Kommission will hartes Verbot von Huawei ∗∗∗
---------------------------------------------
Bisher freiwillige Beschränkungen gegen chinesische Ausrüster will die EU-Kommission nun zwangsweise umsetzen. Das ist in der EU stark umstritten und erscheint aus der Zeit gefallen.
---------------------------------------------
https://www.golem.de/news/cybersecurity-act-eu-kommission-will-hartes-verbo…
∗∗∗ Lohnabrechnungen falsch verschickt: DSGVO-Vorfall bei der Datev ∗∗∗
---------------------------------------------
Nach einer technischen Störung bei der Datev-Lohnabrechnung sind Kundendaten in falsche Hände gelangt. Auslöser war ausgerechnet ein Problemlösungsversuch.
---------------------------------------------
https://www.golem.de/news/lohnabrechnungen-falsch-verschickt-dsgvo-vorfall-…
∗∗∗ Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud ∗∗∗
---------------------------------------------
Cybersecurity researchers have shed light on two service providers that supply online criminal networks with the necessary tools and infrastructure to fuel the pig butchering-as-a-service (PBaaS) economy.
---------------------------------------------
https://thehackernews.com/2026/01/researchers-uncover-service-providers.html
∗∗∗ GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials ∗∗∗
---------------------------------------------
A new wave of GoBruteforcer attacks has targeted databases of cryptocurrency and blockchain projects to co-opt them into a botnet thats capable of brute-forcing user passwords for services such as FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux servers.
---------------------------------------------
https://thehackernews.com/2026/01/gobruteforcer-botnet-targets-crypto.html
∗∗∗ UK government exempting itself from flagship cyber law inspires little confidence ∗∗∗
---------------------------------------------
Ministers promise equivalent standards just without the legal obligation ANALYSIS From Mays cyberattack on the Legal Aid Agency to the Foreign Office breach months later, cyber incidents have become increasingly common in UK government.
---------------------------------------------
https://www.theregister.com/2026/01/10/csr_bill_analysis/
∗∗∗ Instagram-Datenleck: Daten von 6,2 Millionen Konten bei Have-I-Been-Pwned ∗∗∗
---------------------------------------------
Daten von 6,2 Millionen Instagram-Nutzern sind beim Have-I-Been-Pwned-Projekt gelandet.
---------------------------------------------
https://www.heise.de/news/Instagram-6-2-Millionen-Nutzerdaten-mittels-Scrap…
∗∗∗ ÖIAT-Schwerpunkterhebung deckt auf: Massive Präsenz von Abo-Fallen in Google-Anzeigen ∗∗∗
---------------------------------------------
Bei einer eingehenden Analyse der Google Werbebibliothek entdeckte das Österreichische Institut für angewandte Telekommunikation (ÖIAT) eine große Menge an gefährlichen Ads. Insgesamt waren es weit über 27.000 problematische Werbeanzeigen, die als Köder für Abo-Fallen dienten. Auf Beschwerden reagierte Google bisher nicht.
---------------------------------------------
https://www.watchlist-internet.at/news/schwerpunkterhebung-abo-fallen-googl…
∗∗∗ Basketball player arrested for alleged ransomware ties freed in Russia-France prisoner swap ∗∗∗
---------------------------------------------
Daniil Kasatkin, 26, was seen in a video shared by Russian state news outlet TASS emerging from a plane that was then used to send French researcher Laurent Vinatier back to France.
---------------------------------------------
https://therecord.media/france-frees-russian-basketball-player-ransomware-s…
∗∗∗ MC1215070: MFA für Microsoft 365 Admin Center ab Feb. 2026 Pflicht ∗∗∗
---------------------------------------------
Noch eine kurze Information für Administratoren von Microsoft 365-Tenants. Microsoft erzwingt aus Sicherheitsgründen ab dem 9. Februar 2026 eine Multifaktor-Authentifizierung (MFA) zur Administratoranmeldung am Microsoft 365 Admin Center. Ohne entsprechende Maßnahmen scheitert dann die Anmeldung.
---------------------------------------------
https://borncity.com/blog/2026/01/11/mc1215070-mfa-fuer-microsoft-365-admin…
∗∗∗ Database of 323,986 BreachForums Users Leaked as Admin Disputes Scope ∗∗∗
---------------------------------------------
Database of 323,986 BreachForums users leaked online as forum admins claim the exposed data is partial and dates back to August 2025.
---------------------------------------------
https://hackread.com/breachforums-database-users-leak-admin-disputes/
∗∗∗ Everest Ransomware Claims Breach at Nissan, Says 900GB of Data Stolen ∗∗∗
---------------------------------------------
Everest ransomware claims to have breached Nissan Motor Corporation, alleging the theft of 900GB of internal data, including documents and screenshots.
---------------------------------------------
https://hackread.com/everest-ransomware-nissan-data-breach/
∗∗∗ How Safe is the Rust Ecosystem? A Deep Dive into crates.io ∗∗∗
---------------------------------------------
The relentless wave of high-impact supply chain attacks throughout 2025—most notably the major incident within npm [..] —suggests this trend is far from peaking. In fact, with the rapid adoption of AI and LLMs in development workflows, we are likely facing an acceleration of these threats rather than a decline, in my opinion.
---------------------------------------------
https://mr-leshiy-blog.web.app/blog/crates_io_analysis/
∗∗∗ Detection of Kerberos Golden Ticket Attacks via Velociraptor ∗∗∗
---------------------------------------------
Kerberos is a strange technology. Over the years, I’ve gone through its internal workings again and again, yet parts of it always seem to slip away. It has been a while since I did my OSCP, so inevitably I’ve found myself back in this topic to refresh my knowledge.
---------------------------------------------
https://detect.fyi/detection-of-kerberos-golden-ticket-attacks-via-velocira…
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdate: Dell-Laptops mit Adreno-GPU sind verwundbar ∗∗∗
---------------------------------------------
Der Treiber von Qualcomms Adreno GPU ist löchrig und gefährdet die Sicherheit verschiedener Dell-Laptops. Ein reparierter Treiber steht zum Download bereit.
---------------------------------------------
https://www.heise.de/news/Sicherheitsupdate-Dell-Laptops-mit-Adreno-GPU-sin…
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (chromium and sogo), Fedora (chromium, foomuuri, libpng, libsodium, mariadb10.11, musescore, nginx, python-pdfminer, python-urllib3, python3.12, seamonkey, wasmedge, and wget2), Mageia (curl, libpcap, sodium, wget2, and zlib), Slackware (lcms2), SUSE (chromedriver, chromium, noopenh264, coredns, curl, dcmtk, fontforge, gdk-pixbuf-loader-libheif, gimp, kernel, libheif, libpng16, libsoup-2_4-1, libvirt, mariadb, php8, poppler, python-filelock, python-tornado6, python311-aiohttp, qemu, sssd, and traefik), and Ubuntu (libheif, libtasn1-6, linux-azure-nvidia, linux-kvm, linux-raspi, linux-raspi-realtime, and php7.2, php7.4, php8.1, php8.3, php8.4).
---------------------------------------------
https://lwn.net/Articles/1053820/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 08-01-2026 18:00 − Freitag 09-01-2026 18:00
Handler: Felician Fuchs
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ VMware ESXi zero-days likely exploited a year before disclosure ∗∗∗
---------------------------------------------
Chinese-speaking threat actors used a compromised SonicWall VPN appliance to deliver a VMware ESXi exploit toolkit that seems to have been developed more than a year before the targeted vulnerabilities became publicly known.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/vmware-esxi-zero-days-likely…
∗∗∗ FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs ∗∗∗
---------------------------------------------
The North Korean state-sponsored hacker group Kimsuki is using malicious QR codes in spearphishing campaigns that target U.S. organizations, the Federal Bureau of Investigation warns in a flash alert.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/fbi-warns-about-kimsuky-hack…
∗∗∗ New China-linked hackers breach telcos using edge device exploits ∗∗∗
---------------------------------------------
A sophisticated threat actor that uses Linux-based malware to target telecommunications providers has recently broadened its operations to include organizations in Southeastern Europe.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-china-linked-hackers-bre…
∗∗∗ Defeating KASLR by Doing Nothing at All ∗∗∗
---------------------------------------------
I’ve recently been researching Pixel kernel exploitation and as part of this research I found myself with an excellent arbitrary write primitive…but without a KASLR leak. As necessity is the mother of all invention, on a hunch, I started researching the Linux kernel linear mapping.
---------------------------------------------
https://projectzero.google/2025/11/defeating-kaslr-by-doing-nothing-at-all.…
∗∗∗ Google Sees Spam, You See Your Site: A Cloaked SEO Spam Attack ∗∗∗
---------------------------------------------
We recently handled a case where a customer reported strange SEO behavior on their website. Regular visitors saw a normal site. No popups. No redirects. No visible spam. However, when they checked their site on Google, the search results were flooded with eBay-type-looking websites and “Situs Toto” gambling spam. This is a professional-grade SEO cloaking attack.
---------------------------------------------
https://blog.sucuri.net/2026/01/google-sees-spam-you-see-your-site-a-cloake…
∗∗∗ Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations ∗∗∗
---------------------------------------------
Russian state-sponsored threat actors have been linked to a fresh set of credential harvesting attacks targeting individuals associated with a Turkish energy and nuclear research agency, as well as staff affiliated with a European think tank and organizations in North Macedonia and Uzbekistan.
---------------------------------------------
https://thehackernews.com/2026/01/russian-apt28-runs-credential-stealing.ht…
∗∗∗ Auslegungssache 150: Auf digitaler Spurensuche ∗∗∗
---------------------------------------------
Im ct-Datenschutz-Podcast erklärt eine IT-Forensikerin, wie sie nach Vorfällen Spuren sichert, mit Erpressern verhandelt und den Datenschutz im Blick behält.
---------------------------------------------
https://www.heise.de/hintergrund/Auslegungssache-150-Auf-digitaler-Spurensu…
∗∗∗ Von München bis Sevilla: Internationaler Schlag gegen Cyber-Mafia „Black Axe“ ∗∗∗
---------------------------------------------
Ermittlern gelang in Spanien ein empfindlicher Schlag gegen die als „Black Axe“ bekannte nigerianische Cyber-Mafia.
---------------------------------------------
https://www.heise.de/news/Von-Muenchen-bis-Sevilla-Internationaler-Schlag-g…
∗∗∗ Who Benefited from the Aisuru and Kimwolf Botnets? ∗∗∗
---------------------------------------------
Our first story of 2026 revealed how a destructive new botnet called Kimwolf rapidly grew to infect more than two million devices by mass-compromising a vast number of unofficial Android TV streaming boxes. Today, well dig through digital clues left behind by the hackers, network operators, and cybercrime services that appear to have benefitted from Kimwolfs spread.
---------------------------------------------
https://krebsonsecurity.com/2026/01/who-benefited-from-the-aisuru-and-kimwo…
∗∗∗ CPPA fines data broker selling lists of Alzheimers patients ∗∗∗
---------------------------------------------
Datamasters bought and resold the names, addresses, phone numbers and email addresses of millions of people with Alzheimer’s disease, drug addiction, bladder incontinence and other medical conditions for targeted advertising, according to the CPPA.
---------------------------------------------
https://therecord.media/ccpa-fines-data-broker-selling-lists-alzheimers
∗∗∗ Russian Hacktivists hack CCTV Cameras in Denmark ∗∗∗
---------------------------------------------
The hacktivists had recorded part of the video stream from the CCTV as proof of the hack and published it. It was reported that no individuals were identifiable on the recording.
---------------------------------------------
https://www.truesec.com/hub/blog/russian-hacktivists-hack-cctv-cameras-in-d…
∗∗∗ CISCO-Switches gehen wegen DNS-Fehler in Boot-Schleifen ∗∗∗
---------------------------------------------
Weltweit kämpfen Administratoren wohl damit, dass bestimmte Switches des Herstellers CISCO in einer Neustart-Schleife (Boot-Loop) gefangen sind. Das tritt auf, nachdem die Geräte einen DNS-Client-Fehler protokolliert haben.
---------------------------------------------
https://borncity.com/blog/2026/01/09/cisco-switches-gehen-wegen-dns-fehler-…
∗∗∗ Hacker Behind Wired.com Leak Now Selling Full 40M Condé Nast Records ∗∗∗
---------------------------------------------
A hacker claims to be selling nearly 40 million Condé Nast user records after leaking Wired.com data, with multiple major brands allegedly affected.
---------------------------------------------
https://hackread.com/wired-com-hacker-data-leak-conde-nast-records/
∗∗∗ Threat Actors Actively Targeting LLMs ∗∗∗
---------------------------------------------
Our Ollama honeypot infrastructure captured 91,403 attack sessions between October 2025 and January 2026. Buried in that data: two distinct campaigns that reveal how threat actors are systematically mapping the expanding surface area of AI deployments.
---------------------------------------------
https://www.greynoise.io/blog/threat-actors-actively-targeting-llms
∗∗∗ Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691) ∗∗∗
---------------------------------------------
Welcome to 2026! While we are all waiting for the scheduled SSLVPN ITW exploitation programming that occurs every January, we’re back from Christmas and idle hands, idle minds, yada yada. In December, we were alerted to a vulnerability in SmarterTools’ SmarterMail solution, accompanied by an advisory from Singapore’s Cyber Security Agency (CSA) - CVE-2025-52691, a pre-auth RCE that obtained full marks (10/10) on the industry’s scale.
---------------------------------------------
https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertoo…
∗∗∗ Fake Windows Update and BSOD Alerts Used in a Tech Support Scam ∗∗∗
---------------------------------------------
While reviewing submissions received through the WordPress feedback form on my website, I came across a URL that initially appeared unremarkable. Such submissions are common and often contain benign questions or comments, but this particular link stood out enough to warrant closer inspection.
---------------------------------------------
https://malwr-analysis.com/2026/01/09/fake-windows-update-and-bsod-alerts-u…
=====================
= Vulnerabilities =
=====================
∗∗∗ VU#361400: BeeS Software Solutions BeeS Examination Tool (BET) portal contains SQL injection vulnerability ∗∗∗
---------------------------------------------
The BeeS Examination Tool (BET) portal from BeeS Software Solutions contains an SQL injection vulnerability in its website login functionality. More than 100 universities use the BET portal for test administration and other academic tasks.
---------------------------------------------
https://kb.cert.org/vuls/id/361400
∗∗∗ RICOH Streamline NX vulnerable to improper authorization ∗∗∗
---------------------------------------------
RICOH Streamline NX provided by Ricoh Company, Ltd. contains an improper authorization vulnerability.
---------------------------------------------
https://jvn.jp/en/jp/JVN12770174/
∗∗∗ Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions ∗∗∗
---------------------------------------------
Trend Micro has released security updates to address multiple security vulnerabilities impacting on-premise versions of Apex Central for Windows, including a critical bug that could result in arbitrary code execution. The vulnerability, tracked as CVE-2025-69258, carries a CVSS score of 9.8 out of a maximum of 10.0.
---------------------------------------------
https://thehackernews.com/2026/01/trend-micro-apex-central-rce-flaw.html
∗∗∗ Mediaplayer VLC: Aktualisierte Version stopft zahlreiche Lücken ∗∗∗
---------------------------------------------
Die Version 3.0.23 des VLC Media Player bessert diverse Schwachstellen aus, die möglicherweise Unterschieben von Schadcode erlauben.
---------------------------------------------
https://www.heise.de/news/VLC-stopft-diverse-Sicherheitslecks-11135921.html
∗∗∗ Security updates for Friday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (pdfminer and vlc), Red Hat (kernel, kernel-rt, and microcode_ctl), Slackware (libtasn1), SUSE (apptainer, curl, ImageMagick, libpcap, libvirt, libwget4, php8, podman, python311-cbor2, qemu, and rsync), and Ubuntu (gnupg, gnupg2, gpsd, libsodium, and python-tornado).
---------------------------------------------
https://lwn.net/Articles/1053492/
∗∗∗ Hitachi Energy Asset Suite ∗∗∗
---------------------------------------------
Hitachi Energy is aware of a Jasper Report vulnerability that affects the Asset Suite product versions mentioned in this document below. This vulnerability can be exploited to carry out remote code execution (RCE) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-008-01
∗∗∗ K000159018: Linux kernel vulnerability CVE-2023-53178 ∗∗∗
---------------------------------------------
A local unprivileged user may exploit this vulnerability and cause data integrity issues or system instability under specific conditions.
---------------------------------------------
https://my.f5.com/manage/s/article/K000159018
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 07-01-2026 18:00 − Donnerstag 08-01-2026 18:00
Handler: Felician Fuchs
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ New GoBruteforcer attack wave targets crypto, blockchain projects ∗∗∗
---------------------------------------------
A new wave of GoBruteforcer botnet malware attacks is targeting databases of cryptocurrency and blockchain projects on exposed servers believed to be configured using AI-generated examples.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-gobruteforcer-attack-wav…
∗∗∗ Cisco warns of Identity Service Engine flaw with exploit code ∗∗∗
---------------------------------------------
Cisco has patched an ISE vulnerability with public proof-of-concept exploit code that can be abused by attackers with admin privileges.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-serv…
∗∗∗ Dringend MFA aktivieren: Massenhaft Daten aus Cloud-Instanzen abgeflossen ∗∗∗
---------------------------------------------
Betroffen sind self-hosted Instanzen von Owncloud, Nextcloud und Sharefile. Daten von 50 Organisationen stehen zum Verkauf, weil die MFA nicht aktiv war.
---------------------------------------------
https://www.golem.de/news/dringend-mfa-aktivieren-massenhaft-daten-aus-clou…
∗∗∗ NIS-2-Umsetzung: BSI schaltet Meldeportal auf Amazon-Servern frei ∗∗∗
---------------------------------------------
Fast 30.000 Firmen und Behörden der kritischen Infrastruktur müssen sich beim BSI registrieren. Das Portal läuft auf Clouddiensten von AWS.
---------------------------------------------
https://www.golem.de/news/nis-2-umsetzung-bsi-schaltet-meldeportal-auf-amaz…
∗∗∗ BSI warnt: 40 Prozent der deutschen Zimbra-Server sind angreifbar ∗∗∗
---------------------------------------------
Ein Großteil aller Zimbra-Server in Deutschland basiert noch auf einer veralteten Version, die anfällig für gefährliche Sicherheitslücken ist.
---------------------------------------------
https://www.golem.de/news/bsi-warnt-40-prozent-der-deutschen-zimbra-server-…
∗∗∗ Fake Browser Updates Targeting WordPress Administrators via Malicious Plugin ∗∗∗
---------------------------------------------
We recently investigated a case involving a WordPress website where a customer reported persistent fake pop-up notifications appearing on their site. The warnings were urging them to update their browser (Chrome or Firefox), even though their software was already fully up-to-date.
---------------------------------------------
https://blog.sucuri.net/2026/01/fake-browser-updates-targeting-wordpress-ad…
∗∗∗ CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited ∗∗∗
---------------------------------------------
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
---------------------------------------------
https://thehackernews.com/2026/01/cisa-flags-microsoft-office-and-hpe.html
∗∗∗ Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered three malicious npm packages that are designed to deliver a previously undocumented malware called NodeCordRAT.
---------------------------------------------
https://thehackernews.com/2026/01/researchers-uncover-nodecordrat-hidden.ht…
∗∗∗ IBMs AI agent Bob easily duped to run malware, researchers show ∗∗∗
---------------------------------------------
Prompt injection lets risky commands slip past guardrails IBM describes its coding agent thus: "Bob is your AI software development partner that understands your intent, repo, and security standards." Unfortunately, Bob doesnt always follow those security standards.
---------------------------------------------
https://www.theregister.com/2026/01/07/ibm_bob_vulnerability/
∗∗∗ Gemeinsam gegen Cyber-Kriminalität: Info-Offensive zum ESC-Ticketkauf ∗∗∗
---------------------------------------------
Vor dem Start der ersten Ticket-Verkaufswelle am 13. Jänner sensibilisieren ORF, EBU, BMI, Stadt Wien, Polizei und „Watchlist Internet“ für Cyber-Gefahren und richten eine zentrale Meldestelle für Betrugsversuche ein.
---------------------------------------------
https://www.watchlist-internet.at/news/gemeinsam-gegen-cyber-kriminalitaet-…
∗∗∗ Stalkerware operator pleads guilty in rare prosecution ∗∗∗
---------------------------------------------
The owner of a Michigan-based stalkerware company pleaded guilty to federal charges for selling a product designed to spy on people without their consent.
---------------------------------------------
https://therecord.media/stalkerware-guilty-plea-fleming
∗∗∗ Fake ChatGPT and DeepSeek Extensions Spied on Over 1 Million Chrome Users ∗∗∗
---------------------------------------------
Security researchers have identified two malicious Chrome extensions recording AI chats. Learn how to identify and remove these tools to protect your privacy.
---------------------------------------------
https://hackread.com/fake-chatgpt-deepseek-extensions-spy-chrome-users/
∗∗∗ Discord Controlled NodeCordRAT Steals Chrome Data via NPM Packages ∗∗∗
---------------------------------------------
Zscaler ThreatLabz identifies three malicious NPM packages mimicking Bitcoin libraries. The NodeCordRAT virus uses Discord commands to exfiltrate MetaMask data and Chrome passwords.
---------------------------------------------
https://hackread.com/discord-nodecordrat-steal-chrome-data-npm-packages/
∗∗∗ The Ransomware Ground Game: How A Christmas Scanning Campaign Will Fuel 2026 Attacks ∗∗∗
---------------------------------------------
Over four days in December, one operator scanned the internet with 240+ exploits, logging confirmed vulnerabilities that could power targeted intrusions in 2026.
---------------------------------------------
https://www.greynoise.io/blog/christmas-scanning-campaign-fuel-2026-attacks
∗∗∗ Decoding the GitHub recommendations for npm maintainers ∗∗∗
---------------------------------------------
This blog post explores the rationale and implementation behind GitHubs security recommendations for npm maintainers following numerous high-profile supply-chain incidents. It details how hardening publishing infrastructure through trusted publishing, enforced two-factor authentication, and WebAuthn-based protocols can meaningfully increase the resilience of the ecosystem.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/decoding-the-recommendations-fo…
∗∗∗ Abusing ROPC to Bypass MFA — and How I Built a Detection for It in Microsoft Sentinel ∗∗∗
---------------------------------------------
Among all the OAuth2 grant types available in Azure AD (now Microsoft Entra ID), the Resource Owner Password Credential (ROPC) flow remains one of the most misunderstood — and most abused.
---------------------------------------------
https://detect.fyi/abusing-ropc-to-bypass-mfa-and-how-i-built-a-detection-f…
∗∗∗ Preparing for Post-Quantum Cryptography ∗∗∗
---------------------------------------------
Learn what you can do today to prepare for Q-Day.
---------------------------------------------
https://www.wiz.io/blog/preparing-for-post-quantum-cryptography
∗∗∗ npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens ∗∗∗
---------------------------------------------
The JavaScript ecosystem spent much of 2025 responding to a sustained run of supply chain attacks, but it was the multi-wave Shai-Hulud campaign that ultimately reset expectations for what large-scale, automated compromise looks like. By the end of the year, organizations with JavaScript-heavy infrastructure were no longer treating supply chain malware as an edge case, but as an operational risk that could spread faster than human review. Now, npm says it is preparing its next major response.
---------------------------------------------
https://socket.dev/blog/npm-to-implement-staged-publishing
∗∗∗ Crimson Collective Claims to Disconnect Brightspeed Internet Users After Hack ∗∗∗
---------------------------------------------
The hacking group Crimson Collective claims to have access to Brightspeed’s infrastructure and is disconnecting users from the company’s home internet services. The group made its latest claims in a post on Telegram yesterday. “Hey BrightSpeed, we disconnected alot of your users home internet.. they might be complaining you should check,” the Telegram post says.
---------------------------------------------
https://thecyberexpress.com/crimson-collective-disconnects-brightspeed/
∗∗∗ Trump Orders US Exit from Global Cyber and Hybrid Threat Coalitions ∗∗∗
---------------------------------------------
President Donald Trump has ordered the immediate withdrawal of the United States from several premier international bodies dedicated to cybersecurity, digital human rights, and countering hybrid warfare, as part of a major restructuring of American defense and diplomatic posture.
---------------------------------------------
https://thecyberexpress.com/trump-orders-us-exit-from-cyber-coalitions/
∗∗∗ UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan ∗∗∗
---------------------------------------------
The UK government has revealed the Government Cyber Action Plan as a renewed effort to close the growing gap between escalating cyber threats and the public sector’s ability to respond effectively. The move comes amid a series of cyberattacks targeting UK retail and manufacturing sectors, incidents that have underscored broader vulnerabilities affecting critical services and government operations.
---------------------------------------------
https://thecyberexpress.com/uk-government-cyber-action-plan/
=====================
= Vulnerabilities =
=====================
∗∗∗ Max severity Ni8mare flaw lets hackers hijack n8n servers ∗∗∗
---------------------------------------------
A maximum severity vulnerability dubbed "Ni8mare" allows remote, unauthenticated attackers to take control over locally deployed instances of the N8N workflow automation platform.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/max-severity-ni8mare-flaw-le…
∗∗∗ Critical jsPDF flaw lets hackers steal secrets via generated PDFs ∗∗∗
---------------------------------------------
The jsPDF library for generating PDF documents in JavaScript applications is vulnerable to a critical vulnerability that allows an attacker to steal sensitive data from the local filesystem by including it in generated files.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-jspdf-flaw-lets-hac…
∗∗∗ The installers for multiple PIONEER products may insecurely load Dynamic Link Libraries ∗∗∗
---------------------------------------------
The installers for multiple products provided by PIONEER CORPORATION may insecurely load Dynamic Link Libraries. Arbitrary code may be executed with the privileges of the running installer.
---------------------------------------------
https://jvn.jp/en/jp/JVN17956874/
∗∗∗ zlib: Kritische Sicherheitslücke ermöglicht Codeschmuggel – noch kein Update ∗∗∗
---------------------------------------------
In einem Werkzeug der Kompressionsbibliothek zlib, die in zahlreichen Programmen und Betriebssystemen enthalten ist, haben IT-Forscher eine kritische Sicherheitslücke entdeckt. Sie ermöglicht unter Umständen das Einschleusen und Ausführen von Schadcode. Ein Update zum Stopfen des Sicherheitslecks gibt es bislang noch nicht.
---------------------------------------------
https://www.heise.de/news/zlib-Kritische-Sicherheitsluecke-ermoeglicht-Code…
∗∗∗ Sieben kritische Sicherheitslücken mit Höchstwertung bedrohen Coolify ∗∗∗
---------------------------------------------
Admins von Platform-as-a-Service-Umgebungen auf der Basis von Coolify sollten ihre Instanzen zügig auf den aktuellen Stand bringen. Geschieht das nicht, können Angreifer unter anderem an sieben „kritischen“ Sicherheitslücken mit Höchstwertung (CVSS Score 10 von 10) ansetzen, um Server vollständig zu kompromittieren.
---------------------------------------------
https://www.heise.de/news/Sieben-kritische-Sicherheitsluecken-mit-Hoechstwe…
∗∗∗ Kanboard-Sicherheitslücke ermöglicht Anmeldung als beliebiger User ∗∗∗
---------------------------------------------
Das Open-Source-Kanban Kanboard ist von drei Schwachstellen betroffen. Eine davon gilt den Entwicklern als kritisches Risiko und ermöglicht die Anmeldung als beliebiger User – sofern eine bestimmte Konfigurationsoption gesetzt ist.
---------------------------------------------
https://www.heise.de/news/Kanboard-Sicherheitsluecke-ermoeglicht-Anmeldung-…
∗∗∗ Security updates for Thursday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gcc-toolset-14-binutils, gcc-toolset-15-binutils, httpd, kernel, libpng, mariadb, mingw-libpng, poppler, python3.12, and ruby:3.3), Debian (foomuuri and libsodium), Fedora (python-pdfminer and wget2), Oracle (audiofile, bind, gcc-toolset-15-binutils, libpng, mariadb, mariadb10.11, mariadb:10.11, mariadb:10.5, mingw-libpng, poppler, and python3.12), Red Hat (git-lfs, kernel, libpng, libpq, mariadb:10.3, osbuild-composer, postgresql, postgresql:13, and postgresql:15), Slackware (curl), SUSE (c-ares-devel, capstone, curl, gpsd, ImageMagick, libpcap, log4j, python311-filelock, and python314), and Ubuntu (libcaca, libxslt, and net-snmp).
---------------------------------------------
https://lwn.net/Articles/1053277/
∗∗∗ [R1] Nessus Agent Versions 11.0.3 and 10.9.3 Fix One Vulnerability ∗∗∗
---------------------------------------------
A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges. Tenable has released Nessus Agent 11.0.3 and Nessus Agent 10.9.3 to address these issues.
---------------------------------------------
https://www.tenable.com/security/tns-2026-01
∗∗∗ CVE-2025-42877: Memory Corruption in SAP Web Dispatcher ∗∗∗
---------------------------------------------
SAP Web Dispatcher and Internet Communication Manager (ICM) contain a critical memory corruption vulnerability in the HTTP header parsing function. The vulnerability allows an unauthenticated attacker to cause heap corruption and lead to Denial of Service through specially crafted HTTP requests.
---------------------------------------------
https://redrays.io/blog/cve-2025-42877-sap-web-dispatcher-memory-corruption…
∗∗∗ Case opened: DIVD-2025-00011 - Severe vulnerabilities in Growatt portal ∗∗∗
---------------------------------------------
https://csirt.divd.nl/cases/DIVD-2025-00011/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 05-01-2026 18:00 − Mittwoch 07-01-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ New D-Link flaw in legacy DSL routers actively exploited in attacks ∗∗∗
---------------------------------------------
Threat actors are exploiting a recently discovered command injection vulnerability that affects multiple D-Link DSL gateway routers that went out of support years ago.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-d-link-flaw-in-legacy-ds…
∗∗∗ ownCloud urges users to enable MFA after credential theft reports ∗∗∗
---------------------------------------------
File-sharing platform ownCloud warned users today to enable multi-factor authentication (MFA) to block attackers using compromised credentials from stealing their data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/owncloud-urges-users-to-enab…
∗∗∗ Microsoft: Classic Outlook bug prevents opening encrypted emails ∗∗∗
---------------------------------------------
Microsoft has confirmed a known issue that prevents recipients from opening encrypted emails in classic Outlook.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-classic-outlook-b…
∗∗∗ Founder of Spyware Maker PcTattletale Pleads Guilty To Hacking, Advertising Surveillance Software ∗∗∗
---------------------------------------------
An anonymous reader quotes a report from TechCrunch: The founder of a U.S.-based spyware company, whose surveillance products allowed customers to spy on the phones and computers of unsuspecting victims, pleaded guilty to federal charges linked to his long-running operation. pcTattletale founder Bryan Fleming entered a guilty plea in a San Diego federal ..
---------------------------------------------
https://yro.slashdot.org/story/26/01/07/0033238/founder-of-spyware-maker-pc…
∗∗∗ UK injects just £210M into cyber plan to stop Whitehall getting pwnd ∗∗∗
---------------------------------------------
Central government will supposedly be as secure as energy facilities and datacenters under new proposals The UK today launches its Government Cyber Action Plan, committing £210 million ($282 million) to strengthen defenses across digital public services and hold itself to the same cybersecurity standards its imposing on critical infrastructure operators.
---------------------------------------------
https://www.theregister.com/2026/01/06/government_cyber_action_plan/
∗∗∗ Malicious NPM Packages Deliver NodeCordRAT ∗∗∗
---------------------------------------------
Zscaler ThreatLabz regularly monitors the npm database for suspicious packages. In November 2025, ThreatLabz identified three malicious packages: bitcoin-main-lib, bitcoin-lib-js, and bip40. The bitcoin-main-lib and bitcoin-lib-js packages execute a postinstall.cjs script during installation, which installs bip40, the package that contains the ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/malicious-npm-packages-deli…
∗∗∗ CISA-Katalog attackierter Schwachstellen wuchs 2025 um 20 Prozent ∗∗∗
---------------------------------------------
Die US-amerikanische IT-Sicherheitsbehörde CISA pflegt einen Katalog angegriffener Schwachstellen. Der wuchs 2025 etwas schneller.
---------------------------------------------
https://www.heise.de/news/CISA-Katalog-attackierter-Schwachstellen-wuchs-20…
∗∗∗ Patchday: Dolby-Digital-Sicherheitslücke in Android geschlossen ∗∗∗
---------------------------------------------
Androidgeräte sind für eine Zero-Click-Attacke anfällig. Dieses Sicherheitsproblem wurde nun gelöst.
---------------------------------------------
https://www.heise.de/news/Patchday-Dolby-Digital-Sicherheitsluecke-in-Andro…
∗∗∗ Ubiquiti UniFi Protect: Sicherheitslücke ermöglicht Zugriff auf Kameras ∗∗∗
---------------------------------------------
In der UniFi Protect Application können Angreifer Schwachstellen für unbefugten Zugriff auf Kameras und DoS-Attacken missbrauchen.
---------------------------------------------
https://www.heise.de/news/Ubiquiti-UniFi-Protect-Sicherheitsluecke-ermoegli…
∗∗∗ Mehrere Sicherheitslücken bedrohen Veeam Back & Replication ∗∗∗
---------------------------------------------
Ein wichtiges Sicherheitsupdate schließt mehrere Schwachstellen in Veeam Back & Replication. Bislang sind keine Attacken bekannt.
---------------------------------------------
https://www.heise.de/news/Mehrere-Sicherheitsluecken-bedrohen-Veeam-Back-Re…
∗∗∗ Krypto-Phishing mit angeblicher Mail des Bundeszentralamts für Steuern ∗∗∗
---------------------------------------------
Eine aktuelle Phishing-Welle behauptet Abweichungen bei „Krypto-Angaben“ beim Bundeszentralamt für Steuern.
---------------------------------------------
https://www.heise.de/news/Krypto-Phishing-mit-angeblicher-Mail-des-Bundesze…
∗∗∗ 2025, the year of the Infostealer ∗∗∗
---------------------------------------------
TL;DR Introduction Infostealers are not new malware. They have been around for decades. What has changed is how effective they have become, and how easily they blend into normal user behaviour. In 2025, infostealers became the fastest growing malware category, overtaking ransomware in terms of deployment and spread. The H1 2025 reports highlighted a sharp rise in simple ..
---------------------------------------------
https://www.pentestpartners.com/security-blog/2025-the-year-of-the-infostea…
∗∗∗ Russian hackers target European hospitality industry with ‘blue screen of death’ malware ∗∗∗
---------------------------------------------
The scheme starts with a fake reservation cancellation that impersonates a popular booking site, and eventually prompts victims with an error message and “Blue Screen of Death” page.
---------------------------------------------
https://therecord.media/russian-hackers-europe-hospitality-blue-screen
∗∗∗ Alleged cyber scam kingpin arrested, extradited to China ∗∗∗
---------------------------------------------
Chen Zhi’s arrest is the latest chapter in the remarkable downfall of one of the country’s most prominent businesses, with holdings in the real estate, banking, entertainment and airline industries.
---------------------------------------------
https://therecord.media/alleged-cyber-scam-kingpin-cambodia-arrested-extrad…
∗∗∗ Analysis of a Fake Cloudflare Turnstile Used as a Traffic Filtering Gate ∗∗∗
---------------------------------------------
During analysis of a phishing URL chain, I observed a fake Cloudflare Turnstile verification page acting as an intelligent traffic filtering gate. Rather than protecting a website, this page selectively blocks, redirects, or allows access based on geolocation, proxy usage, and browser fingerprinting. This phishing infrastructure demonstrates Traffic Distribution System like behavior ..
---------------------------------------------
https://malwr-analysis.com/2026/01/07/analysis-of-a-fake-cloudflare-turnsti…
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco Identity Services Engine XML External Entity Processing Information Disclosure Vulnerability ∗∗∗
---------------------------------------------
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information. This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to ..
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Multiple Cisco Products Snort 3 Distributed Computing Environment/Remote Procedure Call Vulnerabilities ∗∗∗
---------------------------------------------
Multiple Cisco products are affected by vulnerabilities in the processing of Distributed Computing Environment Remote Procedure Call (DCE/RPC) requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, which would result in an interruption of packet inspection. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address ..
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ [20260101] - Core - Inadequate content filtering for data URLs ∗∗∗
---------------------------------------------
https://developer.joomla.org/security-centre/1016-20260101-core-inadequate-…
∗∗∗ [20260102] - Core - XSS vector in the pagebreak plugin ∗∗∗
---------------------------------------------
https://developer.joomla.org/security-centre/1017-20260102-core-xss-vector-…
∗∗∗ [20260102] - Core - XSS vectors in the pagebreak and pagenavigation plugins ∗∗∗
---------------------------------------------
https://developer.joomla.org/security-centre/1017-20260102-core-xss-vector-…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 02-01-2026 18:00 − Montag 05-01-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Hackers claim to hack Resecurity, firm says it was a honeypot ∗∗∗
---------------------------------------------
The ShinyHunters hacking group claims it breached the systems of cybersecurity firm Resecurity and stole internal data, while Resecurity says the attackers only accessed a deliberately deployed honeypot containing fake information used to monitor their activity.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-claim-resecurity-hac…
∗∗∗ How to Protect Your iPhone or Android Device From Spyware ∗∗∗
---------------------------------------------
Being targeted by sophisticated spyware is relatively rare, but experts say that everyone needs to stay vigilant as this dangerous malware continues to proliferate worldwide.
---------------------------------------------
https://www.wired.com/story/how-to-protect-your-iphone-or-android-device-fr…
∗∗∗ Plex Media Server: Noch ungepatchte Zugriffsschwachstellen ∗∗∗
---------------------------------------------
Im Plex Media Server klaffen Sicherheitslecks, durch die Angreifer sich unbefugt Zugriff verschaffen können. Updates stehen aus.
---------------------------------------------
https://www.heise.de/news/Plex-Media-Server-Noch-ungepatchte-Zugriffsschwac…
∗∗∗ MongoBleed-Scanner für Admins ∗∗∗
---------------------------------------------
Viele MongoDB-Instanzen sind oder waren potenziell für MongoBleed anfällig. Ein Tool hilft bei der Server-Analyse auf Angriffsspuren.
---------------------------------------------
https://www.heise.de/news/MongoBleed-Scanner-fuer-Admins-11129291.html
∗∗∗ Taiwan: 2,6 Millionen Cyberangriffe Chinas pro Tag ∗∗∗
---------------------------------------------
Die Angriffe haben laut Taiwan in zeitlicher Nähe zu Militärübungen stattgefunden. China dementiert
---------------------------------------------
https://www.derstandard.at/story/3000000302832/taiwan-26-millionen-cyberang…
∗∗∗ Aktuelle Angriffe gegen alte Sicherheitslücke in Fortinet-Geräten (CVE-2020-12812) ∗∗∗
---------------------------------------------
Eine bereits seit Juli 2020 bekannte Sicherheitslücke in Fortinet-Firewalls, CVE-2020-12812, wird aktuell aktiv ausgenutzt. Durch Ausnutzung der Schwachstelle können Angreifer:innen durch eine simple Manipulation von Groß- und Kleinbuchstaben in Benutzernamen (z. B. "Mmueller" statt "mmueller") die Zwei-Faktor-Authentifizierung (2FA) über Fortitoken umgehen. Besonders gefährdet sind Systeme, die lokale Nutzer:innen über einen ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/1/aktuelle-angriffe-gegen-alte-sicher…
∗∗∗ Nearly 480,000 impacted by Covenant Health data breach ∗∗∗
---------------------------------------------
A cyberattack last year against the Catholic healthcare organization Covenant Health exposed the sensitive information of more than 478,000 people.
---------------------------------------------
https://therecord.media/covenant-health-breach-qilin
∗∗∗ NordVPN Denies Breach After Hacker Claims Access to Salesforce Dev Data ∗∗∗
---------------------------------------------
A hacker using the alias 1011 has claimed to breach a NordVPN development server, posting what appears to…
---------------------------------------------
https://hackread.com/nordvpn-denies-breach-hacker-salesforce-dev-data/
∗∗∗ Schlappe für Softwarebauer: BSI darf Sicherheitskonzept als „auffällig“ rügen ∗∗∗
---------------------------------------------
Das Verwaltungsgericht Köln hat den Eilantrag eines Herstellers gegen eine drohende behördliche Warnung abgewiesen und die BSI-Informationsbefugnisse gestärkt.
---------------------------------------------
https://heise.de/-11127661
∗∗∗ Sicherheitsupdates: Verschiedene Attacken auf Qnap-NAS möglich ∗∗∗
---------------------------------------------
Stimmten die Voraussetzungen, können Angreifer Netzwerkspeicher von Qnap mit weitreichenden Folgen attackieren.
---------------------------------------------
https://heise.de/-11129647
∗∗∗ The Kimwolf Botnet is Stalking Your Local Network ∗∗∗
---------------------------------------------
The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and it’s time for a broader awareness of the threat. The short version is that everything you thought you knew about the security of the internal network behind your Internet router probably is now dangerously out of date.
---------------------------------------------
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-loc…
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (tar), Debian (curl and gimp), Fedora (doctl, gitleaks, gnupg2, grpcurl, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, and usd), Mageia (cups), Red Hat (container-tools:rhel8, go-toolset:rhel8, grafana, and skopeo), and SUSE (dirmngr, fluidsynth, gnu-recutils, libmatio-devel, python311-marshmallow, python312-Django6, rsync, and thunderbird).
---------------------------------------------
https://lwn.net/Articles/1052795/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 30-12-2025 18:00 − Freitag 02-01-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass ∗∗∗
---------------------------------------------
Fortinet released FortiOS versions 6.4.1, 6.2.4, and 6.0.10 in July 2020 to address this flaw (tracked as CVE-2020-12812) and advised admins who couldn't immediately patch to turn off username-case-sensitivity to block 2FA bypass attempts targeting their devices. [..] On Friday, Internet security watchdog Shadowserver revealed that it currently tracks over 10,000 Fortinet firewalls still exposed on the Internet that are unpatched against CVE-2020-12812 and vulnerable to these ongoing attacks ...
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewal…
∗∗∗ The Kimwolf Botnet is Stalking Your Local Network ∗∗∗
---------------------------------------------
The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and its time for a broader awareness of the threat. The short version is that everything you thought you knew about the security of the internal network behind your Internet router probably is now dangerously out of date.
---------------------------------------------
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-loc…
∗∗∗ Everest Ransomware Leaks 1TB of Stolen ASUS Data ∗∗∗
---------------------------------------------
On December 2, 2025, Hackread.com exclusively reported that the Everest ransomware group claimed to have stolen 1TB of sensitive ASUS data, including information related to the company’s AI models, memory dumps, and calibration files. [..] Everest has now leaked the entire dataset online.
---------------------------------------------
https://hackread.com/everest-ransomware-asus-data-leak/
∗∗∗ RondoDox botnet exploits React2Shell flaw to breach Next.js servers ∗∗∗
---------------------------------------------
The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/rondodox-botnet-exploits-rea…
∗∗∗ The biggest cybersecurity and cyberattack stories of 2025 ∗∗∗
---------------------------------------------
2025 was a big year for cybersecurity, with cyberattacks, data breaches, threat groups reaching new notoriety levels, and, of course, zero-day flaws exploited in breaches. Some stories, though, were more impactful or popular with our readers than others. This article explores 15 of the biggest cybersecurity stories of 2025.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/the-biggest-cybersecurity-an…
∗∗∗ Hong Kong’s newest anti-scam technology is over-the-counter banking ∗∗∗
---------------------------------------------
Hong Kong’s banks have a new weapon against scams: Accounts that require customers to visit a branch to access their funds.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2025/12/31/hong_kong_an…
∗∗∗ How AI made scams more convincing in 2025 ∗∗∗
---------------------------------------------
Several AI-related stories in 2025 highlighted how quickly AI systems can move beyond meaningful human control.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/01/how-ai-made-scams-more-convi…
∗∗∗ VVS Discord Stealer Using Pyarmor for Obfuscation and Detection Evasion ∗∗∗
---------------------------------------------
Discord is a social messaging and communications platform that has become a popular target for malware, like VVS stealer. VVS stealer is designed to steal a victim's Discord information and browser data. [..] The stealer also achieves persistence by automatically installing itself on startup. It operates stealthily by displaying fake error messages and capturing screenshots.
---------------------------------------------
https://unit42.paloaltonetworks.com/vvs-stealer/
∗∗∗ Snipping the Long Tail of Shai-Hulud 2.0 ∗∗∗
---------------------------------------------
Wiz Research reveals the data behind Shai-Huluds 2.0 long tail, the massive gap in cloud credential rotation, a potential link to the Trust Wallet incident, and how we finally "snipped the tail" on a month of ongoing infections.
---------------------------------------------
https://www.wiz.io/blog/snipping-the-long-tail-of-shai-hulud-2-0
∗∗∗ RMM Abuse in a Crypto Wallet Distribution Campaign ∗∗∗
---------------------------------------------
A professionally written announcement email titled “Eternl Desktop Is Live — Secure Execution for Atrium & Diffusion Participants” is currently circulating within the Cardano community. [..] This campaign exhibits multiple overlapping indicators consistent with supply-chain abuse and trojanized wallet distribution, combined with pre positioning techniques that leverage RMM tools to establish persistent access.
---------------------------------------------
https://malwr-analysis.com/2025/12/31/rmm-abuse-in-a-crypto-wallet-distribu…
=====================
= Vulnerabilities =
=====================
∗∗∗ Gambio: Wichtiges Security Update 2025-12 v1.0.0 für alle Versionen bis GX5 v5.0.1.0 ∗∗∗
---------------------------------------------
Wir haben soeben ein neues Security Update Paket veröffentlicht, dessen Installation wir allen Shopbetreibern dringend empfehlen. Wichtig: Nutzer der Gambio Cloud müssen nichts unternehmen, alle Shops wurden bereits vollständig von uns abgesichert! [..] Bitte versteht, dass wir keine Details beschreiben werden, die Angreifern als Blaupause für einen Angriff dienen könnten.
---------------------------------------------
https://www.gambio.de/forum/threads/wichtiges-security-update-2025-12-v1-0-…
∗∗∗ QNAP Security Advisories 3. Jan ∗∗∗
---------------------------------------------
QNAP has released 7 new security advisories.
---------------------------------------------
https://www.qnap.com/en-us/security-advisories
∗∗∗ Security updates for Friday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (smb4k), Fedora (direwolf, gh, usd, and webkitgtk), Slackware (libpcap and seamonkey), and SUSE (kepler).
---------------------------------------------
https://lwn.net/Articles/1052600/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 29-12-2025 18:00 − Dienstag 30-12-2025 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ European Space Agency confirms breach of "external servers" ∗∗∗
---------------------------------------------
The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described as "unclassified" information on collaborative engineering activities.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/european-space-agency-confir…
∗∗∗ Zoom Stealer browser extensions harvest corporate meeting intelligence ∗∗∗
---------------------------------------------
A newly discovered campaign, which researchers call Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through 18 extensions that collect online meeting-related data like URLs, IDs, topics, descriptions, and embedded passwords. [..] Because many of these extensions operated innocuously for extended periods, users should carefully review the permissions the extensions require and limit their number to the necessary minimum. Koi Security reported the offending extensions, but many are still present on the Chrome Web Store. The researchers published the complete list of active DarkSpectre extensions.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/zoom-stealer-browser-extensi…
∗∗∗ Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor ∗∗∗
---------------------------------------------
The Chinese hacking group known as Mustang Panda has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia. The findings come from Kaspersky, which observed the new backdoor variant in cyber espionage campaigns mounted by the hacking group targeting government organizations in Southeast and East Asia, primarily Myanmar and Thailand.
---------------------------------------------
https://thehackernews.com/2025/12/mustang-panda-uses-signed-kernel-driver.h…
∗∗∗ Trends, Highlights und Skurrilitäten: Das Jahr 2025 aus Sicht der Watchlist Internet ∗∗∗
---------------------------------------------
Welche Entwicklungen brachte 2025 im Bereich des Online-Betrugs? Welche Artikel waren bei unseren Leser:innen besonders beliebt? Und mit welchen skurrilen Schmankerln hatte es die Redaktion in den vergangenen 12 Monaten zu tun? Ein Rückblick zum Jahreswechsel!
---------------------------------------------
https://www.watchlist-internet.at/news/jahresrueckblick-watchlist-2025/
∗∗∗ 39C3: Schwachstellen in Xplora-Smartwatches gefährdeten Millionen Kinder ∗∗∗
---------------------------------------------
Forscher konnten Nachrichten mitlesen, Standorte fälschen und beliebige Uhren übernehmen – demonstriert aus der Perspektive einer kinderfressenden Waldhexe.
---------------------------------------------
https://heise.de/-11126122
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (openjpeg2, osslsigncode, php-dompdf, and python-django), Fedora (fluidsynth, golang-github-alecthomas-chroma-2, golang-github-evanw-esbuild, golang-github-jwt-5, and opentofu), Mageia (ceph and ruby-rack), and SUSE (anubis, apache2-mod_auth_openidc, dpdk22, kernel, libpng16, and python311-openapi-core).
---------------------------------------------
https://lwn.net/Articles/1052327/
∗∗∗ ZDI-25-1195: (0Day) FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-25-1195/
∗∗∗ ZDI-25-1184: (0Day) FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-25-1184/
∗∗∗ ZDI-25-1201: (0Day) Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-25-1201/
∗∗∗ ZDI-25-1199: (0Day) Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-25-1199/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 23-12-2025 18:00 − Montag 29-12-2025 18:00
Handler: Alexander Riepl
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Schwerwiegende Sicherheitslücke in MongoDB ("MongoBleed") ∗∗∗
---------------------------------------------
In MongoDB wurde um Weihnachten eine schwerwiegende Sicherheitslücke entdeckt. Die Schwachstelle, CVE-2025-14847 (auch bekannt als "MongoBleed") erlaubt es unauthentifizierten Angreifer:innen durch manipulierte, zlib-kompromierte Anfragen Teile des Heap-Speichers auszulesen und damit potentiell sensible Daten (wie beispielsweise Passwörter oder API-Schlüssel) zu stehlen.
---------------------------------------------
https://www.cert.at/de/aktuelles/2025/12/schwerwiegende-sicherheitslucke-in…
∗∗∗ WebRAT malware spread via fake vulnerability exploits on GitHub ∗∗∗
---------------------------------------------
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/webrat-malware-spread-via-fa…
∗∗∗ Microsoft Teams to let admins block external users via Defender portal ∗∗∗
---------------------------------------------
Microsoft announced that security administrators will soon be able to block external users from sending messages, calls, or meeting invitations to members of their organization via Teams.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-to-let-admi…
∗∗∗ Romanian energy provider hit by Gentlemen ransomware attack ∗∗∗
---------------------------------------------
A ransomware attack hit Oltenia Energy Complex, Romanias largest coal-based energy producer, on the second day of Christmas, taking down its IT infrastructure.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/romanian-energy-provider-hit…
∗∗∗ Ubisoft: Rainbow-Six-Siege-Server wegen Hack heruntergefahren ∗∗∗
---------------------------------------------
Hacker erlangten Zugriff auf die Server von Rainbow Six Siege. Nach Bannwellen und Credit-Regen hat Ubisoft mit einem Systemstopp reagiert.
---------------------------------------------
https://www.golem.de/news/ubisoft-rainbow-six-siege-server-wegen-hack-herun…
∗∗∗ Evasive Panda APT poisons DNS requests to deliver MgBot ∗∗∗
---------------------------------------------
Kaspersky GReAT experts analyze the Evasive Panda APTs infection chain, including shellcode encrypted with DPAPI and RC5, as well as the MgBot implant.
---------------------------------------------
https://securelist.com/evasive-panda-apt/118576/
∗∗∗ Are We Ready to Be Governed by Artificial Intelligence? ∗∗∗
---------------------------------------------
Artificial Intelligence (AI) overlords are a common trope in science-fiction dystopias, but the reality looks much more prosaic. The technologies of artificial intelligence are already pervading many aspects of democratic government, affecting our lives in ways both large and small. This has occurred largely without our notice or consent. The result is a government incrementally transformed by AI rather than the singular technological overlord of the big screen.
---------------------------------------------
https://www.schneier.com/blog/archives/2025/12/are-we-ready-to-be-governed-…
∗∗∗ Fake MAS Windows Activation Domain Used To Spread PowerShell Malware ∗∗∗
---------------------------------------------
An anonymous reader shares a report: A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used to distribute malicious PowerShell scripts that infect Windows systems with the Cosmali Loader. BleepingComputer has found that multiple MAS users began reporting on Reddit yesterday that they received pop-up warnings on their systems about a Cosmali Loader infection.
---------------------------------------------
https://it.slashdot.org/story/25/12/25/2058205/fake-mas-windows-activation-…
∗∗∗ New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered a new variant of a macOS information stealer called MacSync thats delivered by means of a digitally signed, notarized Swift application masquerading as a messaging app installer to bypass Apples Gatekeeper checks.
---------------------------------------------
https://thehackernews.com/2025/12/new-macsync-macos-stealer-uses-signed.html
∗∗∗ Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors ∗∗∗
---------------------------------------------
In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In August 2025, malicious Nx packages leaked 2,349 GitHub, cloud, and AI credentials. Throughout 2024, ChatGPT vulnerabilities allowed unauthorized extraction of user data from AI memory.
---------------------------------------------
https://thehackernews.com/2025/12/traditional-security-frameworks-leave.html
∗∗∗ 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of what has been described as a "sustained and targeted" spear-phishing campaign that has published over two dozen packages to the npm registry to facilitate credential theft.
---------------------------------------------
https://thehackernews.com/2025/12/27-malicious-npm-packages-used-as.html
∗∗∗ Death, torture, and amputation: How cybercrime shook the world in 2025 ∗∗∗
---------------------------------------------
The human harms of cyberattacks piled up this year, and violence expected to increase The knock-on, and often unintentional, impacts of a cyberattack are so rarely discussed. As an industry, the focus is almost always placed on the economic damage: the ransom payment; the cost of business downtime; and goodness, dont forget those poor shareholders.
---------------------------------------------
https://www.theregister.com/2025/12/28/death_torture_and_amputation_how/
∗∗∗ The Age of the All-Access AI Agent Is Here ∗∗∗
---------------------------------------------
Big AI companies courted controversy by scraping wide swaths of the public internet. With the rise of AI agents, the next data grab is far more private.
---------------------------------------------
https://www.wired.com/story/expired-tired-wired-all-access-ai-agents/
∗∗∗ The Worst Hacks of 2025 ∗∗∗
---------------------------------------------
>From university breaches to cyberattacks that shut down whole supply chains, these were the worst cybersecurity incidents of the year.
---------------------------------------------
https://www.wired.com/story/worst-hacks-of-2025/
∗∗∗ Samsung: Ausbleibende Google-Play-Dienstupdates sind Absicht ∗∗∗
---------------------------------------------
Seit einigen Wochen gibt es Verwunderung über ausbleibende Google-Play-Dienstupdates auf Samsung-Smartphones. Jetzt erklärt Samsung das.
---------------------------------------------
https://www.heise.de/news/Samsung-erklaert-ausbleibende-Google-Play-Dienstu…
∗∗∗ 39C3: Wie ein Forscher das sichere Mail-Netz der Medizin erneut überlistete ∗∗∗
---------------------------------------------
Ein Sicherheitsexperte zeigte auf dem 39C3, wie sich bei der E-Ärztepost KIM Nachrichten fälschen, Identitäten stehlen und sensible Metadaten abgreifen lassen.
---------------------------------------------
https://www.heise.de/news/39C3-Wie-ein-Forscher-das-sichere-Mail-Netz-der-M…
∗∗∗ 39C3: Diverse Lücken in GnuPG und anderen kryptografischen Werkzeugen ∗∗∗
---------------------------------------------
Sicherheitsforscher haben diverse sicherheitsrelevante Fehler in GnuPG und ähnlichen Programmen gefunden. Viele der Lücken sind (noch) nicht behoben.
---------------------------------------------
https://www.heise.de/news/39C3-Diverse-Luecken-in-GnuPG-und-anderen-kryptog…
∗∗∗ Notepad++: Update entrümpelt Self-Signed-Zertifikatreste ∗∗∗
---------------------------------------------
In Notepad++ konnten Angreifer dem Updater Malware unterschieben. Ein weiteres Update verbessert die Sicherheit und korrigiert Regressionen.
---------------------------------------------
https://www.heise.de/news/Notepad-Update-zum-Aufraeumen-von-Self-Signed-Zer…
∗∗∗ Millionen Kundendaten vom Wired-Magazin im Netz – Diebstahl bei Condé Nast? ∗∗∗
---------------------------------------------
Have I been Pwned listet einen Data Breach für Wired, der sensible Daten von 2,3 Millionen Nutzern umfasst. Mutmaßlich könnten weitere Millionen folgen.
---------------------------------------------
https://www.heise.de/news/Millionen-Kundendaten-vom-Wired-Magazin-im-Netz-D…
∗∗∗ 39C3: Skynet Starter Kit – Forscher übernehmen humanoide Roboter per Funk und KI ∗∗∗
---------------------------------------------
Auf dem 39C3 demonstrieren Experten, wie schlecht es um die Security humanoider Roboter steht. Die Angriffspalette reicht bis zum Jailbreak der integrierten KI.
---------------------------------------------
https://www.heise.de/hintergrund/39C3-Skynet-Starter-Kit-Forscher-uebernehm…
∗∗∗ 39C3: Sicherheitsforscher kapert KI-Coding-Assistenten mit Prompt Injection ∗∗∗
---------------------------------------------
Auf dem 39C3 zeigte Johann Rehberger, wie leicht sich KI-Coding-Assistenten kapern lassen. Viele Lücken wurden gefixt, doch das Grundproblem bleibt.
---------------------------------------------
https://www.heise.de/news/39C3-Sicherheitsforscher-kapert-KI-Coding-Assiste…
∗∗∗ 1800 Nordkoreaner versuchten, sich bei Amazon einzuschleusen ∗∗∗
---------------------------------------------
Es ist nicht das erste Mal, dass Unternehmen von nordkoreanischen Agenten berichten, die gezielt versuchen, sich in ihre Betriebe einzuschleusen. Das Ausmaß der Versuche scheint sich jedoch noch einmal vergrößert zu haben.
---------------------------------------------
https://www.derstandard.at/story/3000000302007/1800-nordkoreaner-versuchten…
∗∗∗ A brush with online fraud: What are brushing scams and how do I stay safe? ∗∗∗
---------------------------------------------
Have you ever received a package you never ordered? It could be a warning sign that your data has been compromised, with more fraud to follow.
---------------------------------------------
https://www.welivesecurity.com/en/scams/brush-online-fraud-what-are-brushin…
∗∗∗ Cyber volunteer effort for small water utilities announces new MSSP effort ∗∗∗
---------------------------------------------
An organization is looking to develop a first-of-its-kind managed security service provider (MSSP) model tailored specifically for rural water utilities.
---------------------------------------------
https://therecord.media/cyber-volunteer-water-utility-mssp
∗∗∗ Georgia arrests ex-spy chief over alleged protection of scam call centers ∗∗∗
---------------------------------------------
Grigol Liluashvili, who ran the Republic of Georgias state security service from 2020 until April of this year, is facing allegations that he protected scam call centers that defrauded victims around the world.
---------------------------------------------
https://therecord.media/republic-of-georgia-former-spy-chief-arrested-scam-…
∗∗∗ Eurostar Accused Researchers of Blackmail for Reporting AI Chatbot Flaws ∗∗∗
---------------------------------------------
Researchers discovered critical flaws in Eurostar’s AI chatbot including prompt injection, HTML injection, guardrail bypass, and unverified chat IDs - Eurostar later accused them of blackmail.
---------------------------------------------
https://hackread.com/eurostar-blackmail-research-report-ai-chatbot-flaw/
∗∗∗ Hacker Leaks 2.3M Wired.com Records, Claims 40M-User Condé Nast Breach ∗∗∗
---------------------------------------------
A hacker using the alias “Lovely” has leaked what they claim is the personal data of over 2.3 million Wired.com users, a prominent American magazine and website. The leak was posted on December 20, 2025, on a newly launched hacking forum called Breach Stars.
---------------------------------------------
https://hackread.com/hacker-leak-wired-com-records-conde-nast-breach/
∗∗∗ Bitlocker bekommt Verschlüsselung per Hardware zurück ∗∗∗
---------------------------------------------
Mehr Tempo und mehr Sicherheit – nach dem Aus 2019 setzt die Windows-Verschlüsselung bald wieder auf Crypto-Hardware statt CPUs.
---------------------------------------------
https://heise.de/-11124708
∗∗∗ Microsoft Is Finally Killing RC4 ∗∗∗
---------------------------------------------
After twenty-six years, Microsoft is finally upgrading the last remaining instance of the encryption algorithm RC4 in Windows.
---------------------------------------------
https://www.schneier.com/blog/archives/2025/12/microsoft-is-finally-killing…
∗∗∗ Strengthening supply chain security: Preparing for the next malware campaign ∗∗∗
---------------------------------------------
Security advice for users and maintainers to help reduce the impact of the next supply chain malware attack.
---------------------------------------------
https://github.blog/security/supply-chain-security/strengthening-supply-cha…
∗∗∗ Forensic Insights into an EDR Freeze Attack ∗∗∗
---------------------------------------------
I have analyzed EDR-Freeze.exe, which puts EDR processes into a suspended “coma” state. Unlike typical EDR attacks (BYOVD etc.) techniques, this approach is more subtle and abuses legitimate Windows functionality.
---------------------------------------------
https://detect.fyi/forensic-insights-into-an-edr-freeze-attack-e559b0e50a91
∗∗∗ 2025 Report: Destructive Malware in Open Source Packages ∗∗∗
---------------------------------------------
Over the past year, the Socket Threat Research Team observed a steady rise in destructive and sabotage-oriented malware embedded in open source packages across multiple ecosystems. Unlike financially motivated campaigns that focus on credential theft, cryptomining, or wallet draining, these incidents were built to damage developer environments directly, deleting source code, breaking builds, or wiping repositories outright.
---------------------------------------------
https://socket.dev/blog/2025-report-destructive-malware-in-open-source-pack…
∗∗∗ Demand Without Development ∗∗∗
---------------------------------------------
The cybersecurity talent shortage is not just a problem of numbers, but of structure. By systematically avoiding the hiring and training of true junior staff, the industry is reinforcing a feedback loop that shrinks its own future workforce.
---------------------------------------------
https://bytesandborscht.com/demand-without-development/
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (kodi, pgbouncer, and rails), Fedora (duc, fluidsynth, gdu, singularity-ce, and tkimg), Slackware (vim), and SUSE (buildah, duc, gnutls, python39, qemu, and webkit2gtk3).
---------------------------------------------
https://lwn.net/Articles/1052236/
∗∗∗ Critical 0day flaw Exposes 70k XSpeeder Devices as Vendor Ignores Alert ∗∗∗
---------------------------------------------
Researchers reveal CVE-2025-54322, a critical unpatched flaw in XSpeeder networking gear found by AI agents. 70,000 industrial and branch devices are exposed.
---------------------------------------------
https://hackread.com/xspeeder-0day-flaw-devices-vendor-ignores-alert/
∗∗∗ Product Security Advisory and Analysis: Observed Abuse of FG-IR-19-283 ∗∗∗
---------------------------------------------
Fortinet has observed recent abuse of the July 2020 vulnerability FG-IR-19-283 / CVE-2020-12812 in the wild based on specific configurations. This blog analysis describes the observed abuse and provides additional context so that administrators can confirm that they are not impacted and guidance based on Fortinet observations to prevent FG-IR-19-283 from being exploited.
---------------------------------------------
https://www.fortinet.com/blog/psirt-blogs/product-security-advisory-and-ana…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 22-12-2025 18:00 − Dienstag 23-12-2025 18:15
Handler: Alexander Riepl
Co-Handler: Felician Fuchs
Das gesamte CERT.at Team bedankt sich herzlich für Ihr Interessen an unserem Daily Newsletter. Wir wünschen Ihnen frohe Weihnachten und erholsame Feiertage.
=====================
= News =
=====================
∗∗∗ Interpol-led action decrypts 6 ransomware strains, arrests hundreds ∗∗∗
---------------------------------------------
An Interpol-coordinated initiative called Operation Sentinel led to the arrest of 574 individuals and the recovery of $3 million linked to business email compromise, extortion, and ransomware incidents.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/interpol-led-action-decrypts…
∗∗∗ CISA flags ASUS Live Update CVE, but the attack is years old ∗∗∗
---------------------------------------------
An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. A closer look, however, shows the CVE documents a historic supply-chain attack in an End-of-Life (EoL) software product, not a new attack.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-flags-asus-live-update-…
∗∗∗ New MacSync malware dropper evades macOS Gatekeeper checks ∗∗∗
---------------------------------------------
The latest variant of the MacSync information stealer targeting macOS systems is delivered through a digitally signed, notarized Swift application.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-macsync-malware-dropper-…
∗∗∗ Nissan says thousands of customers exposed in Red Hat breach ∗∗∗
---------------------------------------------
Nissan Motor Co. Ltd. (Nissan) has confirmed that information of thousands of its customers has been compromised after the data breach at Red Hat in September.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/nissan-says-thousands-of-cus…
∗∗∗ Microsoft Teams strengthens messaging security by default in January ∗∗∗
---------------------------------------------
Microsoft Teams will automatically enable messaging safety features by default in January to strengthen defenses against content tagged as malicious.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-strengthens…
∗∗∗ Gutscheincodes im Netz: Honey erpresste offenbar Onlineshops und nutzte Kinder aus ∗∗∗
---------------------------------------------
Gezielte Werbung an Kinder, das Sammeln von privaten Daten und Schaden für Onlineshops: Honey ist wohl schlimmer, als bisher gedacht.
---------------------------------------------
https://www.golem.de/news/gutscheincodes-im-netz-honey-erpresste-offenbar-o…
∗∗∗ From cheats to exploits: Webrat spreading via GitHub ∗∗∗
---------------------------------------------
We dissect the new Webrat campaign where the Trojan spreads via GitHub repositories, masquerading as critical vulnerability exploits to target cybersecurity researchers.
---------------------------------------------
https://securelist.com/webrat-distributed-via-github/118555/
∗∗∗ Assessing SIEM effectiveness ∗∗∗
---------------------------------------------
We share the results of assessing the effectiveness of Kaspersky SIEM in real-world infrastructures and explore common challenges and solutions to these.
---------------------------------------------
https://securelist.com/siem-effectiveness-assessment/118560/
∗∗∗ Microsoft Is Finally Killing RC4 ∗∗∗
---------------------------------------------
After twenty-six years, Microsoft is finally upgrading the last remaining instance of the encryption algorithm RC4 in Windows.
---------------------------------------------
https://www.schneier.com/blog/archives/2025/12/microsoft-is-finally-killing…
∗∗∗ Chinese Crypto Scammers on Telegram Are Fueling the Biggest Darknet Markets Ever ∗∗∗
---------------------------------------------
Online black markets once lurked in the shadows of the dark web. Today, they’ve moved onto public platforms like Telegram—and are racking up historic illicit fortunes.
---------------------------------------------
https://www.wired.com/story/expired-tired-wired-chinese-scammer-crypto-mark…
∗∗∗ Cyber spies use fake New Year concert invites to target Russian military ∗∗∗
---------------------------------------------
The campaign surfaced earlier in October after researchers at the New York-based cybersecurity firm Intezer identified a malicious XLL file uploaded to VirusTotal, first from Ukraine and later from Russia.
---------------------------------------------
https://therecord.media/cyber-spies-fake-new-year-concert-russian-phishing
∗∗∗ DDoS incident disrupts France’s postal and banking services ahead of Christmas ∗∗∗
---------------------------------------------
Frances La Poste confirmed that a distributed denial-of-service (DDoS) attack was the source of problems with its websites and mobile applications.
---------------------------------------------
https://therecord.media/la-poste-france-ddos-disruption-days-before-christm…
∗∗∗ Scam: Uphold Sicherheitsvorfall über Drittanbieter? ∗∗∗
---------------------------------------------
Heute bin ich darüber "informiert" worden, dass es zu einer "Datenpanne" bei einem Drittanbieter gekommen sei, die Nutzer von Uphold betrifft. Uphold ist eine Plattform, die eine Wallet für Kryptogeld bereitstellt. Und diese Nachricht ist Scam. Ich ziehe mal einige Informationen zusammen, und warum man mutmaßlich die Finger von dem ganzen Zeugs lassen sollte.
---------------------------------------------
https://borncity.com/blog/2025/12/22/uphold-sicherheitsvorfall-ueber-dritta…
∗∗∗ I foretold that Mac app notarization is security theater ∗∗∗
---------------------------------------------
This morning 9to5Mac reported, MacSync Stealer variant finds a way to bypass Apple malware protections, based on an investigation by Jamf.
---------------------------------------------
https://lapcatsoftware.com/articles/2025/12/5.html
∗∗∗ Malicious Chrome Extensions “Phantom Shuttle” Masquerade as a VPN to Intercept Traffic and Exfiltrate Credentials ∗∗∗
---------------------------------------------
Sockets Threat Research Team identified two malicious Chrome extensions sharing the same name Phantom Shuttle (幻影穿梭), published by the same threat actor using the email theknewone.com(a)gmail[.]com, distributed since at least 2017. The extensions market themselves as "multi-location network speed testing plugins" for developers and foreign trade personnel.
---------------------------------------------
https://socket.dev/blog/malicious-chrome-extensions-phantom-shuttle
=====================
= Vulnerabilities =
=====================
∗∗∗ Forscher warnen: Kritische n8n-Lücke betrifft über 17.000 deutsche Server ∗∗∗
---------------------------------------------
Eine Sicherheitslücke lässt Angreifer n8n-Instanzen kapern und Schadcode einschleusen. Besonders viele anfällige Systeme gibt es in Deutschland.
---------------------------------------------
https://www.golem.de/news/forscher-warnen-kritische-n8n-luecke-betrifft-ueb…
∗∗∗ Patches: Hitachi Infrastructure Analytics und Ops Center sind verwundbar ∗∗∗
---------------------------------------------
Zwei Sicherheitslücken bedrohen Hitachi Infrastructure Analytics und Ops Center. Angreifer können die Anmeldung umgehen.
---------------------------------------------
https://www.heise.de/news/Patches-Hitachi-Infrastructure-Analytics-und-Ops-…
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (binutils, curl, gcc-toolset-13-binutils, git-lfs, httpd, httpd:2.4, keylime, libssh, mod_md, openssh, php:8.3, podman, python3.12, python3.9, python39:3.9, skopeo, tomcat, tomcat9, and webkit2gtk3), Fedora (mingw-glib2, mingw-libsoup, and mingw-python3), Mageia (roundcubemail), Oracle (git-lfs and mod_md), and SUSE (glib2, kernel, mariadb, and qemu).
---------------------------------------------
https://lwn.net/Articles/1051758/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 19-12-2025 18:00 − Montag 22-12-2025 18:15
Handler: Alexander Riepl
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ RansomHouse upgrades encryption with multi-layered data processing ∗∗∗
---------------------------------------------
The RansomHouse ransomware-as-a-service (RaaS) has recently upgraded its encryptor, switching from a relatively simple single-phase linear technique to a more complex, multi-layered method.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ransomhouse-upgrades-encrypt…
∗∗∗ Malicious npm package steals WhatsApp accounts and messages ∗∗∗
---------------------------------------------
A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal WhatsApp messages, collect contacts, and gain access to the account.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/malicious-npm-package-steals…
∗∗∗ Leicht hackbar: Deutschlandticket-Betrug erreicht dreistellige Millionenhöhe ∗∗∗
---------------------------------------------
IT-Sicherheitsforscher haben massive Schwachstellen beim Deutschlandticket aufgedeckt. Der Schaden durch Betrug liegt im dreistelligen Millionenbereich.
---------------------------------------------
https://www.golem.de/news/leicht-hackbar-deutschlandticket-betrug-erreicht-…
∗∗∗ Airbus Moving Critical Systems Away From AWS, Google, and Microsoft Citing Data Sovereignty Concerns ∗∗∗
---------------------------------------------
Airbus is preparing to tender a major contract to move mission-critical systems like ERP, manufacturing, and aircraft design data onto a digitally sovereign European cloud, citing national security concerns and fears around U.S. extraterritorial laws like the CLOUD Act.
---------------------------------------------
https://slashdot.org/story/25/12/19/2252254/airbus-moving-critical-systems-…
∗∗∗ Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers ∗∗∗
---------------------------------------------
A suspected Russia-aligned group has been attributed to a phishing campaign that employs device code authentication workflows to steal victims Microsoft 365 credentials and conduct account takeover attacks. The activity, ongoing since September 2025, is being tracked by Proofpoint under the moniker UNK_AcademicFlare.
---------------------------------------------
https://thehackernews.com/2025/12/russia-linked-hackers-use-microsoft-365.h…
∗∗∗ ATM jackpotting gang accused of unleashing Ploutus malware across US ∗∗∗
---------------------------------------------
Latest charges join the mountain of indictments facing alleged Tren de Aragua members. A Venezuelan gang described by US officials as "a ruthless terrorist organization" faces charges over alleged deployment of malware on ATMs across the country, illegally siphoning millions of dollars.
---------------------------------------------
https://www.theregister.com/2025/12/19/tren_de_aragua_atm/
∗∗∗ Around 1,000 systems compromised in ransomware attack on Romanian water agency ∗∗∗
---------------------------------------------
On-site staff keep key systems working while all but one region battles with encrypted PCs Romanias cybersecurity agency confirms a major ransomware attack on the countrys water management administration has compromised around 1,000 systems, with work to remediate them still ongoing.
---------------------------------------------
https://www.theregister.com/2025/12/22/around_1000_systems_compromised_in/
∗∗∗ Zscaler Threat Hunting Catches Evasive SideWinder APT Campaign ∗∗∗
---------------------------------------------
Zscaler Threat Hunting has identified a sophisticated espionage campaign targeting Indian entities by masquerading as the Income Tax Department of India. By reconstructing the complete attack lifecycle from a deceptive “Inspection” lure to a reflectively loaded resident implant, Zscaler Threat Hunting has observed activity which is typically associated with SideWinder APT (also known as Rattlesnake or APT-C-17).
---------------------------------------------
https://www.zscaler.com/blogs/security-research/zscaler-threat-hunting-catc…
∗∗∗ l+f: Reverse Engineering Schritt-für-Schritt – KI hilft auch mit ∗∗∗
---------------------------------------------
Ein Sicherheitsforscher nimmt Interessierte mit auf eine Reise in eine IP-Kamera-Firmware. Das Ergebnis sind Patches für TP-Links Tapo-C200-Modell.
---------------------------------------------
https://www.heise.de/news/l-f-Reverse-Engineering-Schritt-fuer-Schritt-KI-h…
∗∗∗ Eurostar AI vulnerability: when a chatbot goes off the rails ∗∗∗
---------------------------------------------
I first encountered the chatbot as a normal Eurostar customer while planning a trip. When it opened, it clearly told me that “the answers in this chatbot are generated by AI”, which is good disclosure but immediately raised my curiosity about how it worked and what its limits were.
---------------------------------------------
https://www.pentestpartners.com/security-blog/eurostar-ai-vulnerability-whe…
∗∗∗ Phishing Campaign Leverages Trusted Google Cloud Automation Capabilities to Evade Detection ∗∗∗
---------------------------------------------
This report describes a phishing campaign in which attackers impersonate legitimate Google generated messages by abusing Google Cloud Application Integration to distribute malicious emails that appear to originate from trusted Google infrastructure. The emails mimic routine enterprise notifications such as voicemail alerts and file access or permission requests, making them appear normal and trustworthy to recipients.
---------------------------------------------
https://blog.checkpoint.com/research/phishing-campaign-leverages-trusted-go…
∗∗∗ Denmark summons Russian ambassador over alleged cyberattacks on water utility, elections ∗∗∗
---------------------------------------------
Russia’s ambassador to Copenhagen, Vladimir Barbin, confirmed to Russian state media on Friday that he had been called to the Danish foreign ministry, but rejected the accusations as unfounded.
---------------------------------------------
https://therecord.media/denmark-summons-russian-ambassador-cyberattack-elec…
∗∗∗ Nigeria arrests suspected RaccoonO365 phishing kit developer on tip from Microsoft, FBI ∗∗∗
---------------------------------------------
One of the alleged developers behind the RaccoonO365 subscription-based phishing kit was arrested by Nigerian police this week.
---------------------------------------------
https://therecord.media/nigeria-raccoon-developer-tip
∗∗∗ Nefilim ransomware hacker pleads guilty to computer fraud ∗∗∗
---------------------------------------------
A Ukrainian national pleaded guilty in U.S. federal court to one charge stemming from attacks using Nefilim ransomware on companies in the U.S., Canada and Australia.
---------------------------------------------
https://therecord.media/nefilim-ransomware-hacker-fraud
∗∗∗ Judge rules that NSO cannot continue to install spyware via WhatsApp pending appeal ∗∗∗
---------------------------------------------
NSO Group had sought to stay the order pending a decision on its appeal in the case, which centers on allegations that it targeted 1,400 WhatsApp users with its powerful zero-click Pegasus spyware in 2019.
---------------------------------------------
https://therecord.media/judge-rules-nso-cannot-continue-whatsapp-spyware
∗∗∗ Hackers Abuse Popular Monitoring Tool Nezha as a Stealth Trojan ∗∗∗
---------------------------------------------
Cybersecurity firm Ontinue reveals how the open-source tool Nezha is being used as a Remote Access Trojan (RAT) to bypass security and control servers globally.
---------------------------------------------
https://hackread.com/hackers-abuse-monitoring-tool-nezha-trojan/
∗∗∗ Gefälschter Speicher: Jetzt ist besondere Vorsicht geboten ∗∗∗
---------------------------------------------
Während der Weihnachtszeit macht gefälschte Hardware gern die Runde. Die Speicherkrise macht Betrug noch lukrativer.
---------------------------------------------
https://heise.de/-11123055
∗∗∗ "Karvi-geddon": Mangelhafte Sicherheitsarchitektur bei Lieferdienst-Plattform ∗∗∗
---------------------------------------------
Eine auf Github veröffentlichte Sicherheitsanalyse zeigt schwerwiegende Mängel bei Karvi Solutions. Davon sind zehntausende Restaurant-Kunden betroffen.
---------------------------------------------
https://heise.de/-11122678
∗∗∗ Task Injection – Exploiting agency of autonomous AI agents ∗∗∗
---------------------------------------------
This blog post describes what a Task Injection attack is, how this type of attack differs from Prompt Injection, and how it is particularly relevant to AI agents designed for a wide range of actions and tasks, such as computer-use agents.
---------------------------------------------
https://bughunters.google.com/blog/4823857172971520/task-injection-exploiti…
∗∗∗ A Deep Dive into A Vulnerability Apple Deemed Unexploitable ∗∗∗
---------------------------------------------
I’m going to share with you an interesting race condition issue lurking in Apple’s core file-copy API. Apple was aware of the security issue. But they did nothing at first because they deemed it would be nearly impossible to exploit the bug, due to the race condition’s microscopic time window. But I will prove them wrong.
---------------------------------------------
https://jhftss.github.io/Exploiting-the-Impossible/
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (chromium, dropbear, mediawiki, php8.4, python-mechanize, rails, roundcube, usbmuxd, and wordpress), Fedora (cef, chromium, fonttools, gobuster, gosec, mingw-libpng, moby-engine, mqttcli, nextcloud, pgadmin4, python-unicodedata2, uriparser, and util-linux), Mageia (php and webkit2), Oracle (binutils, curl, gcc-toolset-13-binutils, gimp, git-lfs, kernel, openssh, php:8.3, podman, python-kdcproxy, python3.12, python3.9, skopeo, and webkit2gtk3), Red Hat (rsync), Slackware (php), SUSE (alloy, busybox, chromedriver, chromium, coredns-for-k8s, duc, firefox, kernel-devel, libpng16, libruby3_4-3_4, mariadb, netty, php8, python311-tornado6, rsync, taglib, and xen), and Ubuntu (linux-oracle-5.4, linux-raspi, linux-realtime-6.14, and linux-xilinx).
---------------------------------------------
https://lwn.net/Articles/1051572/
∗∗∗ Progress Kemp LoadMaster Schwachstellen patchen (17. Dez. 2025) ∗∗∗
---------------------------------------------
Kurze Vorankündigung für Administratoren, die den Kemp Progress Load Balancer im Einsatz haben. Es gibt wohl Schwachstellen im Produkt, die zeitnah zu patchen sind. Die Informationen sind derzeit nicht öffentlich und sollen erst zum 12. Januar 2026 offen gelegt werden (trage ich dann hier nach).
---------------------------------------------
https://borncity.com/blog/2025/12/21/progress-kemp-loadmaster-schwachstelle…
∗∗∗ BIOS-Sicherheitslücke: Angreifer können Schadcode auf Dell-Server schieben ∗∗∗
---------------------------------------------
Verschiedene Modelle von Dells PowerEdge-Server-Reihe sind verwundbar. Sicherheitspatches sind verfügbar.
---------------------------------------------
https://heise.de/-11122626
∗∗∗ Sicherheitspatches: DoS-Attacken auf IBM App Connect Enterprise möglich ∗∗∗
---------------------------------------------
IBMs Integrationssoftwareangebot App Connect Enterprise ist verwundbar. In aktuellen Versionen haben die Entwickler eine Sicherheitslücke geschlossen.
---------------------------------------------
https://heise.de/-11122938
∗∗∗ Security Advisory - multiple vulnerabilities in Foxit PDF Reader & Editor ∗∗∗
---------------------------------------------
https://www.foxit.com/support/security-bulletins.html
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/