=====================
= End-of-Day report =
=====================
Timeframe: Montag 26-01-2026 18:00 − Dienstag 27-01-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Over 6,000 SmarterMail servers exposed to automated hijacking attacks ∗∗∗
---------------------------------------------
Nonprofit security organization Shadowserver has found over 6,000 SmarterMail servers exposed online and likely vulnerable to attacks exploiting a critical authentication bypass vulnerability.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-6-000-smartermail-serve…
∗∗∗ Nike investigates data breach after extortion gang leaks files ∗∗∗
---------------------------------------------
Nike is investigating what it described as a "potential cyber security incident" after the World Leaks ransomware gang leaked 1.4 TB of files allegedly stolen from the sportswear giant.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/nike-investigates-data-breac…
∗∗∗ Microsoft bringt Notfallpatch: Office-Nutzer werden über Zero-Day-Lücke attackiert ∗∗∗
---------------------------------------------
Eine gefährliche Sicherheitslücke betrifft alle gängigen Office-Versionen. Angesichts der aktiven Ausnutzung sollten Anwender zügig patchen.
---------------------------------------------
https://www.golem.de/news/microsoft-bringt-notfallpatch-office-nutzer-werde…
∗∗∗ Attacken beobachtet: Uralte Telnetd-Lücke gefährdet Hunderttausende Systeme ∗∗∗
---------------------------------------------
Seit über zehn Jahren können sich Angreifer via Telnet Root-Zugriff auf unzählige Geräte verschaffen. Neue Scans zeigen das Ausmaß.
---------------------------------------------
https://www.golem.de/news/attacken-beobachtet-uralte-telnetd-luecke-gefaehr…
∗∗∗ Bypassing Windows Administrator Protection ∗∗∗
---------------------------------------------
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary.This blog post will give a brief overview of the new feature, how it works and how it’s different from UAC. I’ll then describe some of the security research I undertook while it was in the ..
---------------------------------------------
https://projectzero.google/2026/26/windows-administrator-protection.html
∗∗∗ HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns ∗∗∗
---------------------------------------------
Kaspersky researchers analyze updated CoolClient backdoor and new tools and scripts used in HoneyMyte (aka Mustang Panda or Bronze President) APT campaigns, including three variants of a browser data stealer.
---------------------------------------------
https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-a…
∗∗∗ Canva among ~100 targets of ShinyHunters Okta identity-theft campaign ∗∗∗
---------------------------------------------
Atlassian, RingCentral, ZoomInfo also among tech targets ShinyHunters has targeted around 100 organizations in its latest Okta single sign-on (SSO) credential stealing campaign, according to researchers and the criminal group itself.
---------------------------------------------
https://www.theregister.com/2026/01/26/shinyhunters_okta_sso_campaign/
∗∗∗ Threat actors use FortiCloud SSO bypass to collect LDAP connection passwords ∗∗∗
---------------------------------------------
CERT.at gained access to a toolkit of an unknown threat actor targeting FortiCloud SSO bypass in Fortinet appliances (CVE-2025-59718/CVE-2025-59719). We are releasing under TLP:CLEAR key findings about likely post-exploitation goals of the attacker. The obtained exploit works only for the original vulnerability [1] and is not effective against patched ..
---------------------------------------------
https://www.cert.at/en/blog/2026/1/threat-actors-use-forticloud-to-collect-…
∗∗∗ Russian security systems firm Delta hit by cyberattack, services disrupted ∗∗∗
---------------------------------------------
Building and car alarm systems managed by Russian company Delta have been disrupted by a cyberattack blamed on a "hostile foreign state."
---------------------------------------------
https://therecord.media/russia-delta-security-alarm-company-cyberattack
∗∗∗ Clawdbot: Ein OpenSource KI-Assistent – cool und ein Sicherheitsdesaster ∗∗∗
---------------------------------------------
Bisher dominierten AI-Dienste wie ChatGPT, Gemini etc. den Bereich der LLMs – und Bots setzen auf diesen LLMs auf. Peter Steinberger hat mit seinem Team einen OpenSource Bot, Clawdbot, gebaut, der lokal läuft, Schnittstellen zu diversen Diensten und Modellen bietet ..
---------------------------------------------
https://borncity.com/blog/2026/01/26/clawdbot-ein-opensource-ki-assistent/
∗∗∗ Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 ∗∗∗
---------------------------------------------
The Google Threat Intelligence Group (GTIG) has identified widespread, active exploitation of the critical vulnerability CVE-2025-8088 in WinRAR, a popular file archiver tool for Windows, to establish initial access and deliver diverse payloads. Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated threat actors continue to exploit this n-day across disparate operations. The consistent exploitation method, a ..
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critica…
∗∗∗ Apache Hadoop: Fehler im HDFS-Native-Client lässt Schadcode passieren ∗∗∗
---------------------------------------------
Das Framework Apache Hadoop ist verwundbar. Attacken können im Kontext des HDFS-Dateisystems geschehen. Ein Sicherheitspatch ist verfügbar.
---------------------------------------------
https://heise.de/-11155241
=====================
= Vulnerabilities =
=====================
∗∗∗ DSA-6112-1 openjdk-21 - security update ∗∗∗
---------------------------------------------
https://lists.debian.org/debian-security-announce/2026/msg00021.html
∗∗∗ DSA-6111-1 imagemagick - security update ∗∗∗
---------------------------------------------
https://lists.debian.org/debian-security-announce/2026/msg00020.html
∗∗∗ Security Vulnerabilities fixed in Firefox 147.0.2 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-06/
∗∗∗ Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission ∗∗∗
---------------------------------------------
https://grahamhelton.com/blog/nodes-proxy-rce
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 23-01-2026 18:00 − Montag 26-01-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies ∗∗∗
---------------------------------------------
The defense mechanisms that NPM introduced after the Shai-Hulud supply-chain attacks have weaknesses that allow threat actors to bypass them via Git dependencies. [..] the vulnerabilities were discovered in multiple utilities in the JavaScript ecosystem that allow managing dependencies, like pnpm, vlt, Bun, and NPM. [..] They say that the problems were addressed in all tools except for NPM, who closed the report stating that the behavior "works as expected."
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-can-bypass-npms-shai…
∗∗∗ Nearly 800,000 Telnet servers exposed to remote attacks ∗∗∗
---------------------------------------------
Internet security watchdog Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils telnetd server.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-server…
∗∗∗ Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers ∗∗∗
---------------------------------------------
As recently as this month, Konni has been observed distributing spear-phishing emails containing malicious links that are disguised as harmless advertising URLs associated with Google and Naver's advertising platforms to bypass security filters and deliver a remote access trojan codenamed EndRAT. [..] The email messages have been found to masquerade as financial notices, such as transaction confirmations or wire transfer requests, to trick recipients into downloading ZIP archives hosted on WordPress sites. The ZIP file comes with a Windows shortcut (LNK) that's designed to execute an AutoIt script disguised as a PDF document.
---------------------------------------------
https://thehackernews.com/2026/01/konni-hackers-deploy-ai-generated.html
∗∗∗ Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants [..] The extensions, which have 1.5 million combined installs and are still available for download from the official Visual Studio Marketplace, are listed below - ChatGPT - 中文版 [..] ChatGPT - ChatMoss
---------------------------------------------
https://thehackernews.com/2026/01/malicious-vs-code-ai-extensions-with-15.h…
∗∗∗ BitLocker: Microsoft gibt Schlüssel an Strafverfolger heraus ∗∗∗
---------------------------------------------
Wer seine Festplatte oder SSD verschlüsselt, darf eigentlich davon ausgehen, dass nur er diese auch wieder entschlüsseln kann. Bei der Verschlüsselungstechnologie BitLocker von Microsoft scheint dies aber nicht unbedingt der Fall zu sein, weil das Unternehmen den Schlüssel in der Home-Edition von Windows automatisch im Online-Account des Nutzers abspeichert.
---------------------------------------------
https://www.heise.de/news/Microsoft-gibt-BitLocker-Schluessel-an-Strafverfo…
∗∗∗ Microsoft SharePoint/OneDrive: IDCRL-Authentication endet ab 31. Jan. 2026 – OpenID Connect und OAuth kommt (MC1184649) ∗∗∗
---------------------------------------------
Microsoft lässt bei den Online-Versionen das IDCRL-Authentication Protocol zum 31. Januar 2026 auslaufen. Die Authentifizierung erfolgt dann über OpenID Connect und OAuth – lässt sich aber noch einige Wochen wieder umstellen. Microsoft hat die Änderung bereits im November 2025 angekündigt, das Ganze aber als Erinnerung nochmals zum 20. Januar 2026 im Microsoft 365 Message Center unter MC1184649 – Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols eingestellt.
---------------------------------------------
https://borncity.com/blog/2026/01/25/microsoft-sharepoint-onedrive-idcrl-au…
∗∗∗ $6,000 “Stanley” Toolkit Sold on Russian Forums Fakes Secure URLs in Chrome ∗∗∗
---------------------------------------------
Varonis researchers discovered that Stanley uses a clever trick of disguising itself as a simple note-taking tool called Notely. Once a person installs it, the app can display a fake login page directly over a real website. [..] What is most concerning for the average user is that this toolkit isn’t just a piece of software but a full-featured service. The most expensive version comes with a guarantee that the malicious app will pass the official security checks of the Chrome Web Store.
---------------------------------------------
https://hackread.com/stanley-toolkit-russia-forum-fakes-chrome-urls/
∗∗∗ New Fake CAPTCHA Scam Abuses Microsoft Tools to Install Amatera Stealer ∗∗∗
---------------------------------------------
Blackpoint Cyber discovered a new Fake CAPTCHA campaign that tricks users into installing Amatera Stealer. By abusing legitimate Microsoft scripts and hiding malicious code in Google Calendar and PNG images, this attack bypasses standard security to harvest private passwords and browser data.
---------------------------------------------
https://hackread.com/fake-captcha-scam-microsoft-tools-amatera-stealer/
∗∗∗ F5: K000159681: Credential harvesting campaign targeting F5 VPN users ∗∗∗
---------------------------------------------
On January 13, 2026, researchers identified a large-scale credential harvesting campaign targeting several VPN providers, including F5. The threat actors behind the campaign registered numerous doppelgänger domains designed to mimic legitimate F5 domains. These domains are used to deceive victims into downloading counterfeit BIG-IP VPN client installers. [..] IOCs, C2 servers, and the malicious script hash value
---------------------------------------------
https://my.f5.com/manage/s/article/K000159681
∗∗∗ Screeps: How a game about programming exposed thousands of players to remote code execution ∗∗∗
---------------------------------------------
In Screeps (short for "Scripting Creeps"), you cannot click on a unit ("creep") and tell it what to do. If you place a building on the map, your builders will stand next to it and do nothing. There are no buttons to give your creeps instructions. Instead, you must write code to define their behavior. [..] In Multiplayer Screeps worlds, all of the code to progress the game runs on the server, including the AI for your units. [..] Screeps is on Steam, and the native client reuses the browser code but with no sandboxing. nw.require('child_process').exec('your command here') will get you full command line access to the target machine. [..] It is fixed now, which was the primary goal of my writing this.
---------------------------------------------
https://outsidetheasylum.blog/screeps/
∗∗∗ The end of the curl bug-bounty ∗∗∗
---------------------------------------------
There is no longer a curl bug-bounty program. It officially stops on January 31, 2026. [..] We saw an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop – presumably because they too were actually misled by AI but with that fact just hidden better. [..] The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk.
---------------------------------------------
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
=====================
= Vulnerabilities =
=====================
∗∗∗ Hands-Free Lockpicking: Critical Vulnerabilities in dormakaba’s Physical Access Control System ∗∗∗
---------------------------------------------
In this post, Clemens Stockenreitner and Werner Schober of the SEC Consult Vulnerability Lab highlight several critical vulnerabilities found in dormakaba’s physical access control systems based on exos 9300. This access control system originates from the manufacturer's enterprise product line for door and access systems and is predominantly used by large enterprises in Europe, including industrial and service companies, logistics operators, energy providers, and airport operators.
---------------------------------------------
https://sec-consult.com/blog/detail/hands-free-lockpicking-critical-vulnera…
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gimp, glib2, go-toolset:rhel8, golang, java-17-openjdk, java-21-openjdk, kernel, net-snmp, pcs, and thunderbird), Debian (apache2, imagemagick, incus, inetutils, libuev, openjdk-17, php7.4, python3.9, shapelib, taglib, and zvbi), Fedora (mingw-glib2, mingw-harfbuzz, mingw-libsoup, mingw-openexr, pgadmin4, python3.11, python3.12, python3.9, and wireshark), Gentoo (Asterisk, Commons-BeanUtils, GIMP, inetutils, and Vim, gVim), Mageia (kernel), Oracle (glib2, java-17-openjdk, java-21-openjdk, and libpng), Red Hat (java-17-openjdk, java-21-openjdk, kernel, and kernel-rt), SUSE (azure-cli-core, bind, buildah, chromium, coredns, glib2, harfbuzz, kernel, kernel-firmware, libheif, libvirt, openCryptoki, openvswitch, podman, python, python-urllib3, rabbitmq-server, and vlang), and Ubuntu (cjson).
---------------------------------------------
https://lwn.net/Articles/1055958/
∗∗∗ Beckhoff Security Advisory 2025-003: Vulnerabilities in Beckhoff Device Manager ∗∗∗
---------------------------------------------
https://download.beckhoff.com/download/document/product-security/Advisories…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 22-01-2026 18:00 − Freitag 23-01-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Analysis of Single Sign On (SSO) abuse on FortiOS ∗∗∗
---------------------------------------------
Fortinet product security has identified the issue, and the company is working on a fix to remediate this occurrence. An advisory will be issued as the fix scope and timeline is available. It is important to note that while, at this time, only exploitation of FortiCloud SSO has been observed, this issue is applicable to all SAML SSO implementations. In the meantime, Fortinet recommends taking the mitigating actions described below.
---------------------------------------------
https://feeds.fortinet.com/~/941387753/0/fortinet/blogs~Analysis-of-Single-…
∗∗∗ Okta SSO accounts targeted in vishing-based data theft attacks ∗∗∗
---------------------------------------------
Okta is warning about custom phishing kits built specifically for voice-based social engineering (vishing) attacks. BleepingComputer has learned that these kits are being used in active attacks to steal Okta SSO credentials for data theft.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-i…
∗∗∗ Datenlecks analysiert: Solche Passwörter sollten Nutzer besser meiden ∗∗∗
---------------------------------------------
Forscher haben rund sechs Milliarden Passwörter aus mehreren Datenlecks untersucht. Ihr Bericht zeigt Muster auf, die besonders häufig vorkommen.
---------------------------------------------
https://www.golem.de/news/datenlecks-analysiert-solche-passwoerter-sollten-…
∗∗∗ Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a new dual-vector campaign that leverages stolen credentials to deploy legitimate Remote Monitoring and Management (RMM) software for persistent remote access to compromised hosts. [..] The attack unfolds in two distinct waves, where the threat actors leverage fake invitation notifications to steal victim credentials, and then leverage those pilfered credentials to deploy RMM tools to establish persistent access.
---------------------------------------------
https://thehackernews.com/2026/01/phishing-attack-uses-stolen-credentials.h…
∗∗∗ Crims compromised energy firms Microsoft accounts, sent 600 phishing emails ∗∗∗
---------------------------------------------
Unknown attackers are abusing Microsoft SharePoint file-sharing services to target multiple energy-sector organizations, harvest user credentials, take over corporate inboxes, and then send hundreds of phishing emails from compromised accounts to contacts inside and outside those organizations. The attackers likely used previously-compromised email addresses to gain initial access to "multiple" energy-sector organizations targeted in this campaign, according to Redmond, which detailed the digital intrusions in a Wednesday report.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/01/22/crims_compro…
∗∗∗ 149 Million Usernames and Passwords Exposed by Unsecured Database ∗∗∗
---------------------------------------------
This “dream wish list for criminals” includes millions of Gmail, Facebook, banking logins, and more. The researcher who discovered it suspects they were collected using infostealing malware.
---------------------------------------------
https://www.wired.com/story/149-million-stolen-usernames-passwords/
∗∗∗ URL fritz.box leitet seit 22.1.2026 auf 91.195.240.12 um ∗∗∗
---------------------------------------------
Die von der früheren AVM, heute FRITZ, erworbene Domain fritz.box ist wohl wieder auf "Abwegen". [..] Die Whois-Daten zeigen, dass heute (22.1.2026) die Domain-Registrierung abgelaufen ist.
---------------------------------------------
https://borncity.com/blog/2026/01/22/url-fritz-box-leitet-seit-22-1-2026-au…
∗∗∗ KI und Security: Zero-Day-Exploits durch KI sind bereits Realität ∗∗∗
---------------------------------------------
Eine Studie zeigt: KIs können komplexe Zero-Day-Exploits erstellen. Die Folge: Die Suche nach Sicherheitslücken wird erfolgreich industrialisiert und skaliert.
---------------------------------------------
https://heise.de/-11151838
∗∗∗ Exploit Cursor Agents to create persistent, distributed threats ∗∗∗
---------------------------------------------
Yesterday a VSCode exploit was written up. When a programmer simply opens a folder that contains a malicious tasks.json file, the malicious code will silently run from inside the editor itself – where all their work lives. That got me thinking: could I use this to re-program a developer's AI agents and get them to do what I want? Even worse — could I do this to all their code repositories? Turns out: hell yes.
---------------------------------------------
https://ike.io/open-a-folder-all-your-agents-are-mine/
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Friday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (kernel), Debian (bind9, chromium, osslsigncode, and python-urllib3), Fedora (freerdp, ghostscript, hcloud, rclone, rust-rkyv0.7, rust-rkyv_derive0.7, and vsftpd), Mageia (avahi and harfbuzz), SUSE (alloy, avahi, busybox, cargo-c, corepack22, corepack24, curl, docker, dpdk, exiv2-0_26, ffmpeg-4, firefox, glib2, go1.24, go1.25, gpg2, haproxy, kernel, kernel-firmware, keylime, libpng16, librsvg, libsodium, libsoup, libsoup2, libtasn1, log4j, net-snmp, open-vm-tools, openldap2_5, ovmf, pgadmin4, php7, podman, python-filelock, python-marshmallow, python-pyasn1, python-tornado, python-urllib3, python-virtualenv, python3, python311-pyasn1, python311-weasyprint, rust1.91, rust1.92, util-linux, webkit2gtk3, and wireshark), and Ubuntu (libxml2 and pyasn1).
---------------------------------------------
https://lwn.net/Articles/1055671/
∗∗∗ Videokonferenzsoftware: Zoom Node möglicher Ansatzpunkt für Schadcode-Attacken ∗∗∗
---------------------------------------------
In einer Warnmeldung führen die Entwickler aus, dass die nun geschlossene Sicherheitslücke (CVE-2026-22844) mit dem Bedrohungsgrad „kritisch“ eingestuft ist. Die Schwachstelle betrifft konkret die Komponente Multimedia Routers (MMRs). Damit eine Attacke gelingt, muss ein Angreifer Teilnehmer eines Meetings sein. Ist das gegeben, kann er auf einem nicht näher beschriebenen Weg Schadcode ausführen.
---------------------------------------------
https://heise.de/-11151434
∗∗∗ Rockwell Automation CompactLogix 5370 ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-03
∗∗∗ Schneider Electric EcoStruxure Process Expert ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-01
∗∗∗ EVMAPA ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-08
∗∗∗ Weintek cMT X Series HMI EasyWeb Service ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-05
∗∗∗ Delta Electronics DIAView ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-07
∗∗∗ Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-04
∗∗∗ AutomationDirect CLICK Programmable Logic Controller ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-02
∗∗∗ Hubitat Elevation Hubs ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-06
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 21-01-2026 18:00 − Donnerstag 22-01-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ A patch for the NIS2 Directive ∗∗∗
---------------------------------------------
On January 20th, 2026 the EU Commission presented a package of legislative proposals, including an update to the NIS2 directive.
---------------------------------------------
https://www.cert.at/en/blog/2026/1/a-patch-for-the-nis2-directive
∗∗∗ Look at FortiCloud SSO Bypass Exploitation (CVE-2025-59718/59719) ∗∗∗
---------------------------------------------
In December last year, Fortinet disclosed [1] a vulnerability in SAML processing, which allowed full bypass of authentication to management interfaces with FortiCloud SSO enabled. According to new, still not officially confirmed reports, the vulnerability may not have been fully patched [10]. As affected devices are represented in my small high-interactive honeypots network, we have an opportunity to take a look at what the attackers do.
---------------------------------------------
https://www.cert.at/en/blog/2026/1/look-at-forticloud-sso-bypass-exploitati…
∗∗∗ New Android malware uses AI to click on hidden browser ads ∗∗∗
---------------------------------------------
A new family of Android click-fraud trojans leverages TensorFlow machine learning models to automatically detect and interact with specific advertisement elements.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-android-malware-uses-ai-…
∗∗∗ Chainlit AI framework bugs let hackers breach cloud environments ∗∗∗
---------------------------------------------
Two high-severity vulnerabilities in Chainlit, a popular open-source framework for building conversational AI applications, allow reading any file on the server and leaking sensitive information.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/chainlit-ai-framework-bugs-l…
∗∗∗ Is AI-Generated Code Secure?, (Thu, Jan 22nd) ∗∗∗
---------------------------------------------
The title of this diary is perhaps a bit catchy but the question is important. I don’t consider myself as a good developer. That’s not my day job and I’m writing code to improve my daily tasks. I like to say “I’m writing sh*ty code! It works for me, no warranty that it will for for you”. Today, most of my code (the skeleton of the program) is generated by AI, probably like most of you.
---------------------------------------------
https://isc.sans.edu/diary/rss/32648
∗∗∗ Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts ∗∗∗
---------------------------------------------
A new malicious package discovered in the Python Package Index (PyPI) has been found to impersonate a popular library for symbolic mathematics to deploy malicious payloads, including a cryptocurrency miner, on Linux hosts.
---------------------------------------------
https://thehackernews.com/2026/01/malicious-pypi-package-impersonates.html
∗∗∗ Preparing for the EU Cyber Resilience Act (CRA) ∗∗∗
---------------------------------------------
Product security has matured significantly over the last decade. Secure defaults, defined ownership of security risk, reliable update mechanisms, and structured vulnerability handling are now mainstream and well understood by experienced engineering and security teams. These practices are no longer aspirational. They are now the minimum required to build and operate digital products responsibly.
---------------------------------------------
https://www.pentestpartners.com/security-blog/preparing-for-the-eu-cyber-re…
∗∗∗ Phishing-Falle: Verlust des Zugriffs auf ChatGPT ∗∗∗
---------------------------------------------
Eine aktuell kursierende Phishing-Mail warnt vor einer Kündigung des ChatGPT-Kontos. Schuld sei eine ausgebliebene Zahlung. Das Problem ließe sich aber mit einer Aktualisierung der notwendigen Daten aus der Welt schaffen. Wer dem entsprechenden Pfad folgt, übermittelt den Kriminellen allerdings Kreditkarten- und Kontaktinformationen.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-falle-chatgpt/
∗∗∗ European Space Agency’s cybersecurity in freefall as yet another breach exposes spacecraft and mission data ∗∗∗
---------------------------------------------
It has just been a few weeks since reports emerged of the Christmas cyber attack suffered by the European Space Agency (ESA), and the situation has already become worse.
---------------------------------------------
https://www.bitdefender.com/en-us/blog/hotforsecurity/european-space-agency…
∗∗∗ The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time ∗∗∗
---------------------------------------------
Imagine visiting a webpage that looks perfectly safe. It has no malicious code, no suspicious links. Yet, within seconds, it transforms into a personalized phishing page.
---------------------------------------------
https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-…
∗∗∗ Osiris: New Ransomware, Experienced Attackers? ∗∗∗
---------------------------------------------
Poortry driver and modified Rustdesk tool used in recent attack campaign, which bears similarities to previous Inc ransomware attacks.
---------------------------------------------
https://www.security.com/threat-intelligence/new-ransomware-osiris
∗∗∗ Watering Hole Attack Targets EmEditor Users with Information-Stealing Malware ∗∗∗
---------------------------------------------
TrendAI™ Research provides a technical analysis of a compromised EmEditor installer used to deliver multistage malware that performs a range of malicious actions.
---------------------------------------------
https://www.trendmicro.com/en_us/research/26/a/watering-hole-attack-targets…
∗∗∗ Cyber Is What We Make of It ∗∗∗
---------------------------------------------
Cyber Is What We Make of It "Its not what happens to you, but how you react to it that matters." — EpictetusNot long ago an Atlantic Council op-ed in CyberScoop outlined ten key reforms to close Americas cybersecurity gaps. The recommendations are sensible: migrate to memory-safe languages, apply formal verification to critical systems, establish zero trust architectures, build data resilience, conduct proactive threat hunting. Laudable, uncontroversial, and comprehensive;
---------------------------------------------
https://buttondown.com/grugq/archive/cyber-is-what-we-make-of-it/
=====================
= Vulnerabilities =
=====================
∗∗∗ SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release ∗∗∗
---------------------------------------------
A new security flaw in SmarterTools SmarterMail email software has come under active exploitation in the wild, two days after the release of a patch.
---------------------------------------------
https://thehackernews.com/2026/01/smartermail-auth-bypass-exploited-in.html
∗∗∗ Security updates for Thursday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gpsd), Debian (inetutils and modsecurity-crs), Fedora (cpp-httplib, curl, mariadb11.8, mingw-libtasn1, mingw-libxslt, mingw-python3, rclone, and rpki-client), Oracle (gimp, glib2, go-toolset:rhel8, golang, kernel, mariadb-devel:10.3, and thunderbird), Red Hat (buildah, go-toolset:rhel8, golang, grafana, kernel, kernel-rt, multiple packages, openssl, osbuild-composer, podman, and skopeo), Slackware (bind), SUSE (ffmpeg-4, libsodium, libvirt, net-snmp, open-vm-tools, ovmf, postgresql17, postgresql18, python-FontTools, python-weasyprint, and webkit2gtk3), and Ubuntu (glib2.0 and opencc).
---------------------------------------------
https://lwn.net/Articles/1055484/
∗∗∗ Jetzt handeln! Angreifer umgehen offenbar Fortinet-Sicherheitspatch ∗∗∗
---------------------------------------------
Medienberichten zufolge ist ein Sicherheitspatch für diverse Fortinet-Produkte defekt. Admins können Instanzen aber trotzdem schützen.
---------------------------------------------
https://heise.de/-11149777
∗∗∗ Updaten! Angriffsversuche auf Sicherheitslücken in Cisco Unified Communications ∗∗∗
---------------------------------------------
In mehreren Unified-Communications-Produkten von Cisco klafft eine Sicherheitslücke, die Angreifern ohne Anmeldung das Einschleusen von Schadcode aus dem Netz und dessen Ausführung mit Root-Rechten ermöglicht. Admins sollten die bereitstehenden Aktualisierungen zügig anwenden, da Cisco bereits Angriffsversuche aus dem Netz auf die Schwachstelle beobachtet hat.
---------------------------------------------
https://heise.de/-11149877
∗∗∗ Dell Data Protection Advisor über unzählige Sicherheitslücken angreifbar ∗∗∗
---------------------------------------------
Dell schließt teilweise sechzehn Jahre alte Schwachstellen in Data Protection Advisor, über die Angreifer Systeme kompromittieren können.
---------------------------------------------
https://heise.de/-11150421
∗∗∗ SSA-864900 V1.6 (Last Update: 2026-01-22): Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices ∗∗∗
---------------------------------------------
https://cert-portal.siemens.com/productcert/html/ssa-864900.html
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 20-01-2026 18:00 − Mittwoch 21-01-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ EU plans cybersecurity overhaul to block foreign high-risk suppliers ∗∗∗
---------------------------------------------
The European Commission has proposed new cybersecurity legislation mandating the removal of high-risk suppliers to secure telecommunications networks and strengthening defenses against state-backed and cybercrime groups targeting critical infrastructure.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/eu-plans-cybersecurity-overh…
∗∗∗ VoidLink cloud malware shows clear signs of being AI-generated ∗∗∗
---------------------------------------------
The recently discovered cloud-focused VoidLink malware framework is believed to have been developed by a single person with the help of an artificial intelligence model.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/voidlink-cloud-malware-shows…
∗∗∗ Hackers exploit security testing apps to breach Fortune 500 firms ∗∗∗
---------------------------------------------
Threat actors are exploiting misconfigured web applications used for security training and internal penetration testing, such as DVWA, OWASP Juice Shop, Hackazon, and bWAPP, to gain access to cloud environments of Fortune 500 companies and security vendors.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-exploit-security-tes…
∗∗∗ Mass Spam Attacks Leverage Zendesk Instances ∗∗∗
---------------------------------------------
The CRM vendor advised ignoring or deleting suspicious emails and said the attacks were not tied to any breach or software vulnerability.
---------------------------------------------
https://www.darkreading.com/threat-intelligence/mass-spam-attacks-zendesk-i…
∗∗∗ Jetzt abschalten: Zehn Jahre alte Telnetd-Lücke macht jeden Client zum Root ∗∗∗
---------------------------------------------
Seit 2015 kann sich über Telnetd jeder Client einen Root-Zugriff verschaffen. Einen Patch gibt es zwar, empfohlen wird jedoch die Abschaltung.
---------------------------------------------
https://www.golem.de/news/jetzt-abschalten-zehn-jahre-alte-telnetd-luecke-m…
∗∗∗ LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords ∗∗∗
---------------------------------------------
LastPass is alerting users to a new active phishing campaign that's impersonating the password management service, which aims to trick users into giving up their master passwords.
---------------------------------------------
https://thehackernews.com/2026/01/lastpass-warns-of-fake-maintenance.html
∗∗∗ Curl shutters bug bounty program to remove incentive for submitting AI slop ∗∗∗
---------------------------------------------
The maintainer of popular open-source data transfer tool cURL has ended the project’s bug bounty program after maintainers struggled to assess a flood of AI-generated contributions.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/01/21/curl_ends_bu…
∗∗∗ Einschränkung der Anzeigenauslieferung auf Facebook? Unternehmens-Profile im Visier von Kriminellen ∗∗∗
---------------------------------------------
Mit vermeintlich vom Meta-Konzern stammenden E-Mails versuchen Betrüger:innen, sich Zugang zu Unternehmens-Accounts zu erschleichen. Dafür haben sie eine gefälschte Login-Seite gebaut. Wie läuft die Masche konkret ab? Woran ist die Betrugsabsicht zu erkennen? Dieser Artikel liefert Antworten.
---------------------------------------------
https://www.watchlist-internet.at/news/einschraenkung-der-anzeigenausliefer…
∗∗∗ DNS OverDoS: Are Private Endpoints Too Private? ∗∗∗
---------------------------------------------
We discovered an aspect of Azure’s Private Endpoint architecture that could expose Azure resources to denial of service (DoS) attacks. In this article, we explore how both intentional and inadvertent acts could result in limited access to Azure resources through the Azure Private Link mechanism. We uncovered this issue while investigating irregular behavior in Azure test environments.
---------------------------------------------
https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/
∗∗∗ IT-Sicherheit: Roter Draht zwischen Peking und London ∗∗∗
---------------------------------------------
Ein neues, geheimes Forum soll die Kommunikation zwischen britischen und chinesischen Diensten verbessern. Es könnte das erste seiner Art sein.
---------------------------------------------
https://heise.de/-11148209
∗∗∗ Introducing > PowerShell.Exposed ∗∗∗
---------------------------------------------
PowerShell (PS) isn’t just a “Windows admin tool.” Once shell access is established, this is the cheapest and most powerful hands-on-keyboard control an attacker can have.
---------------------------------------------
https://detect.fyi/introducing-powershell-exposed-4974fe712117?source=rss--…
∗∗∗ New EU Vulnerability Platform GCVE Goes Live, Reducing Reliance on Global Systems ∗∗∗
---------------------------------------------
Europe’s long-running conversation about digital autonomy quietly crossed a milestone with the launch of a new public vulnerability platform. The EU Vulnerability Database, created under the GCVE initiative, is now live. This signals a deliberate shift in how software weaknesses are identified, cataloged, and shared across Europe.
---------------------------------------------
https://thecyberexpress.com/eu-launches-gcve-vulnerability-database/
∗∗∗ Critical Vulnerability in Advanced Custom Fields: Extended Plugin Puts 100,000 WordPress Sites at Risk ∗∗∗
---------------------------------------------
A critical security flaw has been discovered in a widely used ACF add-on plugin for WordPress, placing up to 100,000 websites at risk of a full site takeover. The vulnerability affects the Advanced Custom Fields: Extended plugin, an add-on designed to extend the functionality of the popular Advanced Custom Fields ecosystem. An advisory issued about the flaw assigns a severity rating of 9.8, emphasizing the serious impact it can have if exploited.
---------------------------------------------
https://thecyberexpress.com/acf-add-on-vulnerability-wordpress/
=====================
= Vulnerabilities =
=====================
∗∗∗ Aktuelle Angriffswelle gegen CVE-2025-59718, Patches unzureichend ∗∗∗
---------------------------------------------
Im Dezember des vergangenen Jahres hat Fortinet Informationen über einen Login Bypass in mehreren Produkten des Unternehmens veröffentlicht (siehe dazu auch unser Warning vom 19.12.2025) und gleichzeitig Patches zur Verfügung gestellt welche das Problem beheben sollten.
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/1/aktuelle-angriffswelle-gegen-cve-20…
∗∗∗ GitLab Patch Release: 18.8.2, 18.7.2, 18.6.4 ∗∗∗
---------------------------------------------
Learn more about GitLab Patch Release: 18.8.2, 18.7.2, 18.6.4 for GitLab Community Edition (CE) and Enterprise Edition (EE).
---------------------------------------------
https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-re…
∗∗∗ Sicherheitslücken: Nvidia CUDA Toolkit lässt Schadcode passieren ∗∗∗
---------------------------------------------
Nvidias Programmierschnittstelle CUDA weist Sicherheitslücken auf, wodurch unter anderem Schadcode auf Systeme gelangen kann. Davon sind je nach Sicherheitslücke Linux und Windows bedroht. Eine reparierte Ausgabe von CUDA Toolkit schafft Abhilfe.
---------------------------------------------
https://www.heise.de/news/Sicherheitsluecken-Nvidia-CUDA-Toolkit-laesst-Sch…
∗∗∗ Sicherheitspatches: Atlassian sichert Confluence & Co. gegen mögliche Attacken ∗∗∗
---------------------------------------------
Atlassian hat für Bamboo, Bitbucket, Confluence, Crowd, Jira und Jira Service Management Data Center und Server wichtige Sicherheitsupdates veröffentlicht. Nach erfolgreichen Attacken können Angreifer in erster Linie DoS-Zustände und somit Abstürze auslösen.
---------------------------------------------
https://www.heise.de/news/Sicherheitspatches-Atlassian-sichert-Confluence-C…
∗∗∗ Security updates for Wednesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (brotli and container-tools:rhel8), Debian (python-keystonemiddleware and python3.9), Fedora (cef, freerdp, golang-github-tetratelabs-wazero, and libpcap), Oracle (brotli, gpsd, kernel, and transfig), Red Hat (freerdp, golang, java-11-openjdk with Extended Lifecycle Support, libpng, libssh, mingw-libpng, and runc), SUSE (abseil-cpp, alloy, apache2, bind, cpp-httplib, curl, erlang, firefox, gpg2, grafana, haproxy, hauler, hawk2, libblkid-devel, libpng16, libraylib550, python-keystonemiddleware-doc, python-uv, python-weasyprint, squid, and tomcat), and Ubuntu (crawl and iperf3).
---------------------------------------------
https://lwn.net/Articles/1055322/
∗∗∗ VU#458022: Open5GS WebUI uses a hard-coded secrets including JSON Web Token signing key ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/458022
∗∗∗ VU#102648: Code Injection Vulnerability in binary-parser library ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/102648
∗∗∗ VU#481830: libheif Uncompressed Codec Lacks Bounds Check Leading to Application Crash ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/481830
∗∗∗ Oracle Critical Patch Update Advisory - January 2026 ∗∗∗
---------------------------------------------
https://www.oracle.com/security-alerts/cpujan2026.html
∗∗∗ Cisco Unified Communications Products Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Schneider Electric EcoStruxure Foxboro DCS ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-01
∗∗∗ Rockwell Automation Verve Asset Manager ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-03
∗∗∗ Schneider Electric devices using CODESYS Runtime ∗∗∗
---------------------------------------------
https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-02
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 19-01-2026 18:00 − Dienstag 20-01-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a security flaw that leverages indirect prompt injection targeting Google Gemini as a way to bypass authorization guardrails and use Google Calendar as a data extraction mechanism.
---------------------------------------------
https://thehackernews.com/2026/01/google-gemini-prompt-injection-flaw.html
∗∗∗ Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers ∗∗∗
---------------------------------------------
Cloudflare has addressed a security vulnerability impacting its Automatic Certificate Management Environment (ACME) validation logic that made it possible to bypass security controls and access origin servers. [..] The web infrastructure company said it found no evidence that the vulnerability was ever exploited in a malicious context. [..] The vulnerability was addressed by Cloudflare on October 27, 2025, with a code change that serves the response and disables WAF features only when the request matches a valid ACME HTTP-01 challenge token for that hostname.
---------------------------------------------
https://thehackernews.com/2026/01/cloudflare-fixes-acme-validation-bug.html
∗∗∗ Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading ∗∗∗
---------------------------------------------
Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads, likely with the intent to deploy a remote access trojan (RAT).
---------------------------------------------
https://thehackernews.com/2026/01/hackers-use-linkedin-messages-to-spread.h…
∗∗∗ EU-Kommission arbeitet an Open-Source-Strategie und fragt Community nach Feedback ∗∗∗
---------------------------------------------
Einzelpersonen und Gruppen haben bis zum 3. Februar Zeit, um Hinweise einzureichen.
---------------------------------------------
https://www.derstandard.at/story/3000000304870/eu-kommission-arbeitet-an-op…
∗∗∗ Microsoft & Anthropic MCP Servers At Risk of RCE, Cloud Takeovers ∗∗∗
---------------------------------------------
Researchers found the popular model context protocol (MCP) servers, which are integral components of AI services, carry serious vulnerabilities. [..] When they analyzed more than 7,000 MCP servers, they found that the same SSRF exposure might be latent in around 36.7% of all MCP servers on the Web today. [..] The company reported its findings to Anthropic last June. Half a year later, in December, Anthropic released the 2025.12.18 version of the Git MCP server, which better enforced path validation (in response to CVE-2025-68145), addressed argument handling (CVE-2025-68144), and completely removed the git_init tool (CVE-2025-68143).
---------------------------------------------
https://www.darkreading.com/application-security/microsoft-anthropic-mcp-se…
∗∗∗ Inside a Multi-Stage Windows Malware Campaign ∗∗∗
---------------------------------------------
The attack begins with social engineering lures delivered via business-themed documents crafted to appear routine and benign. These documents and accompanying scripts serve as visual distractions, diverting victims to fake tasks or status messages while malicious activity runs silently in the background.
---------------------------------------------
https://feeds.fortinet.com/~/940900697/0/fortinet/blogs~Inside-a-MultiStage…
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitslücke bei TP-Link: Überwachungskameras per Passwort-Reset knackbar ∗∗∗
---------------------------------------------
Der Netzwerkgerätehersteller TP-Link warnt vor einer gefährlichen Sicherheitslücke in seinen Vigi-Überwachungskameras. [..] Laut Schwachstellenbeschreibung basiert die Lücke auf einem Bug in der Passwortwiederherstellungsfunktion der Webschnittstelle betroffener Kameras. [..] Angreifer können mittels CVE-2026-0629 das Admin-Passwort zurücksetzen, ohne dass eine Überprüfung erfolgt. [..] Angreifer brauchen für die Ausnutzung von CVE-2026-0629 zwar einen Zugriff auf das lokale Netzwerk, mit dem die anvisierte Kamera verbunden ist.
---------------------------------------------
https://www.golem.de/news/tp-link-admin-konten-zahlloser-ueberwachungskamer…
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gpsd-minimal, jmc, kernel, kernel-rt, and net-snmp), Debian (apache-log4j2 and dcmtk), Fedora (exim, gpsd, mysql8.0, mysql8.4, python-biopython, and rust-lru), Mageia (firefox, nss and thunderbird), Oracle (container-tools:rhel8, gpsd-minimal, jmc, kernel, net-snmp, and uek-kernel), Red Hat (net-snmp), SUSE (chromium, go, harfbuzz-devel, kernel, libsoup, rust1.91, rust1.92, and thunderbird), and Ubuntu (apache2, avahi, and python-urllib3).
---------------------------------------------
https://lwn.net/Articles/1055152/
∗∗∗ VU#244846: Server-Side Template Injection (SSTI) vulnerability exist in Genshi ∗∗∗
---------------------------------------------
A Server-Side Template Injection (SSTI) vulnerability exists in the Genshi template engine due to unsafe evaluation of template expressions. [..] Genshi is a Python library developed by Edgewall, it provides an integrated set of components for parsing, generating, and processing HTML, XML, or other textual content for output generation on the web. [..] If an attacker can influence or inject template expressions, this vulnerability allows arbitrary code execution with the privileges of the running application. [..] At the time of publication, Genshi has not released an update addressing this issue.
---------------------------------------------
https://kb.cert.org/vuls/id/244846
∗∗∗ VU#271649: Stack-based buffer overflow in libtasn1 versions v4.20.0 and earlier ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/271649
∗∗∗ Beckhoff Security Advisory 2025-002 ∗∗∗
---------------------------------------------
https://download.beckhoff.com/download/document/product-security/Advisories…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 16-01-2026 18:00 − Montag 19-01-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ StealC hackers hacked as researchers hijack malware control panels ∗∗∗
---------------------------------------------
A cross-site scripting (XSS) flaw in the web-based control panel used by operators of the StealC info-stealing malware allowed researchers to observe active sessions and gather intelligence on the attackers’ hardware.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/stealc-hackers-hacked-as-res…
∗∗∗ Autotype: Windows-11-Update macht beliebte Keepass-Funktion kaputt ∗∗∗
---------------------------------------------
Seit dem Januar-Patchday kann Keepass in einigen Windows-Dialogen keine Zugangsdaten mehr per Autotype einfügen. Ein Fix ist nicht zu erwarten.
---------------------------------------------
https://www.golem.de/news/autotype-windows-11-update-macht-beliebte-keepass…
∗∗∗ What Happened After Security Researchers Found 60 Flock Cameras Livestreaming to the Internet ∗∗∗
---------------------------------------------
A couple months ago, YouTuber Benn Jordan "found vulnerabilities in some of Flock's license plate reader cameras," reports 404 Media's Jason Koebler. "He reached out to me to tell me he had learned that some of Flock's Condor cameras were left live-streaming to the open internet."
---------------------------------------------
https://yro.slashdot.org/story/26/01/17/0718211/what-happened-after-securit…
∗∗∗ China-Linked APT Exploited Sitecore Zero-Day in Critical Infrastructure Intrusions ∗∗∗
---------------------------------------------
A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last year.
---------------------------------------------
https://thehackernews.com/2026/01/china-linked-apt-exploits-sitecore-zero.h…
∗∗∗ CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of an ongoing campaign dubbed KongTuke that used a malicious Google Chrome extension masquerading as an ad blocker to deliberately crash the web browser and trick victims into running arbitrary commands using ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) dubbed ModeloRAT.
---------------------------------------------
https://thehackernews.com/2026/01/crashfix-chrome-extension-delivers.html
∗∗∗ Fehlende Postleitzahl? Nachricht von DPD ist eine Phishing-Falle ∗∗∗
---------------------------------------------
Ein Klassiker des Online-Betrugs. Ein Paketdienstleister meldet sich aus heiterem Himmel. Angeblich war ein Zustellversuch aufgrund einer fehlenden Postleitzahl nicht erfolgreich. Tatsächlich versuchen Kriminelle über ein gefälschtes Portal an Kreditkartendaten zu kommen.
---------------------------------------------
https://www.watchlist-internet.at/news/dpd-phishing-falle/
∗∗∗ Windows Januar 2026 Update tauscht Secure Boot Zertifikate ∗∗∗
---------------------------------------------
Im Juni 2026 laufen UEFI Secure Boot-Zertifikate für Windows ab. Im Oktober 2026 trifft es dann das nächste ablaufende UEFI-Zertifikat für den Secure Boot. Microsoft hat zum 13. Januar 2026 im Rahmen des Patchday erneut den Ansatz unternommen, das Secure Boot-Zertifikat im UEFI auszutauschen. Hier eine kurze Nachlese zum Sachstand.
---------------------------------------------
https://borncity.com/blog/2026/01/17/windows-januar-2026-update-tauscht-sec…
∗∗∗ From Extension to Infection: An In-Depth Analysis of the Evelyn Stealer Campaign Targeting Software Developers ∗∗∗
---------------------------------------------
This blog entry provides an in-depth analysis of the multistage delivery of the Evelyn information stealer, which was used in a campaign targeting software developers.
---------------------------------------------
https://www.trendmicro.com/en_us/research/26/a/analysis-of-the-evelyn-steal…
∗∗∗ Hackers Exploiting PDF24 App to Deploy Stealthy PDFSIDER Backdoor ∗∗∗
---------------------------------------------
Resecurity has identified PDFSIDER malware that exploits the legitimate PDF24 App to covertly steal data and allow remote access. Learn how this APT-level campaign targets corporate networks through spear-phishing and encrypted communications.
---------------------------------------------
https://hackread.com/hackers-exploit-pdf24-app-pdfsider-backdoor/
∗∗∗ Blink and youll miss them: 6-day certificates are here! ∗∗∗
---------------------------------------------
What a great way to start 2026! Let's Encrypt have now made their short-lived certificates available, so you can go and start using them right away.
---------------------------------------------
https://scotthelme.ghost.io/blink-and-youll-miss-them-6-day-certificates-ar…
∗∗∗ Microsoft startet mit Identifizierung von unsicherer RC4-Verschlüsselung ∗∗∗
---------------------------------------------
Die Windows-Sicherheitsupdates aus dem Januar läuten den Rauswurf unsicherer RC4-Verschlüsselung ein. Eine Lücke erfordert Maßnahmen.
---------------------------------------------
https://heise.de/-11145332
∗∗∗ Malware Peddlers Are Now Hijacking Snap Publisher Domains ∗∗∗
---------------------------------------------
tl;dr: There’s a relentless campaign by scammers to publish malware in the Canonical Snap Store. Some gets caught by automated filters, but plenty slips through. Recently, these miscreants have changed tactics - they’re now registering expired domains belonging to legitimate snap publishers, taking over their accounts, and pushing malicious updates to previously trustworthy applications. This is a significant escalation.
---------------------------------------------
https://blog.popey.com/2026/01/malware-purveyors-taking-over-published-snap…
∗∗∗ TPM on Embedded Systems: Pitfalls and Caveats ∗∗∗
---------------------------------------------
Trusted Platform Module (TPM) chips have been around since the release of the TPM 1.2 specification more than 20 years ago, and the TPM 2.0 specification1 was released in 2014. The technology is now seeing widespread adoption in various computing sectors. TPMs have been a standard feature in PCs, particularly notebooks, for some time. With integration into tools like systemd’s tooling for LUKS/dm-crypt and legal requirements like EU’s CRA, TPM functionality is also now making its way into the embedded Linux sector. In this post, we’ll highlight common pitfalls and considerations for using TPM chips on embedded devices.
---------------------------------------------
https://sigma-star.at/blog/2026/01/tpm-on-embedded-systems-pitfalls-and-cav…
∗∗∗ How to Remove Saved Passwords From Google Chrome (And Why You Should) ∗∗∗
---------------------------------------------
It usually starts with a small convenience. You log into a site once, Chrome offers to remember the password, and you click “Save” without thinking twice. Weeks turn into months, devices multiply, and before you know it, your browser knows more about your digital life than you do. This is exactly how many users end up relying on Chrome’s built-in tools without ever learning how to delete passwords from Chrome when it actually matters.
---------------------------------------------
https://thecyberexpress.com/how-to-delete-saved-passwords-in-google-chrome/
∗∗∗ All In One SEO Plugin Flaw Exposes AI Token to Low-Privilege WordPress Users ∗∗∗
---------------------------------------------
A newly disclosed security vulnerability in the All In One SEO ecosystem has drawn attention across the WordPress community due to its potential reach and impact. The flaw affects the widely used AIOSEO plugin, which is active on more than 3 million WordPress websites. It allows low-privileged users to access a site-wide AI access token tied to the plugin’s artificial intelligence features.
---------------------------------------------
https://thecyberexpress.com/all-in-one-seo-wordpress-ai-token/
=====================
= Vulnerabilities =
=====================
∗∗∗ Security updates for Monday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (cups, libpq, libsoup3, podman, and postgresql16), Debian (ffmpeg, gpsd, python-urllib3, and thunderbird), Fedora (chromium, foomuuri, forgejo, freerdp, harfbuzz, libtpms, musescore, python-biopython, and python3.12), Mageia (gimp, libpng, nodejs, and python-urllib3), and SUSE (alloy, avahi, bind, chromedriver, chromium, cpp-httplib, docker, erlang, fluidsynth, freerdp, go-sendxmpp, govulncheck-vulndb, kernel, libwireshark19, NetworkManager-applet-l2tp, python, python311-virtualenv, thunderbird, and zk).
---------------------------------------------
https://lwn.net/Articles/1054992/
∗∗∗ Unberechtigte Zugriffe möglich: Lücken in Dells OneFS-NAS-Betriebssystem ∗∗∗
---------------------------------------------
Dells NAS-Betriebssystem PowerScale OneFS ist über mehrere Sicherheitslücken angreifbar. Dagegen stehen abgesicherte Ausgaben zum Download bereit.
---------------------------------------------
https://heise.de/-11145497
∗∗∗ Wireshark 4.6.3 Released, (Sat, Jan 17th) ∗∗∗
---------------------------------------------
https://isc.sans.edu/diary/rss/32636
∗∗∗ K000159600: Rack vulnerability CVE-2022-30123 ∗∗∗
---------------------------------------------
https://my.f5.com/manage/s/article/K000159600
∗∗∗ K000159077: GNU Tar vulnerability CVE-2019-9923 ∗∗∗
---------------------------------------------
https://my.f5.com/manage/s/article/K000159077
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 15-01-2026 18:00 − Freitag 16-01-2026 18:00
Handler: Alexander Riepl
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Per Bitflip zum Root-Zugriff: Lücke in AMD-CPUs ermöglicht Einbruch in Cloud-VMs ∗∗∗
---------------------------------------------
Eine neue Angriffstechnik namens Stackwarp lässt Angreifer über AMD-CPUs virtuelle Maschinen kapern. Vor allem Cloud-Umgebungen sind gefährdet.
---------------------------------------------
https://www.golem.de/news/per-bitflip-zum-root-zugriff-luecke-in-amd-cpus-e…
∗∗∗ AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks ∗∗∗
---------------------------------------------
A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could have allowed complete takeover of the cloud service providers own GitHub repositories, including its AWS JavaScript SDK, putting every AWS environment at risk.
---------------------------------------------
https://thehackernews.com/2026/01/aws-codebuild-misconfiguration-exposed.ht…
∗∗∗ Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that masquerade as human resources (HR) and enterprise resource planning (ERP) platforms like Workday, NetSuite, and SuccessFactors to take control of victim accounts.
---------------------------------------------
https://thehackernews.com/2026/01/five-malicious-chrome-extensions.html
∗∗∗ Chinese spies used Maduros capture as a lure to phish US govt agencies ∗∗∗
---------------------------------------------
Whats next for Venezuela? Click on the file and see What policy wonk wouldnt want to click on an attachment promising to unveil US plans for Venezuela? Chinese cyberspies used just such a lure to target US government agencies and policy-related organizations in a phishing campaign that began just days after an American military operation captured Venezuelan President Nicolás Maduro.
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/01/15/chinese_spie…
∗∗∗ Bankrupt scooter startup left one private key to rule them all ∗∗∗
---------------------------------------------
An Estonian e-scooter owner locked out of his own ride after the manufacturer went bust did what any determined engineer might do. He reverse-engineered it, and claims he ended up discovering the master key that unlocks every scooter the company ever sold.
---------------------------------------------
https://www.theregister.com/2026/01/16/bankrupt_scooter_startup_key/
∗∗∗ RondoDox botnet linked to large-scale exploit of critical HPE OneView bug ∗∗∗
---------------------------------------------
Check Point observes 40K+ attack attempts in our hours, with government organizations under fire A critical HPE OneView flaw is now being exploited at scale, with Check Point tying mass, automated attacks to the RondoDox botnet.
---------------------------------------------
https://www.theregister.com/2026/01/16/rondodox_botnet_hpe_oneview/
∗∗∗ German cops add Black Basta boss to EU most-wanted list ∗∗∗
---------------------------------------------
Ransomware kingpin who escaped Armenian custody is believed to be lying low back home German cops have added Russian national Oleg Evgenievich Nefekov to their list of most-wanted criminals for his services to ransomware.
---------------------------------------------
https://www.theregister.com/2026/01/16/black_basta_boss_wanted/
∗∗∗ Jetzt patchen! Kritische Cisco-Lücke seit Dezember 2025 ausgenutzt ∗∗∗
---------------------------------------------
Angreifer kompromittieren Cisco Secure Email Gateway und Secure Email und Web Manager über eine Root-Schwachstelle. Nun gibt es Sicherheitsupdates.
---------------------------------------------
https://www.heise.de/news/Jetzt-patchen-Kritische-Cisco-Luecke-seit-Dezembe…
∗∗∗ Die lernende Bedrohung: Predator-Spyware ist raffinierter als gedacht ∗∗∗
---------------------------------------------
Die Spähsoftware Predator von Intellexa gewinnt selbst aus gescheiterten Infektionsversuchen wertvolle Daten und macht gezielt Jagd auf IT-Sicherheitsforscher.
---------------------------------------------
https://www.heise.de/news/Die-lernende-Bedrohung-Predator-Spyware-ist-raffi…
∗∗∗ Chinese hackers targeting ‘high value’ North American critical infrastructure, Cisco says ∗∗∗
---------------------------------------------
Chinese hackers successfully breached multiple critical infrastructure organizations in North America over the last year using a combination of compromised credentials and exploitable servers, researchers at Cisco Talos found.
---------------------------------------------
https://therecord.media/china-hackers-apt-cisco-talos
∗∗∗ Canadian investment regulator confirms hackers hit 750,000 investors ∗∗∗
---------------------------------------------
The nongovernmental Canadian Investment Regulatory Organization, which oversees the countrys debt and equity marketplaces as well as some financial institutions, released details about an August 2025 data breach.
---------------------------------------------
https://therecord.media/canada-ciro-investing-regulator-confirms-data-breach
∗∗∗ CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation ∗∗∗
---------------------------------------------
CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut through the noise.
---------------------------------------------
https://www.trendmicro.com/en_us/research/25/l/CVE-2025-55182-analysis-poc-…
∗∗∗ New PayPal Scam Sends Verified Invoices With Fake Support Numbers ∗∗∗
---------------------------------------------
Scammers are using verified PayPal invoices to launch callback phishing attacks. Learn how the "Alexzander" invoice bypasses Google filters.
---------------------------------------------
https://hackread.com/paypal-scam-verified-invoices-fake-support-numbers/
∗∗∗ Operation Endgame: Dutch Police Arrest Alleged AVCheck Operator ∗∗∗
---------------------------------------------
Dutch police arrest the alleged AVCheck operator at Schiphol as part of Operation Endgame, a global effort targeting malware services and cybercrime.
---------------------------------------------
https://hackread.com/operation-endgame-dutch-police-arrest-avcheck-operator/
∗∗∗ Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation ∗∗∗
---------------------------------------------
Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol. Despite Net-NTLMv1 being deprecated and known to be insecure for over two decades—with cryptanalysis dating back to 1999—Mandiant consultants continue to identify its use in active environments.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-depreca…
∗∗∗ Das Meldeportal in der AWS-Cloud: Warum nur, BSI? ∗∗∗
---------------------------------------------
Schön, dass das BSI ein neues Portal für IT-Sicherheit bietet. Aber muss das unbedingt über die AWS-Cloud laufen, fragt sich Tobias Glemser.
---------------------------------------------
https://heise.de/-11142071
∗∗∗ How to Use Pareto Principle to Fine-Tune Alerts and Reduce False Positives Wisely ∗∗∗
---------------------------------------------
False positives were not only consuming analyst time — they were also diluting attention and slowing response on the few alerts that actually mattered.
---------------------------------------------
https://detect.fyi/how-to-use-pareto-principle-to-fine-tune-alerts-and-redu…
=====================
= Vulnerabilities =
=====================
∗∗∗ Hackers exploit Modular DS WordPress plugin flaw for admin access ∗∗∗
---------------------------------------------
Hackers are actively exploiting a maximum severity flaw in the Modular DS WordPress plugin that allows them to bypass authentication remotely and access the vulnerable sites with admin-level privileges.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-exploit-modular-ds-w…
∗∗∗ Critical flaw lets hackers track, eavesdrop via Bluetooth audio devices ∗∗∗
---------------------------------------------
A critical vulnerability in Googles Fast Pair protocol can allow attackers to hijack Bluetooth audio accessories like wireless headphones and earbuds, track users, and eavesdrop on their conversations.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-whisperpair-flaw-le…
∗∗∗ VU#383552: thelibrarian does not secure its interface, allowing for access to internal system data ∗∗∗
---------------------------------------------
Multiple vulnerabilities were discovered in The Librarian, an AI-powered personal assistant tool provided by the company TheLibrarian.io. The Librarian can be used to manage personal email, calendar, documents, and other information through external services, such as Gmail and Google Drive, and also summarize meetings and schedule emails.
---------------------------------------------
https://kb.cert.org/vuls/id/383552
∗∗∗ VU#650657: Livewire Filemanager contains an insecure .php component that allows for unauthenticated RCE in Laravel Products ∗∗∗
---------------------------------------------
A vulnerability, tracked as CVE-2025-14894, has been discovered within Livewire Filemanager, a tool designed for usage within Laravel applications. The Livewire Filemanager tool allows for users to upload various files, including PHP files, and host them within the Laravel application.
---------------------------------------------
https://kb.cert.org/vuls/id/650657
∗∗∗ Juniper Networks: Zahlreiche Sicherheitsupdates für diverse Produkte ∗∗∗
---------------------------------------------
Juniper Networks hat Sicherheitsaktualisierungen für zahlreiche Produkte veröffentlicht. IT-Admins sollten sie rasch anwenden.
---------------------------------------------
https://www.heise.de/news/Juniper-Networks-Zahlreiche-Sicherheitsupdates-fu…
∗∗∗ Security updates for Friday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gnupg2), Debian (firefox-esr), Oracle (cups, gnupg2, libpq, net-snmp, postgresql, postgresql:15, postgresql:16, transfig, and vsftpd), Red Hat (firefox), SUSE (apache2, curl, firefox, gpg2, hawk2, libcryptopp-devel, openCryptoki, python310, python311-urllib3, rke2, squid, and tomcat), and Ubuntu (cpp-httplib, git, python-apt, and simgear).
---------------------------------------------
https://lwn.net/Articles/1054683/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 14-01-2026 18:00 − Donnerstag 15-01-2026 18:00
Handler: Alexander Riepl
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Exploit code public for critical FortiSIEM command injection flaw ∗∗∗
---------------------------------------------
Technical details and a public exploit have been published for a critical vulnerability affecting Fortinets Security Information and Event Management (SIEM) solution that could be leveraged by a remote, unauthenticated attacker to execute commands or code.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/exploit-code-public-for-crit…
∗∗∗ Critical flaw lets hackers track, eavesdrop via Bluetooth audio devices ∗∗∗
---------------------------------------------
A critical vulnerability in Googles Fast Pair protocol can allow attackers to hijack Bluetooth audio accessories like wireless headphones and earbuds, track users, and eavesdrop on their conversations.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-flaw-lets-hackers-t…
∗∗∗ Most Severe AI Vulnerability to Date Hits ServiceNow ∗∗∗
---------------------------------------------
The ITSM giant tacked agentic AI onto a largely unguarded legacy chatbot, exposing customers data and connected systems.
---------------------------------------------
https://www.darkreading.com/remote-workforce/ai-vulnerability-servicenow
∗∗∗ Januar-Patchday: Windows-Updates machen Remote-Anmeldung kaputt ∗∗∗
---------------------------------------------
Einige Anwender haben neuerdings Probleme, sich mit der Windows-App bei Azure Virtual Desktop oder Windows 365 anzumelden. Ein Fix ist in Arbeit.
---------------------------------------------
https://www.golem.de/news/januar-patchday-windows-updates-machen-windows-ap…
∗∗∗ Ransomware-Boss gesucht: Dieser Mann soll der Anführer von Black Basta sein ∗∗∗
---------------------------------------------
Interpol, Europol und das BKA fahnden nach dem Boss der Ransomware-Gruppe Black Basta, die allein in Deutschland über 100 Organisationen geschädigt hat.
---------------------------------------------
https://www.golem.de/news/ransomware-boss-gesucht-dieser-mann-soll-der-anfu…
∗∗∗ A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby ∗∗∗
---------------------------------------------
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription.
---------------------------------------------
https://projectzero.google/2026/01/pixel-0-click-part-1.html
∗∗∗ A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave ∗∗∗
---------------------------------------------
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context.
---------------------------------------------
https://projectzero.google/2026/01/pixel-0-click-part-2.html
∗∗∗ A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? ∗∗∗
---------------------------------------------
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement.
---------------------------------------------
https://projectzero.google/2026/01/pixel-0-click-part-3.html
∗∗∗ Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers ∗∗∗
---------------------------------------------
The Black Lotus Labs team at Lumen Technologies said it null-routed traffic to more than 550 command-and-control (C2) nodes associated with the AISURU/Kimwolf botnet since early October 2025.
---------------------------------------------
https://thehackernews.com/2026/01/kimwolf-botnet-infected-over-2-million.ht…
∗∗∗ Verizon Outage Knocks Out US Mobile Service, Including Some 911 Calls ∗∗∗
---------------------------------------------
A major Verizon outage appeared to impact customers across the United States starting around noon ET on Wednesday. Calls to Verizon customers from other carriers may also be impacted.
---------------------------------------------
https://www.wired.com/story/verizon-outage-knocks-out-us-mobile-service-inc…
∗∗∗ Razzia in Deutschland: Behörden machen Cybercrime-Hoster RedVDS dicht ∗∗∗
---------------------------------------------
Internationalen Ermittlern und Microsoft ist ein Schlag gegen die Infrastruktur des Cybercrime-Hosters RedVDS gelungen. Die Server standen auch in Deutschland.
---------------------------------------------
https://www.heise.de/news/Razzia-in-Deutschland-Behoerden-machen-Cybercrime…
∗∗∗ Chrome: Google kappt Support für älteres macOS ∗∗∗
---------------------------------------------
Das vor weniger als fünf Jahren erschienene macOS 12 alias Monterey ist bei Googles Browser bald raus. Sicherheitslücken bleiben bestehen.
---------------------------------------------
https://www.heise.de/news/Chrome-Google-kappt-Support-fuer-aelteres-macOS-1…
∗∗∗ curl: Projekt beendet Bug-Bounty-Programm ∗∗∗
---------------------------------------------
curl-Maintainer Daniel Stenberg hat das Ende des Bug-Bounty-Programms angekündigt. Unbrauchbare KI-Meldungen nahmen wohl überhand.
---------------------------------------------
https://www.heise.de/news/curl-Projekt-beendet-Bug-Bounty-Programm-11142345…
∗∗∗ Kriminelle imitieren Banknummern: Vorsicht vor Spoofing ∗∗∗
---------------------------------------------
Kriminelle suchen ständig nach neuen Methoden, um an Kontodaten zu gelangen. Leider sind sie fündig geworden: Mit Spoofing täuschen sie die Nummer von Banken vor und erschleichen so das Vertrauen ihrer Opfer.
---------------------------------------------
https://www.watchlist-internet.at/news/kriminelle-imitieren-banknummern-spo…
∗∗∗ Microsoft disrupts RedVDS cybercrime platform behind $40 million in scam losses ∗∗∗
---------------------------------------------
Microsoft and law enforcement partners took down a popular cybercriminal subscription service called RedVDS that was used to enable more than $40 million in fraud losses in the United States alone.
---------------------------------------------
https://therecord.media/microsoft-redvds-cybercrime-scam
∗∗∗ UAT-8837 targets critical infrastructure sectors in North America ∗∗∗
---------------------------------------------
Cisco Talos is closely tracking UAT-8837, a threat actor we assess with medium confidence is a China-nexus advanced persistent threat (APT) actor.
---------------------------------------------
https://blog.talosintelligence.com/uat-8837/
∗∗∗ GhostPoster Browser Malware Hid for 5 Years With 840,000 Installs ∗∗∗
---------------------------------------------
Researchers uncover a 5-year malware campaign using browser extensions on Chrome, Firefox and Edge, relying on hidden payloads and shared infrastructure.
---------------------------------------------
https://hackread.com/ghostposter-browser-malware-840000-installs/
∗∗∗ Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation ∗∗∗
---------------------------------------------
Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol. Despite Net-NTLMv1 being deprecated and known to be insecure for over two decades—with cryptanalysis dating back to 1999—Mandiant consultants continue to identify its use in active environments.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-depreca…
∗∗∗ New Remcos Campaign Distributed Through Fake Shipping Document ∗∗∗
---------------------------------------------
FortiGuard Labs discovered a new phishing campaign in the wild. The campaign delivers a new variant of Remcos, a commercial lightweight remote access tool (RAT) with a wide range of capabilities, including system resource management, remote surveillance, network management, and Remcos agent management.
---------------------------------------------
https://feeds.fortinet.com/~/940295429/0/fortinet/blogs~New-Remcos-Campaign…
∗∗∗ I’m The Captain Now: Hijacking a global ocean supply chain network ∗∗∗
---------------------------------------------
There’s a good chance you have never heard of BLUVOYIX or Bluspark Global, and that’s ok! Not every company that powers global commerce is a household name. Despite their low profile, companies like these have an important role to play in keeping the global supply chain running in the background. Breaches at companies you haven’t heard of can often have the worst impacts.
---------------------------------------------
https://eaton-works.com/2026/01/14/bluspark-bluvoyix-hack/
∗∗∗ Malicious Chrome Extension Steals MEXC API Keys for Account Takeover ∗∗∗
---------------------------------------------
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.
---------------------------------------------
https://socket.dev/blog/malicious-chrome-extension-steals-mexc-api-keys
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access ∗∗∗
---------------------------------------------
A maximum-severity security flaw in a WordPress plugin called Modular DS has come under active exploitation in the wild, according to Patchstack. The vulnerability, tracked as CVE-2026-23550 (CVSS score: 10.0), has been described as a case of unauthenticated privilege escalation impacting all versions of the plugin prior to and including 2.5.1. It has been patched in version 2.5.2.
---------------------------------------------
https://thehackernews.com/2026/01/critical-wordpress-modular-ds-plugin.html
∗∗∗ Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002 ∗∗∗
---------------------------------------------
This module allows site administrators to grant specific roles the authority to assign selected roles to users, without them needing the "administer permissions" permission. The module contains an access bypass vulnerability when used in combination with the Views Bulk Operations module. A user with the ability to delegate a role is also able to assign the administrator role, including to their own user.
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-002
∗∗∗ Group invite - Moderately critical - Access bypass - SA-CONTRIB-2026-001 ∗∗∗
---------------------------------------------
This module enables allows group managers to invite people into their group. The module doesn't sufficiently check access under certain circumstances, allowing unauthorized users to access the group's content.
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-001
∗∗∗ Microsoft Entra ID SSO Login - Critical - Access bypass - SA-CONTRIB-2026-005 ∗∗∗
---------------------------------------------
This module enables Drupal sites to authenticate users via Microsoft Entra ID (formerly Azure AD) using OAuth 2.0. The module doesn't sufficiently validate API responses from Microsoft allowing complete account takeover of any user, including site administrators, without requiring any credentials or access to the target's email account.
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-005
∗∗∗ Fortinet: Heap-based buffer overflow in cw_acd daemon (FortiOS, FortiSASE, FortiSwitchManager) ∗∗∗
---------------------------------------------
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiSwitchManager cw_acd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. CVE-2025-25249 / CVSSv3 Score 7.4
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-25-084
∗∗∗ Angreifer können Palo-Alto-Firewalls in Wartungsmodus zwingen ∗∗∗
---------------------------------------------
Unter bestimmten Bedingungen können Angreifer an einer Sicherheitslücke in PAN-OS ansetzen und so Firewalls von Palo Alto Networks attackieren. Bislang gibt es dem IT-Sicherheitsunternehmen zufolge keine Hinweise auf Attacken.
---------------------------------------------
https://www.heise.de/news/Angreifer-koennen-Palo-Alto-Firewalls-in-Wartungs…
∗∗∗ CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal (Severity: HIGH) ∗∗∗
---------------------------------------------
A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.
---------------------------------------------
https://security.paloaltonetworks.com/CVE-2026-0227
∗∗∗ Security Vulnerabilities fixed in Thunderbird 140.7 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-05/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 147 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-04/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 13-01-2026 18:00 − Mittwoch 14-01-2026 18:30
Handler: Felician Fuchs
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Target employees confirm leaked source code is authentic ∗∗∗
---------------------------------------------
Multiple current and former Target employees confirmed that leaked source code samples posted by a threat actor match real internal systems. The company also rolled out an "accelerated" lockdown of its Git server, requiring VPN access, a day after being contacted by BleepingComputer.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/target-employees-confirm-lea…
∗∗∗ Microsoft: Windows 365 update blocks access to Cloud PC sessions ∗∗∗
---------------------------------------------
Microsoft confirmed that a recent Windows 365 update is blocking customers from accessing their Microsoft 365 Cloud PC sessions.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-365-updat…
∗∗∗ Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners ∗∗∗
---------------------------------------------
Cloud marketplace and distributor Pax8 has confirmed that it mistakenly sent an email to fewer than 40 UK-based partners containing a spreadsheet with internal business information, including MSP customer and Microsoft licensing data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cloud-marketplace-pax8-accid…
∗∗∗ Reprompt attack let hackers hijack Microsoft Copilot sessions ∗∗∗
---------------------------------------------
Researchers identified an attack method dubbed "Reprompt" that could allow attackers to infiltrate a users Microsoft Copilot session and issue commands to exfiltrate sensitive data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/reprompt-attack-let-hackers-…
∗∗∗ ConsentFix debrief: Insights from the new OAuth phishing attack ∗∗∗
---------------------------------------------
ConsentFix is an OAuth phishing technique abusing browser-based authorization flows to hijack Microsoft accounts. Push Security shares new insights from continued tracking, community research, and evolving attacker techniques.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/consentfix-debrief-insights-…
∗∗∗ Microsoft updates Windows DLL that triggered security alerts ∗∗∗
---------------------------------------------
Microsoft has resolved a known issue that was causing security applications to incorrectly flag a core Windows component, the company said in a service alert posted this week.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-updates-windows-d…
∗∗∗ Ohne Authentifizierung: Broadcom-Lücke lässt Angreifer ganze WLAN-Netze lahmlegen ∗∗∗
---------------------------------------------
Zahlreiche WLAN-Netze, die auf Broadcom-Chipsätzen basieren, lassen sich mit nur einem Datenpaket lahmlegen. Angreifer brauchen dafür keinen Schlüssel.
---------------------------------------------
https://www.golem.de/news/ohne-authentifizierung-broadcom-luecke-laesst-ang…
∗∗∗ Corrupting LLMs Through Weird Generalizations ∗∗∗
---------------------------------------------
Abstract LLMs are useful because they generalize so well. But can you have too much of a good thing? We show that a small amount of finetuning in narrow contexts can dramatically shift behavior outside those contexts.
---------------------------------------------
https://www.schneier.com/blog/archives/2026/01/corrupting-llms-through-weir…
∗∗∗ Malware Intercepts Googlebot via IP-Verified Conditional Logic ∗∗∗
---------------------------------------------
Some attackers are increasingly moving away from simple redirects in favor of more “selective” methods of payload delivery. This approach filters out regular human visitors, allowing attackers to serve malicious content to search engine crawlers while remaining invisible to the website owner.
---------------------------------------------
https://blog.sucuri.net/2026/01/malware-intercepts-googlebot-via-ip-verifie…
∗∗∗ Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a malicious Google Chrome extension thats capable of stealing API keys associated with MEXC, a centralized cryptocurrency exchange (CEX) available in over 170 countries, while masquerading as a tool to automate trading on the platform.
---------------------------------------------
https://thehackernews.com/2026/01/malicious-chrome-extension-steals-mexc.ht…
∗∗∗ New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification ∗∗∗
---------------------------------------------
Research analyzing 4,700 leading websites reveals that 64% of third-party applications now access sensitive data without business justification, up from 51% in 2024. Government sector malicious activity spiked from 2% to 12.9%, while 1 in 7 Education sites show active compromise.
---------------------------------------------
https://thehackernews.com/2026/01/new-research-64-of-3rd-party.html
∗∗∗ Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware ∗∗∗
---------------------------------------------
Security experts have disclosed details of an active malware campaign thats exploiting a DLL side-loading vulnerability in a legitimate binary associated with the open-source c-ares library to bypass security controls and deliver a wide range of commodity trojans and stealers.
---------------------------------------------
https://thehackernews.com/2026/01/hackers-exploit-c-ares-dll-side-loading.h…
∗∗∗ Interrail meldet Datenleck: Auch Ausweisdaten betroffen ∗∗∗
---------------------------------------------
Bei Eurail flossen mutmaßlich Daten ab. Der Anbieter stellt Interrail-Pässe auch im Auftrag der deutschen, österreichischen und Schweizer Bahn aus.
---------------------------------------------
https://www.heise.de/news/Interrail-meldet-Datenleck-Auch-Ausweisdaten-betr…
∗∗∗ Kritik an GnuPG und seinem Umgang mit gemeldeten Lücken ∗∗∗
---------------------------------------------
Die auf dem 39C3 demonstrierten Probleme in der PGP-Implementierung GnuPG riefen vielfältige Kritik an GnuPGs Umgang damit, aber auch an PGP insgesamt hervor.
---------------------------------------------
https://www.heise.de/hintergrund/Kritik-an-GnuPG-und-seinem-Umgang-mit-geme…
∗∗∗ Malware-Masche: Jobangebote jubeln Entwicklern bösartige Repositories unter ∗∗∗
---------------------------------------------
Entwickler müssen bei Jobangeboten inzwischen aufpassen. Kriminelle versuchen, Infostealer darüber zu verteilen.
---------------------------------------------
https://www.heise.de/news/Malware-Masche-Jobangebote-jubeln-Entwicklern-boe…
∗∗∗ How real software downloads can hide remote backdoors ∗∗∗
---------------------------------------------
Attackers use legitimate open-source software as cover, relying on user trust to compromise systems. We dive into an example.
---------------------------------------------
https://www.malwarebytes.com/blog/threat-intel/2026/01/how-real-software-do…
∗∗∗ Instagram dementiert Hack nach massenhaften Passwort-Reset-Mails ∗∗∗
---------------------------------------------
Zuvor waren Berichte über entwendete Daten von 17 Millionen Usern kursiert. Das Unternehmen widerspricht und rät zum Ignorieren der Mails
---------------------------------------------
https://www.derstandard.at/story/3000000303975/instagram-dementiert-hack-na…
∗∗∗ Ransomware: Tactical Evolution Fuels Extortion Epidemic ∗∗∗
---------------------------------------------
New whitepaper reveals record number of attacks as threat landscape evolves with new players and new tactics.
---------------------------------------------
https://www.security.com/threat-intelligence/ransomware-extortion-epidemic
∗∗∗ More than 40 countries impacted by North Korea IT worker scams, crypto thefts ∗∗∗
---------------------------------------------
Eleven countries led a session at the UN headquarters in New York centered around a 140-page report released last fall that covered North Korea’s extensive cyber-focused efforts to fund its nuclear and ballistic weapons program.
---------------------------------------------
https://therecord.media/40-countries-impacted-nk-it-thefts-united-nations
∗∗∗ Poland says it repelled major cyberattack on power grid, blames Russia ∗∗∗
---------------------------------------------
Poland narrowly avoided a large-scale power outage by thwarting what officials described as the most serious cyberattack on its energy infrastructure in years.
---------------------------------------------
https://therecord.media/poland-cyberattack-grid-russia
∗∗∗ Western cyber agencies warn about threats to industrial operational technology ∗∗∗
---------------------------------------------
New guidance issued by Britain’s National Cyber Secure Centre (NCSC), a part of signals and cyber intelligence agency GCHQ, sets out how organizations should securely connect equipment such as industrial control systems, sensors and other critical services.
---------------------------------------------
https://therecord.media/cyber-agencies-warn-of-industrial-system-threats
∗∗∗ Telegram to Add Warning for Proxy Links After IP Leak Concerns ∗∗∗
---------------------------------------------
Telegram will add a warning for proxy links after reports showed they can expose user IP addresses with a single click, bypassing VPN or privacy settings.
---------------------------------------------
https://hackread.com/telegram-add-warning-proxy-links-ip-leak/
∗∗∗ Hacker Claims Full Breach of Russia’s Max Messenger, Threatens Public Leak ∗∗∗
---------------------------------------------
A hacker claims a full breach of Russia’s Max Messenger, threatening to leak user data and backend systems if demands are not met.
---------------------------------------------
https://hackread.com/hacker-russia-max-messenger-breach-data-leak/
∗∗∗ Secure Connectivity Principles for Operational Technology (OT) ∗∗∗
---------------------------------------------
CISA and the UK National Cyber Security Centre (NCSC-UK), in collaboration with federal and international partners, have released Secure Connectivity Principles for Operational Technology (OT) guidance to help asset owners address increasing business and regulatory pressures for connectivity into operational technology (OT) networks.
---------------------------------------------
https://www.cisa.gov/resources-tools/resources/secure-connectivity-principl…
∗∗∗ Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8554 ∗∗∗
---------------------------------------------
This blog is the first part of a mini-series looking at the four unpatchable CVEs in every Kubernetes cluster.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerab…
∗∗∗ Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025 ∗∗∗
---------------------------------------------
Despite the advancements that have been made in Wi-Fi security with the arrival of WPA3, some misconfigurations and legacy protocols still remain. In this blogpost, we share insights into Wi-Fi related findings encountered during penetration testing engagements.
---------------------------------------------
https://www.synacktiv.com/en/publications/wireless-infidelity-pentesting-wi…
=====================
= Vulnerabilities =
=====================
∗∗∗ Multiple vulnerabilities in EATON UPS Companion ∗∗∗
---------------------------------------------
EATON UPS Companion provided by Eaton contains multiple vulnerabilities.
---------------------------------------------
https://jvn.jp/en/jp/JVN48187396/
∗∗∗ Patchday Microsoft: Attacken auf Windows und Windows Server beobachtet ∗∗∗
---------------------------------------------
Es sind wichtige Sicherheitsupdates für Office, Windows & Co. erschienen. Angreifer nutzen bereits eine Lücke aus. Weitere Attacken können bevorstehen.
---------------------------------------------
https://www.heise.de/news/Patchday-Microsoft-Angreifer-spionieren-Speicherb…
∗∗∗ Patchday Adobe: Schadcode-Lücken bedrohen Dreamweaver & Co. ∗∗∗
---------------------------------------------
Wichtige Sicherheitsupdates reparieren unter anderem Adobe ColdFusion und InDesign.
---------------------------------------------
https://www.heise.de/news/Patchday-Adobe-Schadcode-Luecken-bedrohen-Dreamwe…
∗∗∗ Security updates for Wednesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (sssd), Debian (linux-6.1 and python-parsl), Fedora (chezmoi, complyctl, composer, and firefox), Oracle (kernel), Red Hat (buildah, libpq, podman, postgresql, postgresql16, postgresql:13, postgresql:15, and postgresql:16), SUSE (avahi, curl, ffmpeg-4, ffmpeg-7, firefox, istioctl, k6, kubelogin, libmicrohttpd, libpcap-devel, libpng16, libtasn1-6-32bit, matio, ovmf, python-tornado6, python311-Authlib, and teleport), and Ubuntu (angular.js, python-urllib3, and webkit2gtk).
---------------------------------------------
https://lwn.net/Articles/1054167/
∗∗∗ Mitigating Denial-of-Service Vulnerability from Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users ∗∗∗
---------------------------------------------
This bug highlights how deeply async_hooks has become embedded in the Node.js ecosystem. What started as a low-level debugging API is now a critical dependency for React Server Components, Next.js, every major APM tool, and any code using AsyncLocalStorage.
---------------------------------------------
https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-…
∗∗∗ F5: K000159546, Python vulnerability CVE-2024-5642 ∗∗∗
---------------------------------------------
https://my.f5.com/manage/s/article/K000159546
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/