===================== = End-of-Day report = =====================
Timeframe: Dienstag 22-09-2026 18:00 − Mittwoch 23-09-2026 18:00 Handler: Guenes Holler Co-Handler: n/a
===================== = News = =====================
∗∗∗ Ab 1.10: Meldepflicht für IT-Vorfälle in Österreich ∗∗∗ --------------------------------------------- Die NIS-2-Richtlinie beschert Österreich Registrierungspflichten für Unternehmen und Behörden. Diese erhalten Zuwachs: Das neue Bundesamt für Cybersicherheit. --------------------------------------------- https://www.heise.de/news/Ab-1-10-Meldepflicht-fuer-IT-Vorfaelle-in-Oesterre...
∗∗∗ Gefälschter FinanzOnline-Mail: 3.612 Euro Steuererstattung versprochen ∗∗∗ --------------------------------------------- Mit einer neuen Variante des bekannten FinanzOnline-Phishings versuchen Kriminelle derzeit, an Bankdaten von Österreicher:innen zu gelangen. In einer gefälschten E-Mail wird eine Steuererstattung von 3.612 Euro versprochen. --------------------------------------------- https://www.watchlist-internet.at/news/gefaelschter-finanzonline-mail/
∗∗∗ Hacker dringen in Systeme von Fresenius Medical Care ein ∗∗∗ --------------------------------------------- Medizinische Geräte, Patientenversorgung, Produktion und laufender Geschäftsbetrieb sollen laut Konzern nicht beeinträchtigt sein. --------------------------------------------- https://www.derstandard.at/story/3000000340976/hacker-dringen-in-systeme-von...
∗∗∗ Microsoft: September Windows updates break Always On VPN connections ∗∗∗ --------------------------------------------- Microsoft has notified IT administrators that users may experience Always On VPN connection issues after installing the September 2026 Windows 11 security updates. --------------------------------------------- https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-win...
∗∗∗ Absturzgefahr: Exploit lässt Angreifer DJI-Drohnen mitten im Flug kapern ∗∗∗ --------------------------------------------- Mehrere Drohnenmodelle des Herstellers DJI sind anfällig für eine gefährliche Sicherheitslücke, die eine vollständige Kontrollübernahme ermöglicht. Nutzer sollten nach korrigierten Firmware-Versionen Ausschau halten. --------------------------------------------- https://www.golem.de/news/per-bluetooth-exploit-laesst-angreifer-dji-drohnen...
∗∗∗ Macfinger ClickFix campaign, (Tue, Sep 22nd) ∗∗∗ --------------------------------------------- I've found several legitimate websites with injected script for a campaign using the ClickFix social engineering technique. This particular ClickFix campaign was documented earlier this month on the Ransom-ISAC Blog, but it doesn't appear to have a nickname yet. Since this campaign is targeting macOS environments through a fingerprinting process, I'm calling it the "Macfinger ClickFix" campaign. No, this is not related to the MacFinger utility from decades ago. Instead, think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore. --------------------------------------------- https://isc.sans.edu/diary/rss/33360
∗∗∗ Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape ∗∗∗ --------------------------------------------- A use-after-free in the Linux kernels AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. --------------------------------------------- https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html
∗∗∗ Recent Increase of Hybrid Attacks Against Defense Sector in Europe ∗∗∗ --------------------------------------------- Recently, a wave of sabotage attacks has been reported in Europe. In most cases Russia is suspected to be responsible. These events follow a broader pattern of hybrid activity directed at European infrastructure, logistics networks, and organizations supporting Ukraine. --------------------------------------------- https://www.truesec.com/hub/blog/recent-increase-of-hybrid-attacks-against-d...
∗∗∗ Iranian Cyber Espionage Campaign ∗∗∗ --------------------------------------------- An Iranian threat actor is conducting a cyber espionage campaign targeting Iranian nationals abroad. The attacker reaches out to the victim on various messaging apps, like Telegram or Whatsapp. The actor often claims to be an individual previously known to the target or technical support from the social messaging platform. --------------------------------------------- https://www.truesec.com/hub/blog/iranian-cyber-espionage-campaign
===================== = Vulnerabilities = =====================
∗∗∗ Cyberangriffe auf F5 BIG-IP, Check Point Security und Arista VeloCloud ∗∗∗ --------------------------------------------- IT-Verantwortliche müssen rasch handeln, um bereitgestellte Aktualisierungen zu installieren. Mehrere IT-Sicherheitsbehörden warnen vor derzeit laufenden Angriffen auf Sicherheitslücken in F5 BIG-IP, Check Point Security Gateway und Management sowie Arista VeloCloud Orchestrator On-Premise. --------------------------------------------- https://heise.de/-11462590
∗∗∗ Patchday: Adobe Connect ist unter Android, macOS und Windows verwundbar ∗∗∗ --------------------------------------------- Es sind wichtige Sicherheitsupdates für verschiedene Adobe-Anwendungen erschienen. --------------------------------------------- https://heise.de/-11462802
∗∗∗ NetBSD 10.2 stopft einige Sicherheitslücken ∗∗∗ --------------------------------------------- NetBSD ist jüngst als Point-Release 10.2 erschienen. Die Entwickler schließen damit einige Sicherheitslücken. --------------------------------------------- https://heise.de/-11463028
∗∗∗ Gleich noch ein Sicherheitsupdate für WordPress ∗∗∗ --------------------------------------------- Angreifer können WordPress dazu bringen, nicht vorgesehene .php-Dateien aufzurufen. Das kann zur Ausführung von Code führen. --------------------------------------------- https://heise.de/-11462385
∗∗∗ Ubiquiti schließt Denial-of-Service-Lücken in Firewalls und Gateways ∗∗∗ --------------------------------------------- In UniFi-Firewalls und -Gateways klaffen hochriskante Denial-of-Service-Lücken. Aktualisierte Firmware stopft die Lecks. --------------------------------------------- https://heise.de/-11463176
∗∗∗ LWN Security updates for Wednesday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1096191/