=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 05-02-2026 18:00 − Freitag 06-02-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ No Pain, No Gain - How Impunity Perpetuates Failure ∗∗∗
---------------------------------------------
It’s time to treat cybersecurity incidents and data breaches like preventable disasters, not the inevitable cost of doing business.
---------------------------------------------
https://bytesandborscht.com/no-pain-no-gain-how-impunity-perpetuates-failur…
∗∗∗ Ransomware gang uses ISPsystem VMs for stealthy payload delivery ∗∗∗
---------------------------------------------
Ransomware operators are hosting and delivering malicious payloads at scale by abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-ispsyst…
∗∗∗ Spains Ministry of Science shuts down systems after breach claims ∗∗∗
---------------------------------------------
Spain's Ministry of Science (Ministerio de Ciencia) announced a partial shutdown of its IT systems, affecting several citizen- and company-facing services.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/spains-ministry-of-science-s…
∗∗∗ CISA orders federal agencies to replace end-of-life edge devices ∗∗∗
---------------------------------------------
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new binding operational directive requiring federal agencies to identify and remove network edge devices that no longer receive security updates from manufacturers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies…
∗∗∗ Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered a new supply chain attack in which legitimate packages on npm and the Python Package Index (PyPI) repository have been compromised to push malicious versions to facilitate wallet credential theft and remote code execution.
---------------------------------------------
https://thehackernews.com/2026/02/compromised-dydx-npm-and-pypi-packages.ht…
∗∗∗ Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries ∗∗∗
---------------------------------------------
Artificial intelligence (AI) company Anthropic revealed that its latest large language model (LLM), Claude Opus 4.6, has found more than 500 previously unknown high-severity security flaws in open-source libraries, including Ghostscript, OpenSC, and CGIF.
---------------------------------------------
https://thehackernews.com/2026/02/claude-opus-46-finds-500-high-severity.ht…
∗∗∗ Datenleck bei Substack: Datensatz mit knapp 700.000 Einträgen im Netz ∗∗∗
---------------------------------------------
Cyberkriminelle haben Daten bei Substack abgezogen. Der Datensatz umfasst rund 700.000 Einträge und ist im Netz verfügbar.
---------------------------------------------
https://heise.de/-11167482
∗∗∗ Angriff per Signal: BfV und BSI warnen Politiker, Militärs und Diplomaten ∗∗∗
---------------------------------------------
Ein vergangene Woche bekannt gewordener Angriff auf Nutzer des Messengers Signal zielt auf Bundestagsabgeordnete und andere wichtige Personen ab.
---------------------------------------------
https://heise.de/-11168254
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Friday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (freerdp, kernel, python3, and python3.12-wheel), Debian (alsa-lib, chromium, openjdk-25, phpunit, tomcat10, tomcat11, and tomcat9), Fedora (openqa, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), Mageia (python-django), SUSE (alloy, cups, dpdk, expat, glib2, java-1_8_0-ibm, java-1_8_0-openj9, java-25-openjdk, kernel, libpainter0, libsoup, libxml2, openssl-3, python-filelock, python-wheel, python312-Django6, thunderbird, traefik2, udisks2, wireshark, and xen), and Ubuntu (glib2.0, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, python3.14, python3.13, python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4, and tracker-miners).
---------------------------------------------
https://lwn.net/Articles/1057506/
∗∗∗ TeamViewer: Lücke erlaubt Zugriffe ohne vorherige Bestätigung ∗∗∗
---------------------------------------------
In TeamViewer wurde eine Sicherheitslücke entdeckt, die angemeldeten Angreifern Zugriffe auf Ressourcen erlaubt, bevor diese Berechtigung lokal bestätigt wurde. Aktualisierte Software-Pakete stehen bereit, um die Schwachstelle zu beheben. IT-Verantwortliche, die TeamViewer einsetzen, sollten zügig updaten.
---------------------------------------------
https://www.heise.de/news/TeamViewer-Luecke-erlaubt-Zugriffe-ohne-vorherige…
∗∗∗ Sicherheitsupdates F5 BIG-IP: Angreifer können Datenverkehr lahmlegen ∗∗∗
---------------------------------------------
Setzen Angreifer erfolgreich an Sicherheitslücken in BIG-IP-Appliances wie Advanced WAF/ASM oder APM an, können sie Abstürze auslösen oder eigentlich geschützte Daten einsehen. Dagegen stehen abgesicherte Versionen zum Download bereit. Bislang gibt es keine Berichte zu Attacken.
---------------------------------------------
https://heise.de/-11167422
∗∗∗ DSA-6122-1 chromium - security update ∗∗∗
---------------------------------------------
https://lists.debian.org/debian-security-announce/2026/msg00031.html
∗∗∗ TP-Link Systems Inc. VIGI Series IP Camera ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-01
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 04-02-2026 18:00 − Donnerstag 05-02-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Zendesk spam wave returns, floods users with Activate account emails ∗∗∗
---------------------------------------------
A fresh wave of spam is hitting inboxes worldwide, with users reporting that they are once again being bombarded by automated emails generated through companies unsecured Zendesk support systems. Some recipients say they are receiving hundreds of messages with strange or alarming subject lines.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/zendesk-spam-wave-returns-fl…
∗∗∗ CISA: VMware ESXi flaw now exploited in ransomware attacks ∗∗∗
---------------------------------------------
CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was used in zero-day attacks since at least February 2024. Broadcom patched this ESXi arbitrary-write vulnerability (tracked as CVE-2025-22225) almost one year ago, in March 2025, alongside a memory leak (CVE-2025-22226) and a TOCTOU flaw (CVE-2025-22224), and tagged them all as actively exploited zero-days.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-vmware-esxi-flaw-now-ex…
∗∗∗ Broken Phishing URLs, (Thu, Feb 5th) ∗∗∗
---------------------------------------------
For a few days, many phishing emails that landed into my mailbox contain strange URLs. [..] But the format of the URLs is broken! In a URL, parameters are extra pieces of information added after a question mark (?) to tell a website more details about a request; they are written as name=value pairs (for example “email=user@domain”), and multiple parameters are separated by an ampersand (&). [..] Threat actors implement this to break security controls.
---------------------------------------------
https://isc.sans.edu/diary/rss/32686
∗∗∗ Three clues that your LLM may be poisoned with a sleeper-agent back door ∗∗∗
---------------------------------------------
The threat sees an attacker embed a hidden backdoor into the model's weights – the importance assigned to the relationship between pieces of information – during its training. Attackers can activate the backdoor using a predefined phrase. [..] In a research paper [PDF] published this week, Kumar and coauthors detailed a lightweight scanner to help enterprises detect backdoored models.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/02/05/llm_poisoned…
∗∗∗ Technical Analysis of Marco Stealer ∗∗∗
---------------------------------------------
Zscaler ThreatLabz has discovered an information stealer that we named Marco Stealer, which was first observed in June 2025. Marco Stealer primarily targets browser data, cryptocurrency wallet information, files from popular cloud services like Dropbox and Google Drive, and other sensitive files stored on the victim’s system. Marco Stealer implements several anti-analysis techniques including string encryption and terminating security tools.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/technical-analysis-marco-st…
∗∗∗ The Shadow Campaigns: Uncovering Global Espionage ∗∗∗
---------------------------------------------
This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. We refer to the group’s activity as the Shadow Campaigns. [..] Over the past year, this group has compromised government and critical infrastructure organizations across 37 countries. This means that approximately one out of every five countries has experienced a critical breach from this group in the past year.
---------------------------------------------
https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espi…
∗∗∗ Black Basta: Defense Evasion Capability Embedded in Ransomware Payload ∗∗∗
---------------------------------------------
Normally the BYOVD defense evasion component of an attack would involve a distinct tool that would be deployed on the system prior to the ransomware payload in order to disable security software. However, in this attack, the vulnerable driver (an NsecSoft NSecKrnl driver) was bundled with the ransomware itself.
---------------------------------------------
https://www.security.com/threat-intelligence/black-basta-ransomware-byovd
∗∗∗ Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework ∗∗∗
---------------------------------------------
Cisco Talos uncovered “DKnife,” a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants that perform deep-packet inspection, manipulate traffic, and deliver malware via routers and edge devices. [..] DKnife’s attacks target a wide range of devices, including PCs, mobile devices, and Internet of Things (IoT) devices. It delivers and interacts with the ShadowPad and DarkNimbus backdoors by hijacking binary downloads and Android application updates.
---------------------------------------------
https://blog.talosintelligence.com/knife-cutting-the-edge/
∗∗∗ Sanctioned Bulletproof Host Linked to Hijacking of Old Home Routers ∗∗∗
---------------------------------------------
Compromised home routers in 30+ countries had DNS traffic redirected, sending users to malicious sites while normal browsing appeared unaffected. [..] According to Infoblox, the manipulated DNS traffic was routed to resolvers hosted by Aeza International, a Russian bulletproof hosting provider sanctioned by the US government in July 2025.
---------------------------------------------
https://hackread.com/sanctioned-bulletproof-host-hijack-old-home-routers/
∗∗∗ How to write your first obfuscator of Java Bytecode ∗∗∗
---------------------------------------------
In this article I describe Java bytecode obfuscation, using one of the challenges I did in 2023 as part of the interviews with Quarkslab for the position of Java compiler engineer in QShield.
---------------------------------------------
http://blog.quarkslab.com/how-to-write-your-first-obfuscator-of-java-byteco…
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco Security Advisories 05.02.2026 ∗∗∗
---------------------------------------------
Cisco Meeting Management, Cisco Secure Web Appliance, Cisco TelePresence Collaboration Endpoint Software and RoomOS, Cisco Prime Infrastructure, Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure,
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/Search.x?publicationTypeIDs…
∗∗∗ Security updates for Thursday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (brotli, curl, kernel, python-wheel, and python3.12), Debian (containerd), Fedora (gnupg2, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), Mageia (expat), Oracle (qemu-kvm and util-linux), Red Hat (kernel, kernel-rt, opentelemetry-collector, and python3.12-wheel), SUSE (abseil-cpp, dpdk, freerdp, glib2, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-ibm, java-1_8_0-openj9, java-1_8_0-openjdk, java-21-openj9, kernel, libsoup, libsoup-3_0-0, openssl-3, patch, python-Django, rekor, rizin, udisks2, and xrdp), and Ubuntu (gh, linux, linux-aws, linux-azure, linux-azure-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux, linux-aws, linux-azure, linux-gcp, linux-oem-6.17, linux-oracle, linux-raspi, linux-realtime, linux, linux-gke, linux-gkeop, linux-hwe-6.8, linux-oracle, linux-oracle-6.8, linux-raspi, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-realtime, linux-intel-iot-realtime, and linux-realtime, linux-realtime-6.8, linux-raspi-realtime).
---------------------------------------------
https://lwn.net/Articles/1057381/
∗∗∗ Automatisierungstool n8n: Weitere kritische Lücken gestopft ∗∗∗
---------------------------------------------
Im Automatisierungstool n8n haben die Entwickler weitere Sicherheitslücken gestopft. Ein Update auf die jüngste Fassung ist empfehlenswert. [..] Eine Auflistung der neuen CVE-Einträge nach Schweregrad sortiert bietet jedoch einen Überblick, Details finden sich auf der n8n-Sicherheitsseite.
---------------------------------------------
https://heise.de/-11165845
∗∗∗ Splunk: SVD-2026-0201: Third-Party Package Updates in Splunk SOAR - February 2026 ∗∗∗
---------------------------------------------
https://advisory.splunk.com//advisories/SVD-2026-0201
∗∗∗ Splunk: SVD-2025-1205: Incorrect permissions assignment on Splunk Enterprise for Windows during new installation or upgrade ∗∗∗
---------------------------------------------
https://advisory.splunk.com//advisories/SVD-2025-1205
∗∗∗ Zyxel security advisory for post-authentication command injection vulnerability in the DDNS configuration CLI command of ZLD firewalls ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
∗∗∗ Patchday Android: Treiberlücke gefährdet Pixel-Smartphones ∗∗∗
---------------------------------------------
https://heise.de/-11165905
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 03-02-2026 18:00 − Mittwoch 04-02-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Wave of Citrix NetScaler scans use thousands of residential proxies ∗∗∗
---------------------------------------------
A coordinated reconnaissance campaign targeting Citrix NetScaler infrastructure over the past week used tens of thousands of residential proxies to discover login panels.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/wave-of-citrix-netscaler-sca…
∗∗∗ Schlüssel kaputt: Weitere Ransomware-Panne führt zu Totalverlust ∗∗∗
---------------------------------------------
In der Nitrogen-Ransomware klafft ein Bug, der alle Lösegeldverhandlungen ad absurdum führt. Die Daten können nicht mehr entschlüsselt werden.
---------------------------------------------
https://www.golem.de/news/schluessel-kaputt-weitere-ransomware-panne-fuehrt…
∗∗∗ AI agents cant yet pull off fully autonomous cyberattacks - but they are already very helpful to crims ∗∗∗
---------------------------------------------
Dont relax: This is a when, not if scenario AI agents and other systems cant yet conduct cyberattacks fully on their own - but they can help criminals in many stages of the attack chain, according to the International AI Safety report.
---------------------------------------------
https://www.theregister.com/2026/02/03/autonomous_cyberattacks_not_real_yet/
∗∗∗ Clouds rush to deliver OpenClaw-as-a-service offerings ∗∗∗
---------------------------------------------
As analyst house Gartner declares AI tool ‘comes with unacceptable cybersecurity risk’ and urges admins to snuff it out If you’re brave enough to want to run the demonstrably insecure AI assistant OpenClaw, several clouds have already started offering it as a service.
---------------------------------------------
https://www.theregister.com/2026/02/04/cloud_hosted_openclaw/
∗∗∗ Angriffe auf Solarwinds Web Help Desk, FreePBX und Gitlab beobachtet ∗∗∗
---------------------------------------------
Die CISA warnt vor jüngst beobachteten Angriffen auf Sicherheitslücken in Solarwinds Web Help Desk, FreePBX und Gitlab.
---------------------------------------------
https://www.heise.de/news/Angriffe-auf-Solarwinds-Web-Help-Desk-FreePBX-und…
∗∗∗ Phishing: Falsche Cloud-Speicher-Warnung nachverfolgt ∗∗∗
---------------------------------------------
Phishing-Mails zielen nicht nur direkt auf Zugangsdaten ab, sondern bringen Opfer öfter zu Affiliate-Marketing-Seiten.
---------------------------------------------
https://www.heise.de/news/Phishing-Falsche-Cloud-Speicher-Warnung-nachverfo…
∗∗∗ Gesucht: Notfallhandwerksdienst, Gefunden: Vermittlungsagentur ∗∗∗
---------------------------------------------
Hinter zahlreichen Webseiten von Notfallinstallateuren, Schlüsseldiensten und ähnlichen Unternehmen stecken gar keine Handwerksbetriebe, sondern lediglich Vermittlungsagenturen. Das ist nicht illegal, kann für Betroffene aber dennoch unangenehme Folgen haben. Woran man die Webauftritte der Agenturen erkennt und wie man am besten für den Ernstfall vorsorgt.
---------------------------------------------
https://www.watchlist-internet.at/news/vermittlungsagentur-statt-handwerksd…
∗∗∗ Exclusive: US used cyber weapons to disrupt Iranian air defenses during 2025 strikes ∗∗∗
---------------------------------------------
The U.S. military digitally disrupted Iranian air missile defense systems during its operation last year against the country’s nuclear program, some of the most sophisticated action Cyber Command has taken to date against Iran.
---------------------------------------------
https://therecord.media/iran-nuclear-cyber-strikes-us
∗∗∗ Phishing Campaigns Abuse Trusted Cloud Platforms, Raising New Risks for Enterprises ∗∗∗
---------------------------------------------
ANY.RUN experts report a surge in phishing campaigns abusing trusted cloud and CDN platforms to bypass security controls and target enterprise users.
---------------------------------------------
https://hackread.com/phishing-campaigns-cloud-platforms-enterprises-risks/
∗∗∗ React Server Components Exploitation Consolidates as Two IPs Generate Majority of Attack Traffic ∗∗∗
---------------------------------------------
Two months after CVE-2025-55182 was disclosed on December 3, 2025, exploitation activity targeting React Server Components has consolidated significantly.
---------------------------------------------
https://www.greynoise.io/blog/react2shell-exploitation-consolidates
∗∗∗ Native Sysmon-Integration in Windows rückt näher ∗∗∗
---------------------------------------------
Microsoft hat Windows-Insider-Vorschauen veröffentlicht, die das mächtige Sysmon-Protokollierungstool als Windows-Feature mitbringen.
---------------------------------------------
https://heise.de/-11164696
∗∗∗ Phishing: Falsche Cloud-Speicher-Warnung nachverfolgt ∗∗∗
---------------------------------------------
Phishing-Mails zielen nicht nur direkt auf Zugangsdaten ab, sondern bringen Opfer öfter zu Affiliate-Marketing-Seiten.
---------------------------------------------
https://heise.de/-11164973
∗∗∗ Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious ∗∗∗
---------------------------------------------
Datadog Security Research has identified an active web traffic hijacking campaign that targets NGINX installations and management panels like Baota (BT). In this post, we provide our analysis of the techniques this campaign uses and share indicators of compromise you can check for in your NGINX configurations.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/web-traffic-hijacking-nginx-con…
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical Vulnerability Alert: CVE-2025-40551 in SolarWinds Web Help Desk ∗∗∗
---------------------------------------------
https://www.bitsight.com/blog/cve-2025-40551-solarwinds-critical-vulnerabil…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 02-02-2026 18:00 − Dienstag 03-02-2026 18:00
Handler: Felician Fuchs
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Aktive Ausnutzung von Sicherheitslücken in Ivanti Endpoint Manager Mobile (CVE-2026-1281, CVE-2026-1340) ∗∗∗
---------------------------------------------
Zwei kürzlich behobene Sicherheitslücken in Ivanti Endpoint Manager Mobile (CVE-2026-1281 und CVE-2026-1340, siehe dazu unsere Warnung vom 31.01.2026 sowie eine technische Analyse der Sicherheitsexpert:innen von Watchtowr) werden bereits von Bedrohungsakteuren ausgenutzt. Laut Ivanti selbst ist die Untersuchung der bisher bekannten Vorfälle noch im Gange und verlässliche technische Indikatoren liegen noch nicht vor.
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/2/aktive-ausnutzung-von-sicherheitslu…
∗∗∗ Hackers exploit critical React Native Metro bug to breach dev systems ∗∗∗
---------------------------------------------
Hackers are targeting developers by exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native to deliver malicious payloads for Windows and Linux.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-use-critical-react-n…
∗∗∗ Iron Mountain: Data breach mostly limited to marketing materials ∗∗∗
---------------------------------------------
Iron Mountain, a leading data storage and recovery services company, says that a recent breach claimed by the Everest extortion gang is limited to mostly marketing materials.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/iron-mountain-data-breach-mo…
∗∗∗ Attackers Harvest Dropbox Logins Via Fake PDF Lures ∗∗∗
---------------------------------------------
A malware-free phishing campaign targets corporate inboxes and asks employees to view "request orders," ultimately leading to Dropbox credential theft.
---------------------------------------------
https://www.darkreading.com/cloud-security/attackers-harvest-dropbox-logins…
∗∗∗ Detecting and Monitoring OpenClaw (clawdbot, moltbot) ∗∗∗
---------------------------------------------
Last week, a new AI agent framework was introduced to automate "live". It targets office work in particular, focusing on messaging and interacting with systems. The tool has gone viral not so much because of its features, which are similar to those of other agent frameworks, but because of a stream of security oversights in its design.
---------------------------------------------
https://isc.sans.edu/diary/rss/32678
∗∗∗ Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users ∗∗∗
---------------------------------------------
A security audit of 2,857 skills on ClawHub has found 341 malicious skills across multiple campaigns, according to new findings from Koi Security, exposing users to new supply chain risks. ClawHub is a marketplace designed to make it easy for OpenClaw users to find and install third-party skills.
---------------------------------------------
https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.ht…
∗∗∗ APT28 Leverages CVE-2026-21509 in Operation Neusploit ∗∗∗
---------------------------------------------
In January 2026, Zscaler ThreatLabz identified a new campaign in-the-wild, tracked as Operation Neusploit, targeting countries in the Central and Eastern European region. In this campaign, the threat actor leveraged specially crafted Microsoft RTF files to exploit CVE-2026-21509 and deliver malicious backdoors in a multi-stage infection chain.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/apt28-leverages-cve-2026-21…
∗∗∗ Neue Runde für den Dauerbrenner: Phishing-SMS im Namen von FinanzOnline ∗∗∗
---------------------------------------------
Wirklich zum Stillstand kam die Betrugsmasche ohnehin nie, aktuell ist aber eine Welle von besonderem Ausmaß zu beobachten. Es geht um die fast schon klassischen Phishing-SMS im Namen von FinanzOnline, die vor einem Ablaufen der Registrierung warnen. In Wahrheit haben es Kriminelle auf die Kontakt- und Bankdaten ihrer Opfer abgesehen.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-sms-finanzonline/
∗∗∗ WhatsApp Encryption, a Lawsuit, and a Lot of Noise ∗∗∗
---------------------------------------------
It’s not every day that we see mainstream media get excited about encryption apps! For that reason, the past several days have been fascinating, since we’ve been given not one but several unusual stories about the encryption used in WhatsApp.
---------------------------------------------
https://blog.cryptographyengineering.com/2026/02/02/whatsapp-encryption-a-l…
∗∗∗ The art of the invisible key: Passkey global breakthrough ∗∗∗
---------------------------------------------
Introduction Passkeys now protects billions of accounts, redefining how the world signs in through stronger, more secure authentication without a password. Yet this global movement runs deeper.
---------------------------------------------
https://www.cyberark.com/resources/threat-research-blog/the-art-of-the-invi…
∗∗∗ The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit ∗∗∗
---------------------------------------------
Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom. Active since 2009, the group is known for its targeted espionage campaigns primarily impacting organizations across Southeast Asia and more recently Central America, focusing on government, telecom, aviation, critical infrastructure, and media sectors.
---------------------------------------------
https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blos…
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdate: Unbefugte Zugriffe auf WatchGuard Firebox vorstellbar ∗∗∗
---------------------------------------------
Angreifer können auf Firebox-Firewalls von WatchGuard zugreifen. Reparierte Fireware-OS-Version stehen zum Download bereit.
---------------------------------------------
https://www.heise.de/news/Sicherheitsupdate-Unbefugte-Zugriffe-auf-WatchGua…
∗∗∗ Critical vLLM Flaw Exposes Millions of AI Servers to Remote Code Execution ∗∗∗
---------------------------------------------
A newly disclosed security flaw has placed millions of AI servers at risk after researchers identified a critical vulnerability in vLLM, a widely deployed Python package for serving large language models. The issue, tracked as CVE-2026-22778 (GHSA-4r2x-xpjr-7cvv), enables remote code execution (RCE) by submitting a malicious video URL to a vulnerable vLLM API endpoint. The vulnerability affects vLLM versions 0.8.3 through 0.14.0 and was patched in version 0.14.1.
---------------------------------------------
https://thecyberexpress.com/cve-2026-22778-vllm-rce-malicious-video-link/
∗∗∗ ZDI-26-043: (0Day) npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability ∗∗∗
---------------------------------------------
This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-0775.
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-043/
∗∗∗ Micropatches released for Microsoft Excel Remote Code Execution Vulnerability (CVE-2025-62203) ∗∗∗
---------------------------------------------
November 2025 Windows Updates brought a patch for CVE-2025-62203, a remote code execution vulnerability in Microsoft Excel that could allow a remote attacker to have their malicious code executed on users computer upon opening an Excel file. The vulnerability was discovered and reported to Microsoft by Quan Jin with DBAPPSecurity.
---------------------------------------------
https://blog.0patch.com/2026/02/micropatches-released-for-microsoft.html
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (fence-agents, gcc-toolset-15-binutils, golang-github-openprinting-ipp-usb, iperf3, kernel, kernel-rt, openssl, osbuild-composer, php:8.2, python3, util-linux, and wireshark), Debian (clamav and xrdp), Fedora (gimp and openttd), Mageia (docker-containerd), Oracle (gimp:2.8, golang-github-openprinting-ipp-usb, grafana-pcp, image-builder, iperf3, kernel, openssl, osbuild-composer, php, php:8.2, php:8.3, python3.9, util-linux, and wireshark), SUSE (cockpit-subscriptions, elemental-register, elemental-toolkit, glibc, gpg2, logback, openssl-1_1, python-urllib3, ucode-amd, and unbound), and Ubuntu (inetutils, libpng1.6, mysql-8.0, mysql-8.4, openjdk-17, openjdk-17-crac, openjdk-21, openjdk-21-crac, openjdk-25, openjdk-25-crac, openjdk-8, openjdk-lts, and thunderbird).
---------------------------------------------
https://lwn.net/Articles/1057047/
∗∗∗ Jetzt updaten! Angreifer übernehmen SmarterMail-Instanzen als Admin ∗∗∗
---------------------------------------------
Alle drei mittlerweile in SmarterMail 100.0.9511 geschlossenen Sicherheitslücken (CVE-2026-23760), CVE-2026-24423, CVE-2025-52691) sind mit dem Bedrohungsgrad „kritisch“ eingestuft. Alle vorigen Ausgaben sollen verwundbar sein. Der US-Sicherheitsbehörde CISA zufolge nutzen Angreifer die ersten beiden Schwachstellen bereits aus.
---------------------------------------------
https://heise.de/-11163471
∗∗∗ Improper file access permission settings in Mitsubishi Small-Capacity UPS Shutdown Software FREQSHIP-mini for Windows ∗∗∗
---------------------------------------------
https://jvn.jp/en/jp/JVN64883963/
∗∗∗ Kubernetes CVE-2026-24514: ingress-nginx Admission Controller denial of service ∗∗∗
---------------------------------------------
https://github.com/kubernetes/kubernetes/issues/136680
∗∗∗ Kubernetes CVE-2026-24513: ingress-nginx auth-url protection bypass ∗∗∗
---------------------------------------------
https://github.com/kubernetes/kubernetes/issues/136679
∗∗∗ Kubernetes CVE-2026-24512: ingress-nginx rules.http.paths.path nginx configuration injection ∗∗∗
---------------------------------------------
https://github.com/kubernetes/kubernetes/issues/136678
∗∗∗ Kuberenetes CVE-2026-1580: ingress-nginx auth-method nginx configuration injection∗∗∗
---------------------------------------------
https://github.com/kubernetes/kubernetes/issues/136677
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 30-01-2026 18:00 − Montag 02-02-2026 18:00
Handler: Felician Fuchs
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Cloud storage payment scam floods inboxes with fake renewals ∗∗∗
---------------------------------------------
Over the past few months, a large-scale cloud storage subscription scam campaign has been targeting users worldwide with repeated emails falsely warning recipients that their photos, files, and accounts are about to be blocked or deleted due to an alleged payment failure.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cloud-storage-payment-scam-f…
∗∗∗ NationStates confirms data breach, shuts down game site ∗∗∗
---------------------------------------------
NationStates, a multiplayer browser-based game, has confirmed a data breach after taking its website offline earlier this week to investigate a security incident.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/nationstates-confirms-data-b…
∗∗∗ Panera Bread breach impacts 5.1 million accounts, not 14 million customers ∗∗∗
---------------------------------------------
The data breach notification service Have I Been Pwned says that a data breach at the U.S. food chain Panera Bread affected 5.1 million accounts, not 14 million customers as previously reported.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/panera-bread-data-breach-imp…
∗∗∗ Spionagegefahr: Verfassungsschutz warnt vor E-Autos aus China ∗∗∗
---------------------------------------------
E-Autos aus China könnten theoretisch ferngesteuert werden. Die technischen Risiken sind dokumentiert - doch auch Tesla sammelt massenhaft Daten.
---------------------------------------------
https://www.golem.de/news/spionagegefahr-verfassungsschutz-warnt-vor-e-auto…
∗∗∗ Texteditor: Notepad++-Server gehackt und Update-Traffic manipuliert ∗∗∗
---------------------------------------------
Angreifern ist es gelungen, die Update-Infrastruktur von Notepad++ zu kompromittieren und Traffic umzuleiten. Der Entwickler entschuldigt sich.
---------------------------------------------
https://www.golem.de/news/texteditor-notepad-server-gehackt-und-update-traf…
∗∗∗ Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 ∗∗∗
---------------------------------------------
In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-free vulnerability (CVE-2025-31235) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability.
---------------------------------------------
https://projectzero.google/2026/01/sound-barrier-2.html
∗∗∗ Google Presentations Abused for Phishing ∗∗∗
---------------------------------------------
Charlie, one of our readers, has forwarded an interesting phishing email. The email was sent to users of the Vivladi Webmail service.
---------------------------------------------
https://isc.sans.edu/diary/rss/32668
∗∗∗ AI Coding Assistants Secretly Copying All Code to China ∗∗∗
---------------------------------------------
There’s a new report about two AI coding assistants, used by 1.5 million developers, that are surreptitiously sending a copy of everything they ingest to China.Maybe avoid using them.
---------------------------------------------
https://www.schneier.com/blog/archives/2026/02/ai-coding-assistants-secretl…
∗∗∗ Shadow Directories: A Unique Method to Hijack WordPress Permalinks ∗∗∗
---------------------------------------------
Last month, while working on a WordPress cleanup case, a customer reached out with a strange complaint: their website looked completely normal to them and their visitors, but Google search results were showing something very different. Instead of normal titles and descriptions, Google was displaying casino and gambling-related content. We have been seeing rising cases of spam on WordPress websites. What made this even more confusing was where the spam was appearing.
---------------------------------------------
https://blog.sucuri.net/2026/01/shadow-directories-a-unique-method-to-hijac…
∗∗∗ Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup ∗∗∗
---------------------------------------------
A former Google engineer accused of stealing thousands of the companys confidential documents to build a startup in China has been convicted in the U.S., the Department of Justice (DoJ) announced Thursday.
---------------------------------------------
https://thehackernews.com/2026/01/ex-google-engineer-convicted-for.html
∗∗∗ Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a supply chain attack targeting the Open VSX Registry in which unidentified threat actors compromised a legitimate developers resources to push malicious updates to downstream users.
---------------------------------------------
https://thehackernews.com/2026/02/open-vsx-supply-chain-attack-used.html
∗∗∗ eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware ∗∗∗
---------------------------------------------
The update infrastructure for eScan antivirus, a security solution developed by Indian cybersecurity company MicroWorld Technologies, has been compromised by unknown attackers to deliver a persistent downloader to enterprise and consumer systems.
---------------------------------------------
https://thehackernews.com/2026/02/escan-antivirus-update-servers.html
∗∗∗ Sicherheitslücke: Tausch weiterer elektronischer Heilberufsausweise in Arbeit ∗∗∗
---------------------------------------------
Kunden von D-Trust und SHC+Care müssen ihre bereits ECC-fähigen elektronischen Heilberufsausweise (eHBA) tauschen. Wie viele das betrifft, ist unklar.
---------------------------------------------
https://www.heise.de/news/Digital-Health-Tausch-weiterer-E-Heilberufsauswei…
∗∗∗ Anonymisierendes Linux: Notfall-Update Tails 7.4.1 erschienen ∗∗∗
---------------------------------------------
Die auf Anonymität im Netz ausgerichtete Linux-Distribution Tails ist in Version 7.4.1 erschienen – ein Notfall-Update.
---------------------------------------------
https://www.heise.de/news/Anonymisierendes-Linux-Notfall-Update-Tails-7-4-1…
∗∗∗ Please Don’t Feed the Scattered Lapsus Shiny Hunters ∗∗∗
---------------------------------------------
A prolific data ransom gang that calls itself Scattered Lapsus ShinyHunters (SLSH) has a distinctive playbook when it seeks to extort payment from victim firms: Harassing, threatening and even swatting executives and their families, all while notifying journalists and regulators about the extent of the intrusion.
---------------------------------------------
https://krebsonsecurity.com/2026/02/please-dont-feed-the-scattered-lapsus-s…
∗∗∗ How fake party invitations are being used to install remote access tools ∗∗∗
---------------------------------------------
“You’re invited!” It sounds friendly, familiar and quite harmless. But in a scam we recently spotted, that simple phrase is being used to trick victims into installing a full remote access tool on their Windows computers—giving attackers complete control of the system.
---------------------------------------------
https://www.malwarebytes.com/blog/threat-intel/2026/02/how-fake-party-invit…
∗∗∗ Microsoft erklärt NTLM als "deprecated" – Deaktivierung in nächster Windows-Version ∗∗∗
---------------------------------------------
Microsoft hat die veraltete NTLM-Authentifizierung in Windows als "deprecated" erklärt. In der nächsten Windows Version (Server und Client) wird NTLM standardmäßig deaktiviert und die Kerberos-Authentifizierung Standard. Damit neigt sich die Verwendung von NTLM seinem Ende zu.
---------------------------------------------
https://borncity.com/blog/2026/02/01/microsoft-erklaert-ntlm-als-deprecated…
∗∗∗ US Seizes $400 Million Linked to Helix Dark Web Crypto Mixer ∗∗∗
---------------------------------------------
US authorities take control of over $400 million in crypto, cash, and property tied to Helix, a major darknet bitcoin mixing service used by drug markets.
---------------------------------------------
https://hackread.com/us-seizes-400m-helix-dark-web-crypto-mixer/
∗∗∗ Windows Malware Uses Pulsar RAT for Live Chats While Stealing Data ∗∗∗
---------------------------------------------
We usually think of computer viruses as silent, invisible programs running in the background, but a worrying discovery shows that modern hackers are getting much more personal.
---------------------------------------------
https://hackread.com/windows-malware-pulsar-rat-live-chats-steal-data/
∗∗∗ Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS ∗∗∗
---------------------------------------------
Mandiant is tracking a significant expansion and escalation in the operations of threat clusters associated with ShinyHunters-branded extortion. As detailed in our companion report, 'Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft', these campaigns leverage evolved voice phishing (vishing) and victim-branded credential harvesting to successfully compromise single sign-on (SSO) credentials and enroll unauthorized devices into victim multi-factor authentication (MFA) solutions.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/defense-against-sh…
∗∗∗ Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft ∗∗∗
---------------------------------------------
Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) credentials and multi-factor authentication (MFA) codes.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhun…
∗∗∗ Manic Monday: A Day in the Life of Threat Hunting ∗∗∗
---------------------------------------------
Discover a day in the life of threat hunting with Bitsight Adversary Intelligence. Learn how security teams detect and disrupt threats before damage is done.
---------------------------------------------
https://www.bitsight.com/blog/day-in-the-life-threat-hunting
∗∗∗ Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) ∗∗∗
---------------------------------------------
When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief. Clearly, the universe had decided to continue mocking Secure-By-Design signers right on schedule - every January.
---------------------------------------------
https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-i…
∗∗∗ The European Space Agency got hacked, and now we own the domain used! ∗∗∗
---------------------------------------------
It's not often that two of my interests align so well, but we're talking about space rockets and cyber security! Whilst Magecart and Magecart-style attacks might not be the most common attack vector at the moment, they are still happening with worrying frequency, and they are still catching out some pretty big organisations.
---------------------------------------------
https://scotthelme.ghost.io/the-european-space-agency-got-hacked-and-now-we…
∗∗∗ archive.today is directing a DDOS attack against my blog ∗∗∗
---------------------------------------------
Around January 11, 2026, archive.today (aka archive.is, archive.md, etc) started using its users as proxies to conduct a distributed denial of service (DDOS) attack against Gyrovague, my personal blog.
---------------------------------------------
https://gyrovague.com/2026/02/01/archive-today-is-directing-a-ddos-attack-a…
∗∗∗ Exploiting MediaTeks Download Agent ∗∗∗
---------------------------------------------
In September 2025, Chimera quietly announced “world-first” support for MediaTek’s latest Dimensity 9400 and 8400 SoCs running DAs compiled months after MediaTek had patched Carbonara. So we figured they’d either found a way around the patches, or they were sitting on something entirely new. We had to find out.
---------------------------------------------
https://blog.r0rt1z2.com/posts/exploiting-mediatek-datwo/
∗∗∗ Hacking Moltbook: The AI Social Network Any Human Can Control ∗∗∗
---------------------------------------------
1 exposed database. 35,000 emails. 1.5M API keys. And 17,000 humans behind the not-so-autonomous AI network.
---------------------------------------------
https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-k…
∗∗∗ Inside Lodash’s Security Reset and Maintenance Reboot ∗∗∗
---------------------------------------------
For more than a decade, Lodash has been one of the most widely deployed libraries in the JavaScript ecosystem. Its utilities are deeply embedded in frameworks, build systems, and production applications across the web. Like many foundational dependencies, Lodash evolved into critical infrastructure long before the ecosystem had strong models for funding, governance, or long-term security operations.
---------------------------------------------
https://socket.dev/blog/inside-lodash-security-reset?utm_medium=feed
∗∗∗ Britain and Japan Join Forces on Cybersecurity and Strategic Minerals ∗∗∗
---------------------------------------------
Japan and Britain have agreed to expand cooperation on cybersecurity and critical mineral supply chains, framing the move as a strategic response to intensifying geopolitical, economic, and technological pressures. The British and Japanese cybersecurity strategy and agreement were confirmed during British Prime Minister Keir Starmer’s overnight visit to Tokyo, where leaders from both countries reaffirmed their commitment to collective security and economic resilience.
---------------------------------------------
https://thecyberexpress.com/britain-japanese-cybersecurity-cooperation/
∗∗∗ Russian APT28 Exploit Zero-Day Hours After Microsoft Discloses Office Vulnerability ∗∗∗
---------------------------------------------
Ukraines cyber defenders warn Russian hackers weaponized a Microsoft zero-day within 24 hours of public disclosure, targeting government agencies with malicious documents delivering Covenant framework backdoors.
---------------------------------------------
https://thecyberexpress.com/russian-apt28-exploit-zero-day-cve-2026-21509/
∗∗∗ Default Credentials, Vulnerable Devices Exploited in Polish Energy Grid Attack ∗∗∗
---------------------------------------------
A cyberattack by Russian state-sponsored threat actors that targeted at least 30 wind and solar farms in Poland relied on default credentials, lack of multi-factor authentication (MFA) and outdated and misconfigured devices, according to a new report on the December 2025 incident by CERT Polska, the Polish computer emergency response team.
---------------------------------------------
https://thecyberexpress.com/default-credentials-polish-energy-grid-attack/
=====================
= Vulnerabilities =
=====================
∗∗∗ OpenSSL: 12 Sicherheitslecks, eines erlaubt Schadcodeausführung und ist kritisch ∗∗∗
---------------------------------------------
In OpenSSL wurden 12 Sicherheitslücken entdeckt – mit KI-Tools. Eine davon gilt als kritisch. Aktualisierte Software steht bereit.
---------------------------------------------
https://www.heise.de/news/OpenSSL-12-Sicherheitslecks-eines-erlaubt-Schadco…
∗∗∗ Sicherheitspatches: Root-Attacken auf IBM Db2 möglich ∗∗∗
---------------------------------------------
Mehrere Sicherheitslücken gefährden IBMs Datenbankmanagementsystem Db2. Primär können Instanzen abstürzen.
---------------------------------------------
https://www.heise.de/news/Sicherheitspatches-Root-Attacken-auf-IBM-Db2-moeg…
∗∗∗ Dell Unity: Angreifer können Schadcode mit Root-Rechten ausführen ∗∗∗
---------------------------------------------
Admins sollten zeitnah ein wichtiges Sicherheitsupdate für Dell Unity Operating Environment installieren.
---------------------------------------------
https://www.heise.de/news/Dell-Unity-Angreifer-koennen-Schadcode-mit-Root-R…
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (iperf3, kernel, and php), Debian (ceph, pillow, pyasn1, python-django, and python-tornado), Fedora (bind9-next, cef, chromium, fontforge, java-21-openjdk, java-25-openjdk, java-latest-openjdk, mingw-python-urllib3, mingw-python-wheel, nodejs20, nodejs22, nodejs24, opencc, openssl, python-wheel, and qownnotes), Red Hat (binutils, gcc-toolset-13-binutils, gcc-toolset-14-binutils, gcc-toolset-15-binutils, java-1.8.0-openjdk, and java-25-openjdk), Slackware (expat), SUSE (bind, cacti, cacti-spine, chromedriver, chromium, dirmngr, fontforge-20251009, glib2, golang-github-prometheus-prometheus, govulncheck-vulndb, icinga2, ImageMagick, kernel, logback, openCryptoki, openssl-1_1, python311-djangorestframework, python311-pypdf, python314, python315, qemu, and xen), and Ubuntu (linux, linux-aws, linux-aws-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm and linux-aws-fips, linux-fips, linux-gcp-fips).
---------------------------------------------
https://lwn.net/Articles/1056923/
∗∗∗ Privileged File System Vulnerability Present in a SCADA System ∗∗∗
---------------------------------------------
We detail our discovery of CVE-2025-0921. This privileged file system flaw in SCADA system Iconics Suite could lead to a denial-of-service (DoS) attack.
---------------------------------------------
https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/
∗∗∗ Vulnerability & Patch Roundup — January 2026 ∗∗∗
---------------------------------------------
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.To help educate website owners about potential threats to their environments, we’ve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month.
---------------------------------------------
https://blog.sucuri.net/2026/01/vulnerability-patch-roundup-january-2026.ht…
∗∗∗ Multiple vulnerabilities in Cybozu Garoon ∗∗∗
---------------------------------------------
https://jvn.jp/en/jp/JVN35265756/
∗∗∗ Multiple Microsoft Office products vulnerable to untrusted search path ∗∗∗
---------------------------------------------
https://jvn.jp/en/jp/JVN04984838/
∗∗∗ Sonatype Nexus Repository vulnerable to server-side request forgery ∗∗∗
---------------------------------------------
https://jvn.jp/en/jp/JVN64861120/
∗∗∗ OS command injection in raspap-webgui ∗∗∗
---------------------------------------------
https://jvn.jp/en/jp/JVN27202136/
∗∗∗ ZDI-26-050: GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-050/
∗∗∗ KI-Bot: OpenClaw (Moltbot) mit hochriskanter Codeschmuggel-Lücke ∗∗∗
---------------------------------------------
https://www.heise.de/news/KI-Bot-OpenClaw-Moltbot-mit-hochriskanter-Codesch…
∗∗∗ Multiple vulnerabilities in Native Instruments Native Access (MacOS) ∗∗∗
---------------------------------------------
https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities…
∗∗∗ CVE-2025-60021 (CVSS 9.8): command injection in Apache bRPC heap profiler ∗∗∗
---------------------------------------------
https://www.cyberark.com/resources/threat-research-blog/cve-2025-60021-cvss…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 29-01-2026 18:00 − Freitag 30-01-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) ∗∗∗
---------------------------------------------
When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief. Clearly, the universe had decided to continue mocking Secure-By-Design signers right on schedule - every January. [..] As we are always keen to remind everyone, today’s blog post didn’t ruin your weekend. Firstly, the APT currently exploiting these vulnerabilities, and secondly, your lack of response to the warnings from Ivanti and CISA did.
---------------------------------------------
https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-i…
∗∗∗ Hugging Face abused to spread thousands of Android malware variants ∗∗∗
---------------------------------------------
A new Android malware campaign is using the Hugging Face platform as a repository for thousands of variations of an APK payload that collects credentials for popular financial and payment services.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hugging-face-abused-to-sprea…
∗∗∗ Microsoft fixes Outlook bug blocking access to encrypted emails ∗∗∗
---------------------------------------------
Microsoft has fixed a known issue that prevented Microsoft 365 customers from opening encrypted emails in classic Outlook after a recent update.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-bug…
∗∗∗ Undocumented "TelnetEnable" functionality of End of Service NETGEAR products ∗∗∗
---------------------------------------------
Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box. [..] Stop using the end of service products, including NETGEAR PR2000.
---------------------------------------------
https://jvn.jp/en/jp/JVN46722282/
∗∗∗ Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries ∗∗∗
---------------------------------------------
Ollama is an open-source framework that allows users to easily download, run, and manage large language models (LLMs) locally on Windows, macOS, and Linux. While the service binds to the localhost address at 127.0.0[.]1:11434 by default, it's possible to expose it to the public internet by means of a trivial change: configuring it to bind to 0.0.0[.]0 or a public interface. The fact that Ollama, like the recently popular Moltbot (formerly Clawdbot), is hosted locally and operates outside of the enterprise security perimeter, poses new security concerns.
---------------------------------------------
https://thehackernews.com/2026/01/researchers-find-175000-publicly.html
∗∗∗ ShadowHS: A Fileless Linux Post‑Exploitation Framework Built on a Weaponized hackshell ∗∗∗
---------------------------------------------
Cyble Research & Intelligence Labs (CRIL) has identified a Linux intrusion chain leveraging a highly obfuscated, fileless loader that deploys a weaponized variant of hackshell entirely from memory. Cyble tracks this activity under the name ShadowHS, reflecting its fileless execution model and lineage from the original hackshell utility.
---------------------------------------------
https://cyble.com/blog/shadowhs-fileless-linux-post-exploitation-framework/
∗∗∗ Cybersicherheitschef der USA lädt vertrauliche Dokumente bei ChatGPT hoch ∗∗∗
---------------------------------------------
Offenbar hatte sich ausgerechnet der Boss eine Ausnahmegenehmigung für die Nutzung des Tools geholt und agierte damit umgehend fahrlässig.
---------------------------------------------
https://www.derstandard.at/story/3000000306469/cybersicherheitschef-der-usa…
∗∗∗ Arsink Spyware Posing as WhatsApp, YouTube, Instagram, TikTok Hits 143 Countries ∗∗∗
---------------------------------------------
The interesting thing about this campaign is that hackers are not using the official Google Play Store to spread this, but posting links on Telegram and Discord or using the file-sharing site MediaFire. [..] They basically offer ‘Pro’ or ‘Mod’ versions of these apps, promising special features that the real apps don’t have. But, as soon as you download one, the app immediately asks for a long list of permissions.
---------------------------------------------
https://hackread.com/arsink-spyware-whatsapp-youtube-instagram-tiktok/
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Friday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (curl, gimp:2.8, glibc, grafana, grafana-pcp, kernel, osbuild-composer, php:8.3, python-urllib3, python3.11, and python3.12), Debian (chromium), Mageia (ceph, gpsd, libxml2, openjdk, openssl, and xen), SUSE (abseil-cpp, assertj-core, coredns, freerdp, java-11-openjdk, java-25-openjdk, libxml2, openssl-1_0_0, openssl-1_1, python, python-filelock, and python311-sse-starlette), and Ubuntu (kernel, linux, linux-aws, linux-aws-hwe, linux-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-aws-fips, linux-fips, linux-fips, and texlive-bin).
---------------------------------------------
https://lwn.net/Articles/1056692/
∗∗∗ Kritische Schwachstellen in Ivanti Endpoint Manager Mobile - Updates empfohlen ∗∗∗
---------------------------------------------
Ivanti hat ein Security Advisory bezüglich kritischer Schwachstellen im Endpoint Manager Mobile veröffentlicht. Diese Sicherheitslücken werden bereits aktiv ausgenutzt. Die Schwachstellen ermöglichen einem*einer entfernten, nicht authentifizierten Angreifer:in, beliebigen Code auf dem betroffenen System auszuführen (Remote Code Execution), was die vollständige Kompromittierung des Servers erlaubt. CVE-2026-1281, CVE-2026-1340
---------------------------------------------
https://www.cert.at/de/warnungen/2026/1/kritische-schwachstellen-in-ivanti-…
∗∗∗ BoidCMS v2.1.2 Apache .htaccess Rule Bypass Leading to Information Disclosure ∗∗∗
---------------------------------------------
https://cxsecurity.com/issue/WLB-2026010019
∗∗∗ Lexmark Security Advisory ∗∗∗
---------------------------------------------
https://www.lexmark.com/content/dam/support/collateral/security-alerts/CVE-…
∗∗∗ KiloView Encoder Series ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-029-01
∗∗∗ Rockwell Automation ArmorStart LT ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-029-02
∗∗∗ Rockwell Automation ControlLogix ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-029-03
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 28-01-2026 18:00 − Donnerstag 29-01-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Aisuru botnet sets new record with 31.4 Tbps DDoS attack ∗∗∗
---------------------------------------------
The Aisuru/Kimwolf botnet launched a new massive distributed denial of service (DDoS) attack that peaked at 31.4 Tbps and 200 million requests per second, setting a new record.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/aisuru-botnet-sets-new-recor…
∗∗∗ Von wegen Virenschutz: Malware über Update-Server von Antivirus-Tool verteilt ∗∗∗
---------------------------------------------
Angreifer haben über das Antivirus-Tool eScan Malware auf Nutzersysteme geschleust. Ein Update-Server des Anbieters war kompromittiert.
---------------------------------------------
https://www.golem.de/news/von-wegen-virenschutz-malware-ueber-update-server…
∗∗∗ Theres a Rash of Scam Spam Coming From a Real Microsoft Address ∗∗∗
---------------------------------------------
There are reports that a legitimate Microsoft email address -- which Microsoft explicitly says customers should add to their allow list -- is delivering scam spam.
---------------------------------------------
https://it.slashdot.org/story/26/01/28/1849206/theres-a-rash-of-scam-spam-c…
∗∗∗ Ransomware crims forced to take off-RAMP as FBI seizes forum ∗∗∗
---------------------------------------------
Ransomware crims have just lost one of their best business platforms. US law enforcement has seized the notorious RAMP cybercrime forum's dark web and clearnet domains.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/01/28/fbi_seizes_r…
∗∗∗ Patch or perish: Vulnerability exploits now dominate intrusions ∗∗∗
---------------------------------------------
Apply fixes within a few hours or face the music, say the pros.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/01/29/faster_patch…
∗∗∗ ConsentFix (a.k.a. AuthCodeFix): Detecting OAuth2 Authorization Code Phishing ∗∗∗
---------------------------------------------
ConsentFix (a.k.a. AuthCodeFix) is the latest variant of the fix-type phishing attacks, initially identified by Push Security1. In this technique, the adversary tricks the victim into generating an OAuth authorization code that is part of a localhost URL by signing in to the Azure CLI instance (or other vulnerable applications). Then, the victim is instructed to copy that URL and paste it into a phishing website, essentially handing over the authorization code to the adversary, who is now able to exchange it for an access token. Using the access token, the adversary gets access to the victim’s Microsoft account.
---------------------------------------------
https://blog.nviso.eu/2026/01/29/consentfix-a-k-a-authcodefix-detecting-oau…
∗∗∗ Dissecting UAT-8099: New persistence mechanisms and regional focus ∗∗∗
---------------------------------------------
Cisco Talos observed new activity from UAT-8099 spanning from August 2025 through early 2026. Analysis of Cisco's file census and DNS traffic indicates that compromised IIS servers are located across India, Pakistan, Thailand, Vietnam, and Japan, with a distinct concentration of attacks in Thailand and Vietnam. Furthermore, this activity significantly overlaps with the WEBJACK campaign; we have identified high-confidence correlations across malware hashes, C2 infrastructure, victimology, and the promoted gambling sites.
---------------------------------------------
https://blog.talosintelligence.com/uat-8099-new-persistence-mechanisms-and-…
∗∗∗ Malicious Google Ads Target Mac Users with Fake Mac Cleaner Pages ∗∗∗
---------------------------------------------
Researchers at MacKeeper have found malicious Google Ads for “Mac cleaner” tools that trick users into running dangerous Terminal commands. Stay safe by learning how to spot these fake Apple sites.
---------------------------------------------
https://hackread.com/malicious-google-ads-mac-fake-mac-cleaner/
∗∗∗ Unveiling the Weaponized Web Shell EncystPHP ∗∗∗
---------------------------------------------
FortiGuard Labs has discovered a web shell that we named “EncystPHP.” It features several advanced capabilities, including remote command execution, persistence mechanisms, and web shell deployment. Incidents were launched in early December last year and propagated via exploitation of the FreePBX vulnerability CVE-2025-64328.
---------------------------------------------
https://feeds.fortinet.com/~/943094408/0/fortinet/blogs~Unveiling-the-Weapo…
=====================
= Vulnerabilities =
=====================
∗∗∗ Nvidia Sicherheitslücken: Attacken auf GPU-Treiber können zu Abstürzen führen ∗∗∗
---------------------------------------------
Softwareschwachstellen gefährden PCs mit Grafikkarten von Nvidia. Sicherheitspatches sind verfügbar.
---------------------------------------------
https://www.heise.de/news/Nvidia-Sicherheitsluecken-Attacken-auf-GPU-Treibe…
∗∗∗ Security updates for Thursday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (java-25-openjdk, openssl, and python3.9), Debian (gimp, libmatio, pyasn1, and python-django), Fedora (perl-HarfBuzz-Shaper, python-tinycss2, and weasyprint), Mageia (glib2.0), Oracle (curl, fence-agents, gcc-toolset-15-binutils, glibc, grafana, java-1.8.0-openjdk, kernel, mariadb, osbuild-composer, perl, php:8.2, python-urllib3, python3.11, python3.11-urllib3, python3.12, and python3.12-urllib3), SUSE (alloy, avahi, bind, buildah, busybox, container-suseconnect, coredns, gdk-pixbuf, gimp, go1.24, go1.24-openssl, go1.25, helm, kernel, kubernetes, libheif, libpcap, libpng16, openjpeg2, openssl-1_0_0, openssl-1_1, openssl-3, php8, python-jaraco.context, python-marshmallow, python-pyasn1, python-urllib3, python-virtualenv, python311, python313, rabbitmq-server, xen, zli, and zot-registry), and Ubuntu (containerd, containerd-app and wlc).
---------------------------------------------
https://lwn.net/Articles/1056544/
∗∗∗ ZDI-26-049: Delta Electronics DIAView Exposed Dangerous Method Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-049/
∗∗∗ ZDI-26-048: Fortinet FortiSandbox fortisandbox Server-Side Request Forgery Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-048/
∗∗∗ ZDI-26-047: Hancom Office DOC File Parsing Type Confusion Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-047/
∗∗∗ ZDI-26-046: Cisco Snort _bnfa_search_csparse_nfa Use-After-Free Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-046/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 27-01-2026 18:00 − Mittwoch 28-01-2026 18:30
Handler: Felician Fuchs
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Fortinet blocks exploited FortiCloud SSO zero day until patch is ready ∗∗∗
---------------------------------------------
Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices running vulnerable firmware versions.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/fortinet-blocks-exploited-fo…
∗∗∗ Slovakian man pleads guilty to operating darknet marketplace ∗∗∗
---------------------------------------------
A Slovakian national admitted on Tuesday to helping operate a darknet marketplace that sold narcotics, cybercrime tools and services, fake government IDs, and stolen personal information for more than two years.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/slovakian-man-pleads-guilty-…
∗∗∗ Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation ∗∗∗
---------------------------------------------
A malicious campaign is actively targeting exposed LLM (Large Language Model) service endpoints to commercialize unauthorized access to AI infrastructure.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-hijack-exposed-llm-e…
∗∗∗ Vibe-Coded Sicarii Ransomware Cant Be Decrypted ∗∗∗
---------------------------------------------
A new ransomware strain that entered the scene last year has poorly designed code and an odd "Hebrew" identity that might be a false flag.
---------------------------------------------
https://www.darkreading.com/endpoint-security/vibe-coded-sicarii-ransomware…
∗∗∗ WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware ∗∗∗
---------------------------------------------
Meta on Tuesday announced its adding Strict Account Settings on WhatsApp to secure certain users against advanced cyber attacks because of who they are and what they do.
---------------------------------------------
https://thehackernews.com/2026/01/whatsapp-rolls-out-lockdown-style.html
∗∗∗ Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that masquerade as spellcheckers but contain functionality to deliver a remote access trojan (RAT).
---------------------------------------------
https://thehackernews.com/2026/01/fake-python-spellchecker-packages-on.html
∗∗∗ Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacks ∗∗∗
---------------------------------------------
Threat actors with ties to China have been observed using an updated version of a backdoor called COOLCLIENT in cyber espionage attacks in 2025 to facilitate comprehensive data theft from infected endpoints.
---------------------------------------------
https://thehackernews.com/2026/01/mustang-panda-deploys-updated.html
∗∗∗ Leder-Unikate von „maronellis.com“: Alles Schwindel! ∗∗∗
---------------------------------------------
Sobald Werbeanzeigen von einem kleinen Familienbetrieb berichten, der leider schließen muss, ist Vorsicht angebracht. Besonders dann, wenn eine angebliche Reportage Eindrücke vom großen Ansturm auf die letzten handgefertigten Einzelstücke liefert. Wie problematische Onlineshops funktionieren und wie die Kriminellen ihre Opfer anlocken – eine Analyse am Beispiel „maronellis.com“.
---------------------------------------------
https://www.watchlist-internet.at/news/leder-unikate-maronelliscom/
∗∗∗ Open Source statt Big Tech: Frankreich will Microsoft Teams, Zoom und Co loswerden ∗∗∗
---------------------------------------------
Visio entsteigt der Pilotphase und soll bis 2027 von 200.000 Beamten genutzt werden. Das Streben nach Souveränität, aber auch Kosteneinsparungen liefern die Motivation
---------------------------------------------
https://www.derstandard.at/story/3000000306024/open-source-statt-big-tech-f…
∗∗∗ EU fordert Öffnung von Android für andere KI – innerhalb von sechs Monaten ∗∗∗
---------------------------------------------
Die exklusive, tiefgehende Integration von Gemini in das Betriebssystem sei ein Verstoß gegen den Digital Markets Act. Zudem will die EU, dass Google Suchdaten an Konkurrenten herausgibt
---------------------------------------------
https://www.derstandard.at/story/3000000306105/eu-fordert-oeffnung-von-andr…
∗∗∗ Angriffswelle auf Journalisten über Signal-Messenger ∗∗∗
---------------------------------------------
Auch andere zivilgesellschaftliche Akteure betroffen. Bösartige Phishing-Nachricht fordert wegen "verdächtiger Aktivitäten" zur "Verifizierung" auf.
---------------------------------------------
https://www.derstandard.at/story/3000000306125/angriffswelle-auf-journalist…
∗∗∗ Beware! Fake ChatGPT browser extensions are stealing your login credentials ∗∗∗
---------------------------------------------
If youve installed a browser extension to enhance your ChatGPT experience, you might want to think again. Read more in my article on the Hot for Security blog.
---------------------------------------------
https://www.bitdefender.com/en-us/blog/hotforsecurity/beware-fake-chatgpt-b…
∗∗∗ Cyberattack on Poland’s power grid hit around 30 facilities, new report says ∗∗∗
---------------------------------------------
Adding to previous research about an operation against Polands electrical grid, analysts at Dragos say it affected dozens of facilities and disrupted operational technology.
---------------------------------------------
https://therecord.media/poland-electrical-grid-cyberattack-30-facilities-af…
∗∗∗ Exchange Online: Microsoft verschiebt SMTP AUTH Basic Authentication-Abschaltung ∗∗∗
---------------------------------------------
Eigentlich wollte Microsoft in Exchange Online die Unterstützung für die Basisauthentifizierung mit Client-Übermittlung (SMTP AUTH) bereits im September 2025 einstellen. Dann hieß es, dass die Einstellung zwischen 1. März 2026 bis zum 30. April 2026 schrittweise einstellen.
---------------------------------------------
https://borncity.com/blog/2026/01/28/exchange-online-microsoft-verschiebt-s…
∗∗∗ ShinyHunters Target 100+ Firms Using Phone Calls to Bypass SSO Security ∗∗∗
---------------------------------------------
ShinyHunters is driving attacks on 100+ organisations, using vishing and fake login pages with allied groups to bypass SSO and steal company data, reports Silent Push.
---------------------------------------------
https://hackread.com/shinyhunters-target-firms-bypass-sso-security/
∗∗∗ Russian Cybercrime Platform RAMP Forum Seized by Feds ∗∗∗
---------------------------------------------
US authorities have seized the RAMP cybercrime forum, taking down both its clearnet and dark web domains in a major hit to the ransomware infrastructure.
---------------------------------------------
https://hackread.com/russian-cybercrime-ramp-forum-seized-feds/
∗∗∗ OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows ∗∗∗
---------------------------------------------
A deep dive into OpenSSL’s January 2026 CMS and PKCS#12 vulnerabilities, including a pre-auth stack overflow and a PKCS#12 parsing bug.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/openssl-january-2026-security-u…
=====================
= Vulnerabilities =
=====================
∗∗∗ Administrative FortiCloud SSO authentication bypass ∗∗∗
---------------------------------------------
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS, FortiManager, FortiAnalyzer may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-060
∗∗∗ SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws ∗∗∗
---------------------------------------------
SolarWinds has released security updates to patch critical authentication bypass and remote command execution vulnerabilities in its Web Help Desk IT help desk software.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/solarwinds-warns-of-critical…
∗∗∗ Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution.
---------------------------------------------
https://thehackernews.com/2026/01/two-high-severity-n8n-flaws-allow.html
∗∗∗ Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution ∗∗∗
---------------------------------------------
A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating system. The vulnerability, tracked as CVE-2026-22709, carries a CVSS score of 9.8 out of 10.0 on the CVSS scoring system.
---------------------------------------------
https://thehackernews.com/2026/01/critical-vm2-nodejs-flaw-allows-sandbox.h…
∗∗∗ Netzwerkmanagementlösung HPE Aruba Fabric Composer ist angreifbar ∗∗∗
---------------------------------------------
Angreifer können Systeme mit HPE Aruba Networking Fabric Composer mit Schadcode attackieren.
---------------------------------------------
https://www.heise.de/news/Netzwerkmanagementloesung-HPE-Aruba-Fabric-Compos…
∗∗∗ A critical GnuPG security update ∗∗∗
---------------------------------------------
There is a new GnuPG update for a "critical security bug" in recentGnuPG releases. A crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack buffer overflow in gpg-agent during the PKDECRYPT--kem=CMS handling. This can easily be used for a DoS but, worse, the memory corruption can very likley also be used to mount a remote code execution attack. The bug was introduced while changing an internal API to the FIPS required KEM API.
---------------------------------------------
https://lwn.net/Articles/1056209/
∗∗∗ Security updates for Wednesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (java-1.8.0-openjdk), Debian (openssl), Fedora (assimp, chromium, curl, freerdp, gimp, and harfbuzz), Mageia (glibc, haproxy, iperf, and python-pyasn1), Red Hat (image-builder, openssl, and osbuild-composer), Slackware (mozilla), SUSE (avahi, cups, gio-branding-upstream, google-osconfig-agent, java-11-openjdk, java-17-openjdk, java-21-openjdk, kernel-firmware, libmatio-devel, libopenjp2-7, nodejs22, php8, python-python-multipart, python311-urllib3_1, qemu, and xen), and Ubuntu (ffmpeg, jaraco.context, openssl, and openssl, openssl1.0).
---------------------------------------------
https://lwn.net/Articles/1056330/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 140.7.1 ∗∗∗
---------------------------------------------
CSS-based exfiltration of the content from partially encrypted emails when allowing remote content.
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-08/
∗∗∗ [R1] Tenable Network Monitor Version 6.5.3 Fixes Multiple Vulnerabilities ∗∗∗
---------------------------------------------
Nessus Network Monitor leverages third-party software to help provide underlying functionality. Several of the third-party components (libxml2, libxslt, expat, c-ares, curl, sqlite) were found to contain vulnerabilities, and updated versions have been made available by the providers.
---------------------------------------------
https://www.tenable.com/security/tns-2026-02
∗∗∗ Notification about the vulnerability in beat-access for Windows – Privilege Escalation Risk ∗∗∗
---------------------------------------------
A vulnerability has been identified in beat‑access for Windows, a remote access software provided as part of the beat service, which may allow malicious code to be executed from the local environment. At the time of posting this notice, no attacks exploiting this vulnerability have been confirmed. However, we strongly recommend that customers using beat‑access for Windows promptly update to the latest version (4.0.0 or later).
---------------------------------------------
https://www.fujifilm.com/fbglobal/eng/company/news/notice/2026/0127_announc…
∗∗∗ CVE-2025-60021 (CVSS 9.8): Command injection in Apache bRPC heap profiler ∗∗∗
---------------------------------------------
CVE‑2025‑60021, a critical command injection issue in Apache bRPC’s /pprof/heap profiler endpoint, was identified during broader analysis of diagnostic and debugging surfaces in the framework.
---------------------------------------------
https://www.cyberark.com/resources/threat-research-blog/cve-2025-60021-cvss…
∗∗∗ Chrome: Stable Channel Update for Desktop ∗∗∗
---------------------------------------------
http://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desk…
∗∗∗ Johnson Controls Products ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-04
∗∗∗ Festo Didactic SE MES PC ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
∗∗∗ iba Systems ibaPDA ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-01
∗∗∗ Schneider Electric Zigbee Products ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-03
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 26-01-2026 18:00 − Dienstag 27-01-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Over 6,000 SmarterMail servers exposed to automated hijacking attacks ∗∗∗
---------------------------------------------
Nonprofit security organization Shadowserver has found over 6,000 SmarterMail servers exposed online and likely vulnerable to attacks exploiting a critical authentication bypass vulnerability.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-6-000-smartermail-serve…
∗∗∗ Nike investigates data breach after extortion gang leaks files ∗∗∗
---------------------------------------------
Nike is investigating what it described as a "potential cyber security incident" after the World Leaks ransomware gang leaked 1.4 TB of files allegedly stolen from the sportswear giant.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/nike-investigates-data-breac…
∗∗∗ Microsoft bringt Notfallpatch: Office-Nutzer werden über Zero-Day-Lücke attackiert ∗∗∗
---------------------------------------------
Eine gefährliche Sicherheitslücke betrifft alle gängigen Office-Versionen. Angesichts der aktiven Ausnutzung sollten Anwender zügig patchen.
---------------------------------------------
https://www.golem.de/news/microsoft-bringt-notfallpatch-office-nutzer-werde…
∗∗∗ Attacken beobachtet: Uralte Telnetd-Lücke gefährdet Hunderttausende Systeme ∗∗∗
---------------------------------------------
Seit über zehn Jahren können sich Angreifer via Telnet Root-Zugriff auf unzählige Geräte verschaffen. Neue Scans zeigen das Ausmaß.
---------------------------------------------
https://www.golem.de/news/attacken-beobachtet-uralte-telnetd-luecke-gefaehr…
∗∗∗ Bypassing Windows Administrator Protection ∗∗∗
---------------------------------------------
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary.This blog post will give a brief overview of the new feature, how it works and how it’s different from UAC. I’ll then describe some of the security research I undertook while it was in the ..
---------------------------------------------
https://projectzero.google/2026/26/windows-administrator-protection.html
∗∗∗ HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns ∗∗∗
---------------------------------------------
Kaspersky researchers analyze updated CoolClient backdoor and new tools and scripts used in HoneyMyte (aka Mustang Panda or Bronze President) APT campaigns, including three variants of a browser data stealer.
---------------------------------------------
https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-a…
∗∗∗ Canva among ~100 targets of ShinyHunters Okta identity-theft campaign ∗∗∗
---------------------------------------------
Atlassian, RingCentral, ZoomInfo also among tech targets ShinyHunters has targeted around 100 organizations in its latest Okta single sign-on (SSO) credential stealing campaign, according to researchers and the criminal group itself.
---------------------------------------------
https://www.theregister.com/2026/01/26/shinyhunters_okta_sso_campaign/
∗∗∗ Threat actors use FortiCloud SSO bypass to collect LDAP connection passwords ∗∗∗
---------------------------------------------
CERT.at gained access to a toolkit of an unknown threat actor targeting FortiCloud SSO bypass in Fortinet appliances (CVE-2025-59718/CVE-2025-59719). We are releasing under TLP:CLEAR key findings about likely post-exploitation goals of the attacker. The obtained exploit works only for the original vulnerability [1] and is not effective against patched ..
---------------------------------------------
https://www.cert.at/en/blog/2026/1/threat-actors-use-forticloud-to-collect-…
∗∗∗ Russian security systems firm Delta hit by cyberattack, services disrupted ∗∗∗
---------------------------------------------
Building and car alarm systems managed by Russian company Delta have been disrupted by a cyberattack blamed on a "hostile foreign state."
---------------------------------------------
https://therecord.media/russia-delta-security-alarm-company-cyberattack
∗∗∗ Clawdbot: Ein OpenSource KI-Assistent – cool und ein Sicherheitsdesaster ∗∗∗
---------------------------------------------
Bisher dominierten AI-Dienste wie ChatGPT, Gemini etc. den Bereich der LLMs – und Bots setzen auf diesen LLMs auf. Peter Steinberger hat mit seinem Team einen OpenSource Bot, Clawdbot, gebaut, der lokal läuft, Schnittstellen zu diversen Diensten und Modellen bietet ..
---------------------------------------------
https://borncity.com/blog/2026/01/26/clawdbot-ein-opensource-ki-assistent/
∗∗∗ Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 ∗∗∗
---------------------------------------------
The Google Threat Intelligence Group (GTIG) has identified widespread, active exploitation of the critical vulnerability CVE-2025-8088 in WinRAR, a popular file archiver tool for Windows, to establish initial access and deliver diverse payloads. Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated threat actors continue to exploit this n-day across disparate operations. The consistent exploitation method, a ..
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critica…
∗∗∗ Apache Hadoop: Fehler im HDFS-Native-Client lässt Schadcode passieren ∗∗∗
---------------------------------------------
Das Framework Apache Hadoop ist verwundbar. Attacken können im Kontext des HDFS-Dateisystems geschehen. Ein Sicherheitspatch ist verfügbar.
---------------------------------------------
https://heise.de/-11155241
=====================
= Vulnerabilities =
=====================
∗∗∗ DSA-6112-1 openjdk-21 - security update ∗∗∗
---------------------------------------------
https://lists.debian.org/debian-security-announce/2026/msg00021.html
∗∗∗ DSA-6111-1 imagemagick - security update ∗∗∗
---------------------------------------------
https://lists.debian.org/debian-security-announce/2026/msg00020.html
∗∗∗ Security Vulnerabilities fixed in Firefox 147.0.2 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-06/
∗∗∗ Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission ∗∗∗
---------------------------------------------
https://grahamhelton.com/blog/nodes-proxy-rce
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 23-01-2026 18:00 − Montag 26-01-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies ∗∗∗
---------------------------------------------
The defense mechanisms that NPM introduced after the Shai-Hulud supply-chain attacks have weaknesses that allow threat actors to bypass them via Git dependencies. [..] the vulnerabilities were discovered in multiple utilities in the JavaScript ecosystem that allow managing dependencies, like pnpm, vlt, Bun, and NPM. [..] They say that the problems were addressed in all tools except for NPM, who closed the report stating that the behavior "works as expected."
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-can-bypass-npms-shai…
∗∗∗ Nearly 800,000 Telnet servers exposed to remote attacks ∗∗∗
---------------------------------------------
Internet security watchdog Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils telnetd server.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-server…
∗∗∗ Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers ∗∗∗
---------------------------------------------
As recently as this month, Konni has been observed distributing spear-phishing emails containing malicious links that are disguised as harmless advertising URLs associated with Google and Naver's advertising platforms to bypass security filters and deliver a remote access trojan codenamed EndRAT. [..] The email messages have been found to masquerade as financial notices, such as transaction confirmations or wire transfer requests, to trick recipients into downloading ZIP archives hosted on WordPress sites. The ZIP file comes with a Windows shortcut (LNK) that's designed to execute an AutoIt script disguised as a PDF document.
---------------------------------------------
https://thehackernews.com/2026/01/konni-hackers-deploy-ai-generated.html
∗∗∗ Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants [..] The extensions, which have 1.5 million combined installs and are still available for download from the official Visual Studio Marketplace, are listed below - ChatGPT - 中文版 [..] ChatGPT - ChatMoss
---------------------------------------------
https://thehackernews.com/2026/01/malicious-vs-code-ai-extensions-with-15.h…
∗∗∗ BitLocker: Microsoft gibt Schlüssel an Strafverfolger heraus ∗∗∗
---------------------------------------------
Wer seine Festplatte oder SSD verschlüsselt, darf eigentlich davon ausgehen, dass nur er diese auch wieder entschlüsseln kann. Bei der Verschlüsselungstechnologie BitLocker von Microsoft scheint dies aber nicht unbedingt der Fall zu sein, weil das Unternehmen den Schlüssel in der Home-Edition von Windows automatisch im Online-Account des Nutzers abspeichert.
---------------------------------------------
https://www.heise.de/news/Microsoft-gibt-BitLocker-Schluessel-an-Strafverfo…
∗∗∗ Microsoft SharePoint/OneDrive: IDCRL-Authentication endet ab 31. Jan. 2026 – OpenID Connect und OAuth kommt (MC1184649) ∗∗∗
---------------------------------------------
Microsoft lässt bei den Online-Versionen das IDCRL-Authentication Protocol zum 31. Januar 2026 auslaufen. Die Authentifizierung erfolgt dann über OpenID Connect und OAuth – lässt sich aber noch einige Wochen wieder umstellen. Microsoft hat die Änderung bereits im November 2025 angekündigt, das Ganze aber als Erinnerung nochmals zum 20. Januar 2026 im Microsoft 365 Message Center unter MC1184649 – Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols eingestellt.
---------------------------------------------
https://borncity.com/blog/2026/01/25/microsoft-sharepoint-onedrive-idcrl-au…
∗∗∗ $6,000 “Stanley” Toolkit Sold on Russian Forums Fakes Secure URLs in Chrome ∗∗∗
---------------------------------------------
Varonis researchers discovered that Stanley uses a clever trick of disguising itself as a simple note-taking tool called Notely. Once a person installs it, the app can display a fake login page directly over a real website. [..] What is most concerning for the average user is that this toolkit isn’t just a piece of software but a full-featured service. The most expensive version comes with a guarantee that the malicious app will pass the official security checks of the Chrome Web Store.
---------------------------------------------
https://hackread.com/stanley-toolkit-russia-forum-fakes-chrome-urls/
∗∗∗ New Fake CAPTCHA Scam Abuses Microsoft Tools to Install Amatera Stealer ∗∗∗
---------------------------------------------
Blackpoint Cyber discovered a new Fake CAPTCHA campaign that tricks users into installing Amatera Stealer. By abusing legitimate Microsoft scripts and hiding malicious code in Google Calendar and PNG images, this attack bypasses standard security to harvest private passwords and browser data.
---------------------------------------------
https://hackread.com/fake-captcha-scam-microsoft-tools-amatera-stealer/
∗∗∗ F5: K000159681: Credential harvesting campaign targeting F5 VPN users ∗∗∗
---------------------------------------------
On January 13, 2026, researchers identified a large-scale credential harvesting campaign targeting several VPN providers, including F5. The threat actors behind the campaign registered numerous doppelgänger domains designed to mimic legitimate F5 domains. These domains are used to deceive victims into downloading counterfeit BIG-IP VPN client installers. [..] IOCs, C2 servers, and the malicious script hash value
---------------------------------------------
https://my.f5.com/manage/s/article/K000159681
∗∗∗ Screeps: How a game about programming exposed thousands of players to remote code execution ∗∗∗
---------------------------------------------
In Screeps (short for "Scripting Creeps"), you cannot click on a unit ("creep") and tell it what to do. If you place a building on the map, your builders will stand next to it and do nothing. There are no buttons to give your creeps instructions. Instead, you must write code to define their behavior. [..] In Multiplayer Screeps worlds, all of the code to progress the game runs on the server, including the AI for your units. [..] Screeps is on Steam, and the native client reuses the browser code but with no sandboxing. nw.require('child_process').exec('your command here') will get you full command line access to the target machine. [..] It is fixed now, which was the primary goal of my writing this.
---------------------------------------------
https://outsidetheasylum.blog/screeps/
∗∗∗ The end of the curl bug-bounty ∗∗∗
---------------------------------------------
There is no longer a curl bug-bounty program. It officially stops on January 31, 2026. [..] We saw an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop – presumably because they too were actually misled by AI but with that fact just hidden better. [..] The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk.
---------------------------------------------
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
=====================
= Vulnerabilities =
=====================
∗∗∗ Hands-Free Lockpicking: Critical Vulnerabilities in dormakaba’s Physical Access Control System ∗∗∗
---------------------------------------------
In this post, Clemens Stockenreitner and Werner Schober of the SEC Consult Vulnerability Lab highlight several critical vulnerabilities found in dormakaba’s physical access control systems based on exos 9300. This access control system originates from the manufacturer's enterprise product line for door and access systems and is predominantly used by large enterprises in Europe, including industrial and service companies, logistics operators, energy providers, and airport operators.
---------------------------------------------
https://sec-consult.com/blog/detail/hands-free-lockpicking-critical-vulnera…
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gimp, glib2, go-toolset:rhel8, golang, java-17-openjdk, java-21-openjdk, kernel, net-snmp, pcs, and thunderbird), Debian (apache2, imagemagick, incus, inetutils, libuev, openjdk-17, php7.4, python3.9, shapelib, taglib, and zvbi), Fedora (mingw-glib2, mingw-harfbuzz, mingw-libsoup, mingw-openexr, pgadmin4, python3.11, python3.12, python3.9, and wireshark), Gentoo (Asterisk, Commons-BeanUtils, GIMP, inetutils, and Vim, gVim), Mageia (kernel), Oracle (glib2, java-17-openjdk, java-21-openjdk, and libpng), Red Hat (java-17-openjdk, java-21-openjdk, kernel, and kernel-rt), SUSE (azure-cli-core, bind, buildah, chromium, coredns, glib2, harfbuzz, kernel, kernel-firmware, libheif, libvirt, openCryptoki, openvswitch, podman, python, python-urllib3, rabbitmq-server, and vlang), and Ubuntu (cjson).
---------------------------------------------
https://lwn.net/Articles/1055958/
∗∗∗ Beckhoff Security Advisory 2025-003: Vulnerabilities in Beckhoff Device Manager ∗∗∗
---------------------------------------------
https://download.beckhoff.com/download/document/product-security/Advisories…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/