=====================
= End-of-Day report =
=====================
Timeframe: Freitag 24-04-2026 18:00 − Montag 27-04-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Cyber Threat Intelligence - Art, Science, something else entirely? ∗∗∗
---------------------------------------------
Is Cyber Threat Intelligence an art, science, both, or something else entirely?
---------------------------------------------
https://bytesandborscht.com/cyber-threat-intelligence-art-science-something…
∗∗∗ New BlackFile extortion group linked to surge of vishing attacks ∗∗∗
---------------------------------------------
A new financially motivated hacking group tracked as BlackFile has been linked to a wave of data theft and extortion attacks against retail and hospitality organizations since February 2026.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang…
∗∗∗ ADT confirms data breach after ShinyHunters leak threat ∗∗∗
---------------------------------------------
Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-aft…
∗∗∗ Panne bei RDP-Verbindungen: Windows-Update mit kaputter Warnmeldung verteilt ∗∗∗
---------------------------------------------
Neue Warnmeldungen sollen Windows-Nutzer eigentlich vor bösartigen RDP-Dateien schützen. Doch die sind manchmal weder gut lesbar noch bedienbar.
---------------------------------------------
https://www.golem.de/news/panne-bei-rdp-verbindungen-windows-update-mit-kap…
∗∗∗ Attacken auf Firmennetzwerke: Hacker tricksen Teams-Nutzer mit Spam aus ∗∗∗
---------------------------------------------
Google-Forscher warnen vor einer Hackergruppe, die Nutzer bei Microsoft Teams austrickst, um gefährliche Malware in Firmennetzwerke zu schleusen.
---------------------------------------------
https://www.golem.de/news/attacken-auf-firmennetzwerke-hacker-tricksen-team…
∗∗∗ FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches ∗∗∗
---------------------------------------------
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER.
---------------------------------------------
https://thehackernews.com/2026/04/firestarter-backdoor-hit-federal-cisco.ht…
∗∗∗ Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran's nuclear program by destroying uranium enrichment centrifuges.
---------------------------------------------
https://thehackernews.com/2026/04/researchers-uncover-pre-stuxnet-fast16.ht…
∗∗∗ LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure ∗∗∗
---------------------------------------------
A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving large language models (LLMs), has come under active exploitation in the wild less than 13 hours after its public disclosure.
---------------------------------------------
https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.ht…
∗∗∗ Gesundheitsdaten aus UK Biobank auf Alibaba angeboten ∗∗∗
---------------------------------------------
Gesundheitsdaten der UK Biobank wurden online angeboten. Der Zugriff ist inzwischen gestoppt. Weitere Sicherheitsmaßnahmen sind geplant.
---------------------------------------------
https://www.heise.de/news/Gesundheitsdaten-aus-UK-Biobank-auf-Alibaba-angeb…
∗∗∗ New ClickFix attack Hides in Native Windows Tools to Reduce Detection Risk ∗∗∗
---------------------------------------------
Fake CAPTCHA ClickFix attack tricks users into running malicious commands, using cmdkey and regsvr32 to maintain persistence and avoid detection on Windows.
---------------------------------------------
https://hackread.com/clickfix-variant-native-windows-tools-bypass-security/
∗∗∗ Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation ∗∗∗
---------------------------------------------
Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.
---------------------------------------------
https://hackread.com/microsoft-entra-agent-id-flaw-tenant-takeover/
∗∗∗ Angriffe auf SimpleHelp, Samsung MagicINFO und D-Link DIR-823X beobachtet ∗∗∗
---------------------------------------------
Die US-Behörde CISA warnt vor beobachteten Attacken auf Schwachstellen in SimpleHelp, Samsung MagicINFO und D-Link DIR-823X.
---------------------------------------------
https://heise.de/-11272629
∗∗∗ 73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations ∗∗∗
---------------------------------------------
Socket is tracking cloned Open VSX extensions tied to GlassWorm, with several updated from benign-looking sleepers into malware delivery vehicles.
---------------------------------------------
https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm?utm_medium…
∗∗∗ Udemy Data Breach — ShinyHunters Claims 1.4M Records ∗∗∗
---------------------------------------------
The notorious cybercriminal group ShinyHunters posted a “Pay or Leak” warning on their data leak site on April 24, 2026, claiming the compromise of over 1.4 million records containing PII and internal corporate data from Udemy. The final deadline set for Udemy to respond is April 27, 2026, or face public exposure.
---------------------------------------------
https://thecyberthrone.in/2026/04/24/udemy-data-breach-shinyhunters-claims-…
∗∗∗ Operation TrustTrap Reveals 16,800 Fake Domains Exploiting User Trust ∗∗∗
---------------------------------------------
In a world where digital threats are becoming more confusing, Cyble Research and Intelligence Labs (CRIL) has uncovered one of the most extensive deceptive domain spoofing campaigns to date.
---------------------------------------------
https://thecyberexpress.com/operation-trusttrap/
∗∗∗ Fake CAPTCHA Scam Abuses Verification Clicks to Send Costly International Texts ∗∗∗
---------------------------------------------
Research from Infoblox reveals a massive Click2SMS fraud scheme using fake CAPTCHAs and back button hijacking to trick victims into sending costly international texts.
---------------------------------------------
https://hackread.com/fake-captcha-pages-exploit-clicks-send-texts/
=====================
= Vulnerabilities =
=====================
∗∗∗ Werbeblocker Pi-hole: Update stopft Codeschmuggel- und Rechteausweitungslücken ∗∗∗
---------------------------------------------
Die Entwickler haben den DNS-basierten Werbeblocker Pi-hole aktualisiert. Das Update stopft hochriskante Sicherheitslecks.
---------------------------------------------
https://www.heise.de/news/Werbeblocker-Pi-hole-Update-stopft-Codeschmuggel-…
∗∗∗ VMware Tanzu Spring Boot: Angreifer können auf Endpoints zugreifen ∗∗∗
---------------------------------------------
Wichtige Sicherheitsupdates schließen mehrere Schwachstellen in der VMware-Tanzu-Spring-Framework-Komponente Spring Boot.
---------------------------------------------
https://heise.de/-11272771
∗∗∗ „Pack2TheRoot“: Sicherheitslücke betrifft mehrere Linux-Distributionen ∗∗∗
---------------------------------------------
Das Telekom-Sicherheitsteam hat die Sicherheitslücke „Pack2TheRoot“ entdeckt, die Rechteausweitung in mehreren Distributionen ermöglicht.
---------------------------------------------
https://heise.de/-11272897
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1069938/
∗∗∗ K000160994: SQLite vulnerability CVE-2025-70873 ∗∗∗
---------------------------------------------
https://my.f5.com/manage/s/article/K000160994
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 23-04-2026 18:00 − Freitag 24-04-2026 18:00
Handler: Guenes Holler
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ Trigona ransomware attacks use custom exfiltration tool to steal data ∗∗∗
---------------------------------------------
Recently observed Trigona ransomware attacks are using a custom, command-line tool to steal data from compromised environments faster and more efficiently.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/trigona-ransomware-attacks-u…
∗∗∗ LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure ∗∗∗
---------------------------------------------
A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving LLMs, has come under active exploitation in the wild less than 13 hours after its public disclosure.
---------------------------------------------
https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.ht…
∗∗∗ Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2 ∗∗∗
---------------------------------------------
Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the abuse of Microsoft Visual Studio Code (VS Code) tunnels for remote access.
---------------------------------------------
https://thehackernews.com/2026/04/tropic-trooper-uses-trojanized.html
∗∗∗ Behörde für abgesicherte Ausweise geknackt – Millionen Franzosen betroffen ∗∗∗
---------------------------------------------
Frankreichs Behörde für Ausweise gesteht ein, dass Daten von 12 Millionen Franzosen auf dem Schwarzmarkt feilgeboten werden. Der Täter spricht von 19 Millionen.
---------------------------------------------
https://www.heise.de/news/Behoerde-fuer-abgesicherte-Ausweise-geknackt-Mill…
∗∗∗ Handala Hack Team: Threat Actor Profile ∗∗∗
---------------------------------------------
Handala Hack Team, also stylized as Handala_hack, is a hacktivist threat group aligned with pro-Palestinian messaging and Iranian strategic interests. It emerged in December 2023 following the escalation of the Gaza conflict, shortly after the 7 October 2023 Hamas attack on Israel, presenting itself as a pro-Palestinian hacktivist collective. Its operations closely mirror Iranian state-linked activity and indicate a focus on disruption and psychological impact rather than financial gain.
---------------------------------------------
https://outpost24.com/blog/handala-hack-threat-profile/
∗∗∗ Analyzing GLOBAL GROUP (BlackLock) Artifacts ∗∗∗
---------------------------------------------
In the rapidly evolving threat landscape of early 2026, ransomware operations have shifted dramatically toward high-impact infrastructure targets, with VMware ESXi hypervisors emerging as a prime vector for mass disruption. Ransomware groups like GLOBAL GROUP are one of those groups. It started all today with an technical analysis of a publicly shared X domain by the MalwareHunterTeam and the leak of the whole ecosystem of RAMP .
---------------------------------------------
https://detect.fyi/analyzing-global-group-blacklock-artifacts-72dabc14c500?…
=====================
= Vulnerabilities =
=====================
∗∗∗ Update #1: Schwerwiegende Sicherheitslücken in Cisco Adaptive Security Appliance - aktiv ausgenutzt - Updates verfügbar ∗∗∗
---------------------------------------------
Cisco hat Informationen zu einer vermutlich bereits seit einigen Monaten laufenden Angriffskampagne veröffentlicht. Im Rahmen dieser Kampagne haben Angreifer:innen, denen bereits im vergangenen Jahr eine breitgefächerte Kampagne gegen Edge-Devices zugerechnet wurde, Cisco Adaptive Security Appliance (ASA) Systeme der 5500-X Reihe welche "VPN web services" kompromittiert um in weiterer Folge auf den übernommenen Geräten Schadsoftware zu platzieren und Daten zu stehlen.
---------------------------------------------
https://www.cert.at/de/warnungen/2026/4/schwerwiegende-sicherheitslucken-in…
∗∗∗ Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks ∗∗∗
---------------------------------------------
Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to ongoing attacks exploiting a cross-site scripting (XSS) security flaw, according to nonprofit security organization Shadowserver. On Friday, Internet security watchdog Shadowserver also warned that over 10,500 Zimbra servers exposed online remain unpatched, most of them in Asia (3,794) and Europe (3,793).
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-says-zimbra-flaw-now-ex…
∗∗∗ Fast 12 Jahre unentdeckt: Telekom deckt gefährliche Root-Lücke in Linux auf ∗∗∗
---------------------------------------------
Sicherheitsforscher der Telekom haben Claude auf Linux -Systeme losgelassen. Die KI hat eine seit 2014 bestehende Root-Lücke in Packagekit gefunden.
---------------------------------------------
https://www.golem.de/news/fast-12-jahre-unentdeckt-telekom-deckt-gefaehrlic…
∗∗∗ Patch richtet fehlerhafte Zugriffskontrolle in HCL BigFix Service Management ∗∗∗
---------------------------------------------
Die KI-gestützte Endpoint-Verwaltungsplattform HCL BigFix Service Management ist verwundbar. Aufgrund einer fehlerhaften Zugriffskontrolle können Angreifer auf Instanzen zugreifen. Ein Sicherheitspatch steht zum Download bereit. Bislang gibt es keine Berichte zu Attacken.
---------------------------------------------
https://www.heise.de/news/Patch-richtet-fehlerhafte-Zugriffskontrolle-in-HC…
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1069549/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 22-04-2026 18:00 − Donnerstag 23-04-2026 18:00
Handler: Felician Fuchs
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ New Mirai campaign exploits RCE flaw in EoL D-Link routers ∗∗∗
---------------------------------------------
A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-mirai-campaign-exploits-…
∗∗∗ New GopherWhisper APT group abuses Outlook, Slack, Discord for comms ∗∗∗
---------------------------------------------
A previously undocumented state-backed threat actor named GopherWhisper is using a Go-based custom toolkit and legitimate services like Microsoft 365 Outlook, Slack, and Discord in attacks against government entities.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-gopherwhisper-apt-group-…
∗∗∗ Electricity Is a Growing Area of Cyber Risk ∗∗∗
---------------------------------------------
IT has long been concerned about ensuring systems receive the right amount of electricity. Cyberattackers are realizing they can manipulate voltage fluctuations for their purposes, too.
---------------------------------------------
https://www.darkreading.com/cyber-risk/are-power-regulators-becoming-a-new-…
∗∗∗ Hacker erbeuten Daten von Intersport-Kunden ∗∗∗
---------------------------------------------
Die Cyberkriminellen haben Kundendaten von Usern erbeutet, die den Onlineshop von Intersport benutzt haben.
---------------------------------------------
https://futurezone.at/digital-life/intersport-hacker-angriff-kriminelle-dat…
∗∗∗ Vercel Finds More Compromised Accounts in Context.ai-Linked Breach ∗∗∗
---------------------------------------------
Vercel on Wednesday revealed that it has identified an additional set of customer accounts that were compromised as part of a security incident that enabled unauthorized access to its internal systems.
---------------------------------------------
https://thehackernews.com/2026/04/vercel-finds-more-compromised-accounts.ht…
∗∗∗ Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages ∗∗∗
---------------------------------------------
Apple has rolled out a software fix for iOS and iPadOS to address a Notification Services flaw that stored notifications marked for deletion on the device.The vulnerability, tracked as CVE-2026-28950 (CVSS score: N/A), has been described as a logging issue that has been addressed with improved data redaction.
---------------------------------------------
https://thehackernews.com/2026/04/apple-patches-ios-flaw-that-stored.html
∗∗∗ AI Tools Are Helping Mediocre North Korean Hackers Steal Millions ∗∗∗
---------------------------------------------
One group of hackers used AI for everything from vibe coding their malware to creating fake company websites—and stole as much as $12 million in three months.
---------------------------------------------
https://www.wired.com/story/ai-tools-are-helping-mediocre-north-korean-hack…
∗∗∗ Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener ∗∗∗
---------------------------------------------
On March 12, 2026, Zscaler ThreatLabz discovered a malicious ZIP archive containing military-themed document lures targeting Chinese-speaking individuals. Our analysis of this sample uncovered a campaign leveraging a multi-stage attack chain where a trojanized SumatraPDF reader deploys an AdaptixC2 Beacon agent, ultimately leading to the download and abuse of Visual Studio (VS) Code tunnels for remote access.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/tropic-trooper-pivots-adapt…
∗∗∗ Sicherheitsbehörden warnen vor chinesischen Mitnutzern ∗∗∗
---------------------------------------------
Nachrichtendienste und Cybersicherheitsbehörden warnen vor Angreifern aus der Volksrepublik, die Infrastruktur Nichtsahnender für Operationen nutzenn.
---------------------------------------------
https://www.heise.de/news/Sicherheitsbehoerden-warnen-vor-chinesischen-Mitn…
∗∗∗ Fake-Fahrzeugbericht: Diese Falle wartet beim Online-Autoverkauf! ∗∗∗
---------------------------------------------
Wer online ein KFZ verkaufen möchte, erhält oft seltsame Anfragen. Bestehen Interessent:innen auf der Erstellung eines zusätzlichen Prüfberichts und liefern gleich die dafür passende Website mit, ist allerhöchste Vorsicht angebracht! Mit derartigen Fake-Portalen ziehen Kriminellen ihren Opfern das Geld aus der Tasche und ergaunern Kreditkartendaten.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-fahrzeugbericht/
∗∗∗ Hackers deployed wiper malware in destructive attacks on Venezuela’s energy sector ∗∗∗
---------------------------------------------
Hackers deployed a previously unknown wiper malware against Venezuela’s energy and utilities sector in an attack that appears to have been designed to destroy systems.
---------------------------------------------
https://therecord.media/hackers-venezuela-wiper-malware-oil
∗∗∗ Defending against China-nexus covert networks of compromised devices ∗∗∗
---------------------------------------------
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it
---------------------------------------------
https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-…
∗∗∗ Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite ∗∗∗
---------------------------------------------
Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-eng…
∗∗∗ Signal-Phishing-Warnung: Auslöser wohl Angriff auf Julia Klöckner ∗∗∗
---------------------------------------------
Julia Klöckner ist offenbar Opfer der Signal-Phishing-Angriffe geworden, vor denen BfV und BSI am Mittwoch erneut gewarnt haben.
---------------------------------------------
https://heise.de/-11268708
∗∗∗ Tails 7.7: Warnung vor abgelaufenen Secure-Boot-Zertifikaten ∗∗∗
---------------------------------------------
Die Linux-Distribution für anonymes Bewegen im Netz, Tails, ist in Version 7.7 erschienen. Sie warnt vor alten Secure-Boot-Zertifikaten.
---------------------------------------------
https://heise.de/-11269936
∗∗∗ University of Warsaw Data Breach Exposes 200,000+ Sensitive Files on Darknet ∗∗∗
---------------------------------------------
Over 200,000 files containing sensitive personal information from the University of Warsaw have been leaked online. The University of Warsaw cyberattack, which targeted the institutions digital systems, resulted in the publication of the stolen data on the darknet in mid-April 2026.
---------------------------------------------
https://thecyberexpress.com/university-of-warsaw-cyberattack/
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdate: Diverse Attacken auf IBM App Connect Enterprise möglich ∗∗∗
---------------------------------------------
IBMs Integrationsplattform App Connect Enterprise ist verwundbar. Angreifer können an mehreren Schwachstellen ansetzen.
---------------------------------------------
https://www.heise.de/news/Sicherheitsupdate-Diverse-Attacken-auf-IBM-App-Co…
∗∗∗ n8n: Updates beheben kritische Sicherheitslücken in Automatisierungsplattform ∗∗∗
---------------------------------------------
Die Aktualisierung wurde per E-Mail allen Admins angekündigt, diese sollten sie nun prompt einspielen. Es droht Code-Einschleusung.
---------------------------------------------
https://heise.de/-11268464
∗∗∗ VMware Tanzu Spring Security: Angreifer können bösartigen Clients anmelden ∗∗∗
---------------------------------------------
Aufgrund von Sicherheitsproblemen ist im Kontext von VMware Tanzu Spring Security unter anderem die Authentifizierung umgehbar.
---------------------------------------------
https://heise.de/-11268714
∗∗∗ Kritische Lücke in Rubys Standardbibliothek ERB: Angreifer können Code ausführen ∗∗∗
---------------------------------------------
Die Ruby-Lücke ist nicht einfach auszunutzen, ermöglicht einem Angreifer aber, sensible Daten auszulesen, Code zu starten und Backdoors zu installieren.
---------------------------------------------
https://heise.de/-11268704
∗∗∗ Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions ∗∗∗
---------------------------------------------
Docker alerted Socket to malicious images pushed to the official checkmarx/kics Docker Hub repository after internal monitoring flagged suspicious new activity around KICS image tags. Our investigation found that attackers appear to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to a legitimate upstream release.
---------------------------------------------
https://socket.dev/blog/checkmarx-supply-chain-compromise
∗∗∗ Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign ∗∗∗
---------------------------------------------
Socket researchers discovered that the Bitwarden CLI was compromised as part of the ongoing Checkmarx supply chain campaign. The affected package version appears to be @bitwarden/cli2026.4.0, and the malicious code was published in bw1.js, a file included in the package contents. The attack appears to have leveraged a compromised GitHub Action in Bitwarden’s CI/CD pipeline, consistent with the pattern seen across other affected repositories in this campaign.
---------------------------------------------
https://socket.dev/blog/bitwarden-cli-compromised
∗∗∗ NTFS-Treiber für Linux: NTFS-3G schließt Rechteausweitungslücke ∗∗∗
---------------------------------------------
https://www.heise.de/news/NTFS-Treiber-fuer-Linux-NTFS-3G-schliesst-Rechtea…
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1069356/
∗∗∗ DLL Hijacking in EfficientLab Controlio (cloud-based employee monitoring service) ∗∗∗
---------------------------------------------
https://sec-consult.com/de/vulnerability-lab/advisory/dll-hijacking-in-effi…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 21-04-2026 18:00 − Mittwoch 22-04-2026 18:00
Handler: Guenes Holler
Co-Handler: Felician Fuchs
=====================
= News =
=====================
∗∗∗ New GoGra malware for Linux uses Microsoft Graph API for comms ∗∗∗
---------------------------------------------
A Linux variant of the GoGra backdoor uses legitimate Microsoft infrastructure, relying on an Outlook inbox for stealthy payload delivery.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-gogra-malware-for-linux-…
∗∗∗ New npm supply-chain attack self-spreads to steal auth tokens ∗∗∗
---------------------------------------------
A new supply chain attack targeting the Node Package Manager (npm) ecosystem is stealing developer credentials and attempting to spread through packages published from compromised accounts.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-npm-supply-chain-attack-…
∗∗∗ Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process ∗∗∗
---------------------------------------------
Fraud operations now operate like call centers, complete with hiring, training, and performance tracking. Flare reveals how cybercriminals manage "Caller-as-a-Service" operations like a professional sales team.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/inside-caller-as-a-service-f…
∗∗∗ 13 Jahre unentdeckt: Mittels KI aufgespürte Lücke gefährdet Tausende Server ∗∗∗
---------------------------------------------
Hacker nutzen eine gefährliche und mithilfe von KI entdeckte Sicherheitslücke in Apache ActiveMQ aus. Auch in Deutschland sollten Admins tätig werden.
---------------------------------------------
https://www.golem.de/news/deutschland-auf-platz-4-tausende-apache-activemq-…
∗∗∗ Backdoor in Claude-Desktop-App: Stille Brücke aus dem Browser ∗∗∗
---------------------------------------------
Claude Desktop legt auf MacOS Native Messaging Hosts in jeden Chromium-Browser, sogar in noch nicht installierte. Das ist nicht harmlos - was nun zu tun ist.
---------------------------------------------
https://www.golem.de/news/backdoor-in-claude-desktop-app-stille-bruecke-aus…
∗∗∗ Impressums-Diebstahl: Fake-Shops für Anhänger als Dauerbrenner ∗∗∗
---------------------------------------------
Sie zählen zu den am häufigsten gemeldeten Fake-Shops: Portale für KFZ-Anhänger. Zu Bestpreisen, versteht sich. Nach der Bezahlung via Vorauskasse sind die Kriminellen plötzlich nicht mehr erreichbar. Das Geld ist weg, der Anhänger kommt nie. Was die Shops so gefährlich macht und woran man sie erkennt, erklärt dieser Artikel.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-shops-anhaenger/
∗∗∗ Kritische Schwachstelle in Microsoft-GitHub-Repository ∗∗∗
---------------------------------------------
Sicherheitsforscher von Tenable Research haben eine kritische Schwachstelle (CVSSv4 Score 9,3) in einem Microsoft-GitHub-Repository entdeckt. Die Sicherheitslücke ermöglicht Remote Code Execution (RCE) sowie unautorisierten Zugriff auf Repository-Secrets. Die Entdeckung unterstreicht, dass CI/CD-Infrastrukturen ein zentraler Bestandteil moderner Angriffsflächen sind.
---------------------------------------------
https://borncity.com/blog/2026/04/22/kritische-schwachstelle-in-microsoft-g…
∗∗∗ Attacken laufen bereits: Rund 1.300 Sharepoint-Instanzen sind angreifbar ∗∗∗
---------------------------------------------
Eine Lücke in Microsoft Sharepoint lässt Angreifer vertrauliche Daten lesen und ändern. Obwohl es einen Patch gibt, sind die meisten Systeme ungeschützt.
---------------------------------------------
https://www.golem.de/news/attacken-laufen-bereits-rund-1-300-sharepoint-ins…
∗∗∗ Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk ∗∗∗
---------------------------------------------
The critical remote code execution flaw (CVE-2026-1731) in the remote monitoring and management tool can be exploited to spread ransomware and compromise supply chains.
---------------------------------------------
https://www.darkreading.com/cyberattacks-data-breaches/surge-bomgar-rmm-exp…
=====================
= Vulnerabilities =
=====================
∗∗∗ Microsoft releases emergency patches for critical ASP.NET flaw ∗∗∗
---------------------------------------------
Microsoft has released out-of-band (OOB) security updates to patch a critical ASP.NET Core privilege escalation vulnerability. The security flaw (tracked as CVE-2026-40372) was found in the ASP.NET Core Data Protection cryptographic APIs, and it could allow unauthenticated attackers to gain SYSTEM privileges on affected devices by forging authentication cookies.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergenc…
∗∗∗ Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape ∗∗∗
---------------------------------------------
A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-5752, is rated 9.3 on the CVSS scoring system.
---------------------------------------------
https://thehackernews.com/2026/04/cohere-ai-terrarium-sandbox-flaw.html
∗∗∗ Schadcode-Schlupflöcher bedrohen Apache Airflow und Airflow Keycloak ∗∗∗
---------------------------------------------
Apaches Open-Source-Workflow-Management-Plattformen Airflow und Airflow Keycloak sind verwundbar. Eine Lücke gilt als kritisch.
---------------------------------------------
https://www.heise.de/news/Schadcode-Schlupfloecher-bedrohen-Apache-Airflow-…
∗∗∗ Oracle Critical Patch Update Advisory - April 2026 ∗∗∗
---------------------------------------------
https://www.oracle.com/security-alerts/cpuapr2026.html
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1069105/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 20-04-2026 18:00 − Dienstag 21-04-2026 18:00
Handler: Felician Fuchs
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Serial-to-IP Devices Hide Thousands of Old and New Bugs ∗∗∗
---------------------------------------------
The OT devices that translate machine talk into Internet-speak are riddled with vulnerabilities and more frequently targeted for attacks, researchers say.
---------------------------------------------
https://www.darkreading.com/ics-ot-security/serial-ip-devices-thousands-of-…
∗∗∗ BSI warnt: Phishing-Attacken über Signal nehmen zu ∗∗∗
---------------------------------------------
Angreifer kapern regelmäßig Signal-Konten mittels Phishing. Beim BSI gibt es nun einen Leitfaden mit Handlungsempfehlungen für Betroffene.
---------------------------------------------
https://www.golem.de/news/bsi-warnt-phishing-attacken-ueber-signal-nehmen-z…
∗∗∗ A .WAV With A Payload, (Tue, Apr 21st) ∗∗∗
---------------------------------------------
There have been reports of threat actors using a .wav file as a vector for malware. It's a proper .wav file, but they didn't use staganography. The .wav file will play, but you'll just hear noise.
---------------------------------------------
https://isc.sans.edu/diary/rss/32910
∗∗∗ Real Apple notifications are being used to drive tech support scams ∗∗∗
---------------------------------------------
Scammers have found a way to abuse legitimate Apple notification emails to trick people into calling fake tech support numbers.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/04/real-apple-notifications-are…
∗∗∗ Fake-Jobvermittlungsagenturen jubeln Opfern Malware unter ∗∗∗
---------------------------------------------
Sie sind ansprechend designet und versprechen interessante Jobs zu Top-Konditionen. Leider ist an diesen Vermittlungsagenturen nichts echt. Über die Fake-Webseiten und dazugehörige Anwerbe-Mails wollen Kriminelle nicht nur an persönliche Informationen gelangen. Sie schummeln außerdem Schadsoftware auf die Geräte ihrer Opfer.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-jobvermittlungsagenturen/
∗∗∗ Bad Apples: Weaponizing native macOS primitives for movement and execution ∗∗∗
---------------------------------------------
Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture.
---------------------------------------------
https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-prim…
∗∗∗ Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories ∗∗∗
---------------------------------------------
Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a broader supply chain risk.
---------------------------------------------
https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-…
∗∗∗ Deep Malware Analysis of a Multi-Stage Cobalt Strike Loader ∗∗∗
---------------------------------------------
In this blog post, we provide a detailed technical reconstruction of a multi-stage malware chain that ultimately delivers a Cobalt Strike Beacon.
---------------------------------------------
https://www.joesecurity.org/blog/621128515416801396
∗∗∗ Command Execution via Drag-and-Drop in Terminal Emulators ∗∗∗
---------------------------------------------
Many people may not be aware that terminal emulators such as Kitty and xfce4-terminal support dragging and dropping of files into the terminal to insert the file's path directly at the cursor position. While this feature has existed for a while, more people have started to notice this as Claude Code has grown in popularity and allows users to drag and drop files for Claude to process.
---------------------------------------------
https://sdushantha.github.io/post/drop-it-like-its-hot
∗∗∗ Inside An AWS Cloud Threat Detection SOC Lab: Simulating and Detecting Real Cloud Attacks ∗∗∗
---------------------------------------------
Cloud computing has become the backbone over time of how modern systems are built and run. As I started diving deeper into cloud security, I began to see just how much organizations and various industries depend on it, not just for convenience, but for scalability, speed, and the ability to support technologies like artificial intelligence and big data.
---------------------------------------------
https://detect.fyi/inside-an-aws-cloud-threat-detection-soc-lab-simulating-…
∗∗∗ Context.ai OAuth Token Compromise ∗∗∗
---------------------------------------------
Compromised Context.ai OAuth tokens enabled attackers to perform a supply chain attack via trusted SaaS integrations. Learn how to assess the risk in your environment and how to prevent the next attack.
---------------------------------------------
https://www.wiz.io/blog/contextai-oauth-token-compromise
=====================
= Vulnerabilities =
=====================
∗∗∗ SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files ∗∗∗
---------------------------------------------
A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems. The vulnerability, tracked as CVE-2026-5760, carries a CVSS score of 9.8 out of 10.0. It has been described as a case of command injection leading to the execution of arbitrary code.
---------------------------------------------
https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html
∗∗∗ Apache ActiveMQ RCE ∗∗∗
---------------------------------------------
CVE-2026-34197 is a high-severity remote code execution (RCE) vulnerability affecting Apache ActiveMQ Classic. The flaw resides in the exposed Jolokia JMX-HTTP interface and allows attackers to execute arbitrary commands on the underlying system via crafted broker management requests. Recent reporting indicates that this vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild and elevating its priority for remediation.
---------------------------------------------
https://fortiguard.fortinet.com/threat-signal-report/6428
∗∗∗ Schadcode-Lücke mit Höchstwertung bedroht Firebird ∗∗∗
---------------------------------------------
Das Open-Source-Datenbankmanagementsystem Firebird ist über mehrere Wege angreifbar. Es kann Schadcode auf Systeme gelangen.
---------------------------------------------
https://www.heise.de/news/Schadcode-Luecke-mit-Hoechstwertung-bedroht-Fireb…
∗∗∗ Supply Chain Compromise Impacts Axios Node Package Manager ∗∗∗
---------------------------------------------
The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this alert to provide guidance in response to the software supply chain compromise of the Axios node package manager (npm).1 Axios is an HTTP client for JavaScript that developers commonly use in Node.js and browser environments.
---------------------------------------------
https://www.cisa.gov/news-events/alerts/2026/04/20/supply-chain-compromise-…
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1068830/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 17-04-2026 18:00 − Montag 20-04-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ LLM-basierte Schwachstellensuche ∗∗∗
---------------------------------------------
Nachdem sich Open Source Maintainer 2025 noch über eine Flut an minderwertigen Sicherheitshinweisen beschwert hatten, die durch LLM-basierte Schwachstellensuche ausgelöst wurde, so hat sich das Bild 2026 gedreht.
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/4/llm-basierte-schwachstellensuche
∗∗∗ Payouts King ransomware uses QEMU VMs to bypass endpoint security ∗∗∗
---------------------------------------------
The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/payouts-king-ransomware-uses…
∗∗∗ Critical flaw in Protobuf library enables JavaScript code execution ∗∗∗
---------------------------------------------
Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used JavaScript implementation of Googles Protocol Buffers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-flaw-in-protobuf-li…
∗∗∗ WhatsApp Leaks User Metadata to Attackers ∗∗∗
---------------------------------------------
Strangers can infer limited info about you without knowing or messaging you, which could theoretically aid certain kinds of malicious activity.
---------------------------------------------
https://www.darkreading.com/endpoint-security/whatsapp-leaks-user-metadata
∗∗∗ Jugendschutz und Sicherheit: EU-App für Altersnachweis nach zwei Minuten gehackt ∗∗∗
---------------------------------------------
Sicherheitsexperten kritisieren die neue Jugendschutz-App der EU. Die EU-Kommission verteidigt sich und sieht keine aktuellen Probleme.
---------------------------------------------
https://www.golem.de/news/jugendschutz-und-sicherheit-eu-app-fuer-altersnac…
∗∗∗ Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet ∗∗∗
---------------------------------------------
Threat actors are exploiting security flaws in TBK DVR and end‑of‑life (EoL) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42.
---------------------------------------------
https://thehackernews.com/2026/04/mirai-variant-nexcorium-exploits-cve.html
∗∗∗ $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims ∗∗∗
---------------------------------------------
Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said its suspending operations after it blamed Western intelligence agencies for a $13.74 million hack.
---------------------------------------------
https://thehackernews.com/2026/04/1374m-hack-shuts-down-sanctioned-grinex.h…
∗∗∗ I meant to do that! AI vendors shrug off responsibility for vulns ∗∗∗
---------------------------------------------
AI vendors: "You need to use AI to fight AI threats (and do everything else in your corporate IT environment)." Also AI vendors: "That's not a security flaw; it's working as intended."
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/04/19/ai_vendors_r…
∗∗∗ Ransomware-Angriffe fordern Ermittler heraus ∗∗∗
---------------------------------------------
Ransomware-Banden setzen auf KI und das Darknet, um kritische Infrastruktur zu treffen. Ermittler in Koblenz agieren zunehmend proaktiv.
---------------------------------------------
https://www.heise.de/news/Proaktive-Ermittlungen-gegen-Cybercrime-auf-Lande…
∗∗∗ Fake-ÖAMTC-Mail zu angeblichem Notfall-Rettungswerkzeug ∗∗∗
---------------------------------------------
Derzeit kursieren betrügerische E-Mails, die angeblich vom ÖAMTC stammen. In diesen werden Fahrzeughalter:innen zum Kauf eines angeblich verpflichtenden „Notfall-Rettungswerkzeugs” gedrängt. Die Nachricht ist gefälscht und soll zum Kauf in einem problematischen Online-Shop verleiten.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-oeamtc-mail-zu-angeblichem-notf…
∗∗∗ ID Austria: Warnung vor Betrugsmasche mit abgelaufenen Zertifikaten ∗∗∗
---------------------------------------------
Den Umstand, dass bald 300.000 Zertifikate ablaufen, nutzen Kriminelle aus. Entsprechende SMS sind aber immer ein Betrugsversuch, warnen die Behörden.
---------------------------------------------
https://www.derstandard.at/story/3000000317241/id-austria-warnung-vor-betru…
∗∗∗ Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) ∗∗∗
---------------------------------------------
Unit 42 details recent Iranian cyberattack activity, sharing direct observations of phishing, hacktivist activity and cybercrime. We include recommendations for defenders.
---------------------------------------------
https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/
∗∗∗ MAD Bugs: Even "cat readme.txt" is not safe ∗∗∗
---------------------------------------------
Codex found a bug turning "cat readme.txt" into arbitrary code execution.
---------------------------------------------
https://blog.calif.io/p/mad-bugs-even-cat-readmetxt-is-not
∗∗∗ Anthropics Claude Mythos Launch Is Built on Misinformation ∗∗∗
---------------------------------------------
A primary-source investigation for developers and security researchers who want the real story about what the Data says about Mythos.
---------------------------------------------
https://www.artificialintelligencemadesimple.com/p/anthropics-claude-mythos…
∗∗∗ Some secret management belongs in your HTTP proxy ∗∗∗
---------------------------------------------
Larger organizations commit to centralizing secrets management in a service. When done well, these services solve a lot of issues around secrets, at the cost of creating a lot of ops overhead (which is why they are limited to larger organizations) and engineering complexity. Smaller organizations have, until now, lived with the pain. But the pain has become far more significant with agents.
---------------------------------------------
https://blog.exe.dev/http-proxy-secrets
∗∗∗ NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets ∗∗∗
---------------------------------------------
NIST will stop enriching most CVEs under a new risk-based model, narrowing the NVD's scope as vulnerability submissions continue to surge.
---------------------------------------------
https://socket.dev/blog/nist-officially-stops-enriching-most-cves?utm_mediu…
=====================
= Vulnerabilities =
=====================
∗∗∗ Zero-Day-Lücken unter Beschuss: Angriffe auf Windows-Systeme beobachtet ∗∗∗
---------------------------------------------
Hacker haben drei kürzlich bekanntgewordene Sicherheitslücken im Windows Defender ausgenutzt. Nur für eine davon gibt es bisher einen Patch.
---------------------------------------------
https://www.golem.de/news/zero-day-luecken-unter-beschuss-angriffe-auf-wind…
∗∗∗ Mehr als ein Dutzend Root-Lücken gefährden Dell PowerProtect Data Domain ∗∗∗
---------------------------------------------
In aktuellen Versionen von Dell PowerProtect Data Domain haben die Entwickler Schwachstellen geschlossen.
---------------------------------------------
https://heise.de/-11263713
∗∗∗ n8n: Wichtiges Sicherheitsupdate in Sicht ∗∗∗
---------------------------------------------
Offensichtlich ist die Automatisierungsplattform n8n angreifbar. Die Entwickler wollen am Mittwochmittag ein Sicherheitsupdate veröffentlichen.
---------------------------------------------
https://heise.de/-11264561
∗∗∗ Xenbits XSA-488 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-488.html
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1068681/
∗∗∗ Vercel April 2026 security incident ∗∗∗
---------------------------------------------
https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 16-04-2026 18:00 − Freitag 17-04-2026 18:00
Handler: Felician Fuchs
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges ∗∗∗
---------------------------------------------
A researcher known as "Chaotic Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity researchers.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-defender-reds…
∗∗∗ ZionSiphon malware designed to sabotage water treatment systems ∗∗∗
---------------------------------------------
A new malware called ZionSiphon, specifically designed for operational technology, is targeting water treatment and desalination environments to sabotage their operations.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/zionsiphon-malware-designed-…
∗∗∗ Recently leaked Windows zero-days now exploited in attacks ∗∗∗
---------------------------------------------
Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/recently-leaked-windows-zero…
∗∗∗ Every Old Vulnerability Is Now an AI Vulnerability ∗∗∗
---------------------------------------------
AIs danger isnt that its creating new bugs, its that its amplifying old ones.
---------------------------------------------
https://www.darkreading.com/vulnerabilities-threats/every-old-vulnerability…
∗∗∗ Totalrecall Reloaded: Tool zeigt Schwachstelle in Windows Recall ∗∗∗
---------------------------------------------
Eine neue Version des Tools Totalrecall zeigt, wie sich Daten aus Windows Recall immer noch vergleichsweise leicht abgreifen lassen.
---------------------------------------------
https://www.golem.de/news/totalrecall-reloaded-tool-zeigt-schwachstelle-in-…
∗∗∗ Für 2.300 US-Dollar: Forscher entlockt Claude gefährlichen Chrome-Exploit ∗∗∗
---------------------------------------------
Ein Forscher hat mit Claude Opus in rund 20 Stunden eine funktionierende Exploit-Kette für Chrome entwickelt. Mythos braucht es dafür gar nicht.
---------------------------------------------
https://www.golem.de/news/fuer-2-300-us-dollar-forscher-entlockt-claude-gef…
∗∗∗ Joomla SEO Spam Injector: Obfuscated PHP Backdoor Hijacking Site Visitors ∗∗∗
---------------------------------------------
During a recent malware cleanup investigation, we encountered a compromised Joomla website where the site owner reported a strange issue. Their website displayed a large number of suspicious product links that had nothing to do with their business. These products were not added by the website owner and did not exist in their catalog.
---------------------------------------------
https://blog.sucuri.net/2026/04/joomla-seo-spam-injector-obfuscated-php-bac…
∗∗∗ North Korea targets macOS users in latest heist ∗∗∗
---------------------------------------------
Social engineering: low-cost, hard to patch, and scales well North Korean criminals set on stealing Apple users credentials and cryptocurrency are using a combination of social engineering and a fake Zoom software update to trick people into manually running malware on their own computers, according to Microsoft.
---------------------------------------------
https://www.theregister.com/2026/04/16/north_korea_social_engineering_macos/
∗∗∗ Spionageangst im Bendlerblock: Pistorius verbannt Privat-Handys aus Sitzungen ∗∗∗
---------------------------------------------
Wegen akuter Abhörgefahren durch Russland und China verschärft das Verteidigungsministerium die Regeln für Smartphones und Smartwatches in sensiblen Bereichen.
---------------------------------------------
https://www.heise.de/news/Spionageangst-im-Bendlerblock-Pistorius-verbannt-…
∗∗∗ Österlicher Zertifikats-GAU bei D-Trust: Zehntausende Zertifikate ungültig ∗∗∗
---------------------------------------------
Zwischen Gründonnerstag und Ostermontag mussten Admins ihre TLS-Zertifikate austauschen. Nun gibt D-Trust bekannt: Fast 60.000 waren nicht regelkonform.
---------------------------------------------
https://www.heise.de/news/Oesterlicher-Zertifikats-GAU-bei-D-Trust-Zehntaus…
∗∗∗ Windows-Updates: Unerwartete Server-Reboots und Anmeldestörungen ∗∗∗
---------------------------------------------
Die Updates für Windows Server im April haben Nebenwirkungen. Server starten unerwartet neu oder erlauben keine Admin-Anmeldungen.
---------------------------------------------
https://www.heise.de/news/Windows-Updates-Unerwartete-Server-Reboots-und-An…
∗∗∗ “Your shipment has arrived” email hides remote access software ∗∗∗
---------------------------------------------
This DHL-themed email tries to get recipients to install remote access software attackers can use to deploy further malware, including ransomware.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/04/your-shipment-has-arrived-em…
∗∗∗ Sometimes changing the password on your email mailbox isn’t enough ∗∗∗
---------------------------------------------
Have you ever taken a look at your Microsoft 365 mailbox rules? If not, it might be worth a few minutes of your time. Because newly released research reveals that hackers may already have beaten you to it. Read more in my article on the Fortra blog.
---------------------------------------------
https://www.fortra.com/blog/sometimes-changing-password-your-email-mailbox-…
∗∗∗ A Deep Dive Into Attempted Exploitation of CVE-2023-33538 ∗∗∗
---------------------------------------------
CVE-2023-33538 allows for command injection in TP-Link routers. We discuss exploitation attempts with payloads characteristic of Mirai botnet malware.
---------------------------------------------
https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/
∗∗∗ New CGrabber and Direct-Sys Malware Spread Through GitHub ZIP Files ∗∗∗
---------------------------------------------
Hackers spread CGrabber and Direct-Sys malware through GitHub ZIP files, bypassing security tools to steal passwords, crypto wallets, and user data.
---------------------------------------------
https://hackread.com/cgrabber-direct-sys-malware-github-zip-files/
∗∗∗ New Mirai Variant Nexcorium Hijacks DVR Devices for DDoS Attacks ∗∗∗
---------------------------------------------
Cybersecurity researchers at Fortinet have discovered Nexcorium, a new Mirai-based malware targeting TBK DVR systems to turn them into a botnet for DDoS attacks.
---------------------------------------------
https://hackread.com/mirai-variant-nexcorium-dvr-devices-ddos-attacks/
∗∗∗ Android 13 erreicht Support-Ende: Millionen Geräte betroffen ∗∗∗
---------------------------------------------
Android 13 ist raus. Google hat schon Anfang März den Support für die im Jahr 2022 veröffentlichte OS-Version eingestellt.
---------------------------------------------
https://heise.de/-11262547
∗∗∗ Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race ∗∗∗
---------------------------------------------
Obfuscation is security through obscurity; its purpose is to transform a piece of code into a much more complex representation, whilst preserving the original semantics of the code. A compilers job is to transform source code into binary code and produce the simplest and most optimized representation it can for a given architecture. These are contrary goals, yet this contradiction is where obfuscators find their greatest leverage.
---------------------------------------------
http://blog.quarkslab.com/obfuscation-vs-the-optimizer-an-llvm-middle-end-a…
∗∗∗ HTTP desync in Discords media proxy: Spying on a whole platform ∗∗∗
---------------------------------------------
In 2022, I came across a quirky behavior on media.discordapp.net when I miskeyed a space character into an attachment link: a 502 bad gateway. After some fiddling I realized that this was caused by a HTTP injection bug within the media proxy’s request to the upstream GCP bucket. The space character corrupted the proxied HTTP message, which caused the connection to prematurely terminate.
---------------------------------------------
https://tmctmt.com/posts/http-desync-in-discord/
∗∗∗ Russian GRU Cyber Campaign Targets Western Logistics Firms Supporting Ukraine ∗∗∗
---------------------------------------------
A new joint cybersecurity advisory has revealed an ongoing Russian GRU cyber campaign targeting Western logistics entities and technology companies, particularly those involved in coordinating and delivering aid to Ukraine. The activity has been linked to the Russian General Staff Main Intelligence Directorate’s Unit 26165, widely tracked in the cybersecurity community as APT28 or Fancy Bear.
---------------------------------------------
https://thecyberexpress.com/russian-gru-cyber-campaign-targets-logistics/
=====================
= Vulnerabilities =
=====================
∗∗∗ Angreifer attackieren Apache ActiveMQ Broker, Apache ActiveMQ ∗∗∗
---------------------------------------------
Admins sollten zügig die gegen derzeit laufende Attacken gerüsteten Versionen von Apache ActiveMQ Broker und Apache ActiveMQ installieren.
---------------------------------------------
https://www.heise.de/news/Angreifer-attackieren-Apache-ActiveMQ-Broker-Apac…
∗∗∗ YubiKey Manager: Sicherheitslücke ermöglicht Ausführung untergeschobenen Codes ∗∗∗
---------------------------------------------
Yubico warnt vor einer Suchpfad-Schwachstelle im YubiKey Manager, libfido2 und python-fido2. Updates korrigieren die Fehler.
---------------------------------------------
https://www.heise.de/news/YubiKey-Manager-Sicherheitsluecke-ermoeglicht-Aus…
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1068400/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 15-04-2026 18:00 − Donnerstag 16-04-2026 18:00
Handler: Felician Fuchs
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ NIST Updates NVD Operations to Address Record CVE Growth ∗∗∗
---------------------------------------------
NIST is changing the way it handles cybersecurity vulnerabilities and exposures, or CVEs, listed in its National Vulnerability Database (NVD). In the past, NIST’s NVD program aimed to analyze all CVEs to add details — such as severity scores and product lists — that help cybersecurity professionals prioritize and mitigate vulnerabilities. Going forward, NIST will add details, or “enrich,” those CVEs that meet certain criteria, which are explained below.
---------------------------------------------
https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-a…
∗∗∗ New ATHR vishing platform uses AI voice agents for automated attacks ∗∗∗
---------------------------------------------
A new cybercrime platform called ATHR can harvest credentials via fully automated voice phishing attacks that use both human operators and AI agents for the social engineering phase.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-athr-vishing-platform-us…
∗∗∗ Nach Bluehammer: Frustrierter Forscher leakt weiteren Windows-Exploit ∗∗∗
---------------------------------------------
Angreifer können mit dem Exploit auf Windows -Systemen aufgrund eines Fehlers im Defender Systemrechte erlangen. Ein Patch ist noch nicht in Sicht.
---------------------------------------------
https://www.golem.de/news/nach-bluehammer-frustrierter-forscher-leakt-weite…
∗∗∗ Kognitive Schuld: KI-generierte Software erfordert traditionelle Praktiken ∗∗∗
---------------------------------------------
Damit Entwickler ihren mithilfe von KI generierten Code weiterhin verstehen können, wird die Besinnung auf traditionelle Praktiken empfohlen.
---------------------------------------------
https://www.golem.de/news/kognitive-schuld-ki-generierte-software-erfordert…
∗∗∗ [Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th) ∗∗∗
---------------------------------------------
Security cameras are great at monitoring physical doors, but terrible at locking their own digital ones. Across the internet, thousands of unpatched DVRs sit publicly exposed, many guarded only by the default vendor passwords they shipped with. For threat actors, these are low-hanging fruit. This write-up details a recent two-second Telnet capture, providing a mechanical breakdown of how quickly an exposed camera system goes from online to fully compromised by bad actors.
---------------------------------------------
https://isc.sans.edu/diary/rss/32886
∗∗∗ Anthropics Project Glasswing CVE tally is still anyones guess ∗∗∗
---------------------------------------------
Like the majority of the companies participating, it remains a mystery Last week, Anthropic surprised the world by declaring that its latest model, Mythos, is so good at finding vulns that it would create chaos if released. Now, under the title of Project Glasswing, over 50 selected companies and orgs are allowed to test the hyped up LLM to find security holes in their own products. But just how many problems have they really discovered?
---------------------------------------------
https://go.theregister.com/feed/www.theregister.com/2026/04/15/project_glas…
∗∗∗ A fake Slack download is giving attackers a hidden desktop on your machine ∗∗∗
---------------------------------------------
This trojanized Slack installer looks normal, but quietly gives attackers an invisible desktop to access your accounts and data. We take a deep dive into the attack.
---------------------------------------------
https://www.malwarebytes.com/blog/threat-intel/2026/04/a-fake-slack-downloa…
∗∗∗ Teen arrested in Northern Ireland over cyberattack on school network ∗∗∗
---------------------------------------------
A 16-year-old boy has been arrested in Northern Ireland after a cyberattack disrupted access to educational systems used by potentially hundreds of thousands of students.
---------------------------------------------
https://therecord.media/northern-ireland-cyberattack-arrest
∗∗∗ PowMix botnet targets Czech workforce ∗∗∗
---------------------------------------------
Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call “PowMix.”
---------------------------------------------
https://blog.talosintelligence.com/powmix-botnet-targets-czech-workforce/
∗∗∗ Researchers Say Fiverr Left User Files Open to Google Search ∗∗∗
---------------------------------------------
Private Fiverr user documents, including tax records and IDs, were reportedly found in Google search results due to a storage configuration issue. Read more about the findings and the company’s response to the data exposure.
---------------------------------------------
https://hackread.com/fiverr-left-user-files-open-to-google-search/
∗∗∗ The German Cyber Criminal Überfall: Shifts in Europes Data Leak Landscape ∗∗∗
---------------------------------------------
Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023.
---------------------------------------------
https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-l…
∗∗∗ „Power Off“: BKA geht gegen DDoS-Angebote vor ∗∗∗
---------------------------------------------
Bundeskriminalamt und Generalstaatsanwaltschaft Frankfurt sind mit internationalen Partnern gegen sogenannte Stresserdienste vorgegangen. Es gab Festnahmen.
---------------------------------------------
https://heise.de/-11261177
∗∗∗ Europas Regierungen setzen auf eigene Messenger-Lösungen ∗∗∗
---------------------------------------------
Von Berlin bis Brüssel: Regierungen setzen verstärkt auf eigene Messenger, um Abhängigkeiten von US-Plattformen und Sicherheitsrisiken zu reduzieren.
---------------------------------------------
https://heise.de/-11261147
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco: Kritische Codeschmuggel-Lücken in ISE und mehr geschlossen ∗∗∗
---------------------------------------------
In Ciscos Identity Services Engine sowie Webex klaffen kritische Sicherheitslücken. Insgesamt stopfen die Entwickler 10 Sicherheitslecks.
---------------------------------------------
https://www.heise.de/news/Cisco-Kritische-Codeschmuggel-Luecken-in-ISE-und-…
∗∗∗ Anonymisierendes Linux: Notfallupdate auf Tails 7.6.2 schließt Flatpak-Lücke ∗∗∗
---------------------------------------------
Eine Sicherheitslücke in Flatpak ist Auslöser für ein Notfallupdate für die Linux-Distribution Tails, die anonymes Surfen ermöglicht.
---------------------------------------------
https://www.heise.de/news/Anonymisierendes-Linux-Notfallupdate-auf-Tails-7-…
∗∗∗ Gimp: Version 3.2.2 schließt Codeschmuggel-Lücke mit GIFs ∗∗∗
---------------------------------------------
Sicherheitslücken in Gimp erlauben das Einschleusen von Schadcode mit manipulierten Dateien wie GIFs. Version 3.2.2 schließt sie.
---------------------------------------------
https://heise.de/-11260619
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1067993/
∗∗∗ Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2026-002
∗∗∗ Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2026-001
∗∗∗ Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-core-2026-003
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 14-04-2026 18:00 − Mittwoch 15-04-2026 18:00
Handler: Felician Fuchs
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days ∗∗∗
---------------------------------------------
Today is Microsofts April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-…
∗∗∗ Over 100 Chrome extensions in Web Store target users accounts and data ∗∗∗
---------------------------------------------
More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-100-chrome-extensions-i…
∗∗∗ Microsoft: April updates trigger BitLocker key prompts on some servers ∗∗∗
---------------------------------------------
Microsoft confirmed on Tuesday that some Windows Server 2025 devices will boot into BitLocker recovery after installing the April 2026 KB5082063 Windows security update.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-some-windows-serv…
∗∗∗ New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released ∗∗∗
---------------------------------------------
Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution.The vulnerabilities have been described as command ..
---------------------------------------------
https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.h…
∗∗∗ Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover ∗∗∗
---------------------------------------------
A recently disclosed critical security flaw impacting nginx-ui, an open-source, web-based Nginx management tool, has come under active exploitation in the wild.The vulnerability in question is CVE-2026-33032 (CVSS score: 9.8), an ..
---------------------------------------------
https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html
∗∗∗ Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft havent warned users ∗∗∗
---------------------------------------------
Researchers who found the flaws scored beer money bounties and warn the problem is probably pervasive Exclusive Security researchers hijacked three popular AI agents that integrate with GitHub Actions by using a new type of prompt injection attack to steal API keys and access tokens, and the vendors who run agents didn’t disclose the problem.
---------------------------------------------
https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacke…
∗∗∗ UK told its Big Tech habit is now a national security risk ∗∗∗
---------------------------------------------
Open Rights Group says years of reliance on US giants have left Britain exposed Britain has spent years wiring its public sector into US Big Tech, and a new report says that dependence could quickly become a national security headache.
---------------------------------------------
https://www.theregister.com/2026/04/15/uk_big_tech_dependence/
∗∗∗ Ancient Excel bug comes out of retirement for active attacks ∗∗∗
---------------------------------------------
Vuln old enough to drive lands on CISAs exploited list While Microsoft was rolling out its bumper Patch Tuesday updates this week, US cybersecurity agency CISA was readying an alert about a 17-year-old critical Excel flaw now under exploit.
---------------------------------------------
https://www.theregister.com/2026/04/15/excel_exploit/
∗∗∗ Fortinet stopft 18 Sicherheitslecks ∗∗∗
---------------------------------------------
Insgesamt 18 Sicherheitsnotizen hat Fortinet in der Nacht zum Mittwoch veröffentlicht. Sie behandeln teils kritische Lücken.
---------------------------------------------
https://www.heise.de/news/Fortinet-stopft-18-Sicherheitslecks-11257883.html
∗∗∗ Booking.com: Unbefugte Zugriffe von Kriminellen entdeckt ∗∗∗
---------------------------------------------
Booking.com gibt unbefugte Fremdzugriffe auf Buchungsinformationen zu. Betroffene Kunden werden informiert, ihre PINs aktualisiert.
---------------------------------------------
https://www.heise.de/news/Booking-com-Unbefugte-Zugriffe-von-Kriminellen-en…
∗∗∗ Microsoft Office 2021: Support endet am 13. Oktober 2026 ∗∗∗
---------------------------------------------
Microsoft erinnert an das Support-Ende für Office 2021 am 13. Oktober 2026. Es gibt keine erweiterten Sicherheitsupdates (ESU).
---------------------------------------------
https://www.heise.de/news/Microsoft-Office-2021-Support-endet-am-13-Oktober…
∗∗∗ April Patch Tuesday fixes two zero-days, including one under active attack ∗∗∗
---------------------------------------------
This month’s Patch Tuesday addresses 167 vulnerabilities, including two zero-days that could lead to system compromise, data exposure, and privilege escalation.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/04/april-patch-tuesday-fixes-tw…
∗∗∗ Sweden says pro-Russian hackers attempted to breach thermal power plant ∗∗∗
---------------------------------------------
A suspected pro-Russian hacker group attempted to disrupt operations at a thermal power plant in western Sweden last year, a Swedish defense official said.
---------------------------------------------
https://therecord.media/sweden-hackers-russia-power-plant
∗∗∗ The n8n n8mare: How threat actors are misusing AI workflow automation ∗∗∗
---------------------------------------------
Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026.
---------------------------------------------
https://blog.talosintelligence.com/the-n8n-n8mare/
∗∗∗ wolfSSL Vulnerability Hits IoT, Routers and Military Systems, Update to 5.9.1 Now ∗∗∗
---------------------------------------------
Critical wolfSSL flaw CVE-2026-5194 allows digital ID forgery across billions of devices, update to version 5.9.1 to fix the issue and reduce risk.
---------------------------------------------
https://hackread.com/wolfssl-vulnerability-iot-routers-military-systems/
∗∗∗ Adobe-Patchday: Kritische Schadcode-Lücken bedrohen Photoshop & Co. ∗∗∗
---------------------------------------------
Wichtige Sicherheitsupdates schließen Schwachstellen in Anwendungen von Adobe. Weil viele Lücken kritisch sind, sollten Admins zeitnah handeln.
---------------------------------------------
https://heise.de/-11257985
∗∗∗ How to Harden GitHub Actions: An Updated Guide ∗∗∗
---------------------------------------------
Build resilient GitHub Actions workflows with lessons from recent attacks like TeamPCP and Axios.
---------------------------------------------
https://www.wiz.io/blog/github-actions-security-guide
=====================
= Vulnerabilities =
=====================
∗∗∗ Zugänglicher Privater Schlüssel eines X.509 Zertifikats in SAP HANA Cockpit & SAP HANA Database Explorer ∗∗∗
---------------------------------------------
https://sec-consult.com/de/vulnerability-lab/advisory/zugaenglicher-private…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 13-04-2026 18:00 − Dienstag 14-04-2026 18:00
Handler: Felician Fuchs
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Große Gym-Kette: Cyberangriff auf Basic-Fit betrifft eine Million Mitglieder ∗∗∗
---------------------------------------------
Ein unbekannter Angreifer ist in die IT von Basic-Fit eingedrungen und hat zahlreiche persönliche Daten von Mitgliedern aus ganz Europa abgerufen.
---------------------------------------------
https://www.golem.de/news/grosse-gym-kette-cyberangriff-auf-basic-fit-betri…
∗∗∗ ASFINAG-Phishing: Über eine Fake-Mail an die Kreditkartendaten ∗∗∗
---------------------------------------------
Erwischt beim Fahren ohne Vignette? Mit der Zahlung einer Ersatzmaut in Höhe von 12,36 Euro ist die Angelegenheit aus der Welt geschafft? Was auf den ersten Blick aussieht wie eine echte Benachrichtigung der ASFINAG, ist in Wahrheit eine neue Phishing-Welle.
---------------------------------------------
https://www.watchlist-internet.at/news/asfinag-phishing-mail-kreditkartenda…
∗∗∗ The AI-Assisted Breach of Mexicos Government Infrastructure ∗∗∗
---------------------------------------------
In February, we published our initial findings on the AI-assisted breach of Mexico's government infrastructure, warning of the elevated risk that AI-powered threat actors now pose. A single operator used AI to breach nine Mexican government organizations and exfiltrate hundreds of millions of citizen records. Today, we release the full technical report.
---------------------------------------------
https://gambit.security/blog-post/a-single-operator-two-ai-platforms-nine-g…
∗∗∗ The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program ∗∗∗
---------------------------------------------
A briefing for security leaders on how AI-driven vulnerability discovery is reshaping the defender timeline, the operating model of vulnerability management, and the minimum actions required now.
---------------------------------------------
https://labs.cloudsecurityalliance.org/mythos-ciso/
∗∗∗ 108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure ∗∗∗
---------------------------------------------
Sockets Threat Research Team identified 108 malicious Chrome extensions operating as a coordinated campaign under a shared C2 infrastructure at cloudapi[.]stream. The extensions are published under five distinct publisher identities (Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt) and collectively account for approximately 20k Chrome Web Store installs. All 108 route stolen credentials, user identities, and browsing data to servers controlled by the same operator.
---------------------------------------------
https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-s…
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical flaw in wolfSSL library enables forged certificate use ∗∗∗
---------------------------------------------
A critical vulnerability in the wolfSSL SSL/TLS library can weaken security via improper verification of the hash algorithm or its size when checking Elliptic Curve Digital Signature Algorithm (ECDSA) signatures.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-flaw-in-wolfssl-lib…
∗∗∗ SAP-Patchday: Eine kritische SQL-Injection-Lücke – und 18 weitere ∗∗∗
---------------------------------------------
Am April-Patchday behandelt SAP Schwachstellen mit 19 Sicherheitsnotizen. Eine kritische erlaubt das Einschleusen von SQL-Befehlen.
---------------------------------------------
https://www.heise.de/news/SAP-Patchday-Eine-kritische-SQL-Injection-Luecke-…
∗∗∗ Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin ∗∗∗
---------------------------------------------
Considering this vulnerability is under active attack, we urge users to ensure their sites are updated with the latest patched version of Kali Forms, version 2.4.10 at the time of this writing, as soon as possible.
---------------------------------------------
https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critic…
∗∗∗ Fortninet: OS Command Injection through API endpoint ∗∗∗
---------------------------------------------
CVSSv3 Score: 9.1 An Improper Neutralization of Special Elements used in an OS Command (OS command injection) vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-100
∗∗∗ Fortninet: SQL Injection via API ∗∗∗
---------------------------------------------
CVSSv3 Score: 7.9 An improper neutralization of special elements used in an SQL command (SQL Injection) vulnerability [CWE-89] in FortiDDoS-F may allow an authenticated attacker to run arbitrary SQL queries on the database by sending crafted HTTP requests.
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-119
∗∗∗ Fortninet: Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox ∗∗∗
---------------------------------------------
CVSSv3 Score: 9.1 A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-112
∗∗∗ April 2026 Security Update ∗∗∗
---------------------------------------------
Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. [..] To that end, today Ivanti is disclosing vulnerabilities in Ivanti Neurons for ITSM (on-premises and cloud).
---------------------------------------------
https://www.ivanti.com/blog/april-2026-security-update
∗∗∗ Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them ∗∗∗
---------------------------------------------
Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into something malicious. It happened again. This time at a much larger scale.
---------------------------------------------
https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backd…
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1067595/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/