===================== = End-of-Day report = =====================
Timeframe: Donnerstag 10-09-2026 18:00 − Freitag 11-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a
===================== = News = =====================
∗∗∗ Gilt ab heute: CRA setzt 24-Stunden-Frist für Sicherheitsmeldungen ∗∗∗ --------------------------------------------- Der Cyber Resilience Act verpflichtet Hersteller von Produkten mit digitalen Elementen zu Mindeststandards für die Cybersicherheit. Betroffen sind nicht nur vernetzte Geräte wie Router oder industrielle Steuerungen, sondern auch Software. Die meisten Anforderungen gelten für Produkte, die ab dem 11. Dezember 2027 neu auf den EU-Markt kommen. Ab heute, also dem 11. September 2026, müssen Hersteller jedoch bereits aktiv ausgenutzte Schwachstellen und schwerwiegende Sicherheitsvorfälle melden. --------------------------------------------- https://heise.de/-11450208
∗∗∗ Enisa: Anthropic öffnet Mythos-Modell für EU-Cyberagentur ∗∗∗ --------------------------------------------- Nach monatelangen Verhandlungen gibt Anthropic der EU-Agentur Enisa Zugang zu seinem KI-Modell Mythos. Doch die neueste Version gibt es nicht. --------------------------------------------- https://www.golem.de/news/enisa-anthropic-oeffnet-mythos-modell-fuer-eu-cybe...
∗∗∗ Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 ∗∗∗ --------------------------------------------- Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control. --------------------------------------------- https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of...
∗∗∗ PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws ∗∗∗ --------------------------------------------- PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. --------------------------------------------- https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
∗∗∗ ClickFix attacks infecting PCs and Macs are going viral ∗∗∗ --------------------------------------------- It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. --------------------------------------------- https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-...
∗∗∗ Multiple crypto companies warn customers of phishing emails after alleged provider breach ∗∗∗ --------------------------------------------- Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use. --------------------------------------------- https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
∗∗∗ Portasplit-Sicherheitslücke: Midea verteilt Updates an Klimageräte ∗∗∗ --------------------------------------------- Midea aktualisiert in den nächsten Wochen automatisch alle PortaSplit-Klimageräte. Der Hersteller reagiert damit auf einen Hinweis von heise security und einem anonymen Whistleblower. Der hatte eine Android-App entwickelt, um ein Sicherheitsproblem zu demonstrieren. Mit ihr ließen sich beliebige Geräte per Bluetooth Low Energy (BLE) fernsteuern – auch gegen den Willen ihrer Besitzer. --------------------------------------------- https://heise.de/-11449892
∗∗∗ Certificate Authority unter Windows mit PowerShell betreiben ∗∗∗ --------------------------------------------- Mit diesem Blog-Post hier demonstriere ich, wie unter Verwendung von Windows 11 Bordmitteln (Powershell, es wird kein OpenSSL benötigt) eine CA erstellt und daraus Code-Signing-Zertifikate, Webserver-Zertifikate ... --------------------------------------------- https://hitco.at/blog/certificate-authority-windows-powershell-ca-smime-code...
∗∗∗ Beliebige Dateien (z.B. 7z, zip, yaml, …) mittels Catalog-Files und PowerShell signieren ∗∗∗ --------------------------------------------- Die Nutzung eines Code-Signing-Zertifikats zur Authenticode-Signatur ist für zahlreiche Datei-Typen die dies unterstützen direkt inline möglich. Als Beispiele seien *.exe, *.dll, *.ps1, … genannt. Dieses kurze How-To beschäftigt sich allerdings mit Datei-Typen, die keine Signatur unterstützen. Beispielsweise ein YAML-Konfigurationsfile im Textformat, oder ZIP-Container sowie 7zip-Containerfiles. --------------------------------------------- https://hitco.at/blog/beliebige-dateien-7z-zip-yaml-mittels-catalogfiles-pow...
∗∗∗ A rant about phishing: Its not the users fault (and not DNS either) ∗∗∗ --------------------------------------------- "For safety, don't click suspicious links" Neither the username, password nor 2FA prompts are hosted on the company's own domain. Combine that with token expiration triggering random authetication pop-ups, it becomes nearly impossible to notice phishing... because the real thing looks identical to a scam [..] An organization MUST use a single, well recognized, root domain. --------------------------------------------- https://maurycyz.com/misc/domains/
===================== = Vulnerabilities = =====================
∗∗∗ ARISTA Security Advisory 0158 ∗∗∗ --------------------------------------------- Both CVE-2026-73456 and CVE-2026-73457 affect Arista EOS-based platforms with gRPC Network Packet Sampling Interface (gNPSI) configured. which is disabled by default. [..] Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. --------------------------------------------- https://www.arista.com/en/support/advisories-notices/security-advisory/24714...
∗∗∗ GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 ∗∗∗ --------------------------------------------- On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE) and Enterprise Edition (EE). [..] For security fixes, the issues detailing each vulnerability are made public on our issue tracker 90 days after the release in which they were patched. --------------------------------------------- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-release...
∗∗∗ Forgejo 16.0.4 has a critical security bug fix (RCE - Remote Code Execution) ∗∗∗ --------------------------------------------- https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-publis...
∗∗∗ LWN: Security updates for Friday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1093765/