===================== = End-of-Day report = =====================
Timeframe: Mittwoch 07-10-2026 18:00 − Donnerstag 08-10-2026 18:00 Handler: Guenes Holler Co-Handler: n/a
===================== = News = =====================
∗∗∗ Pensionsleistung genehmigt: 723-Euro-Versprechen ist Phishing ∗∗∗ --------------------------------------------- Betrügerische Nachrichten im Namen der Pensionsversicherung gab es schon vor einiger Zeit per SMS, jetzt landen sie auch im E-Mail-Postfach. Die Masche: Eine angebliche Auszahlung soll Empfänger:innen zur Preisgabe ihrer Bankdaten bringen. --------------------------------------------- https://www.watchlist-internet.at/news/pensionsleistung-genehmigt-723-euro/
∗∗∗ Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia ∗∗∗ --------------------------------------------- Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. --------------------------------------------- https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html
∗∗∗ Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers ∗∗∗ --------------------------------------------- Quoth the LLM, More and more. --------------------------------------------- https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-securit...
∗∗∗ 16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials ∗∗∗ --------------------------------------------- Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces. --------------------------------------------- https://socket.dev/blog/firefox-crypto-wallet-stealers?utm_medium=feed
∗∗∗ TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack ∗∗∗ --------------------------------------------- Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware. --------------------------------------------- https://socket.dev/blog/tensorlake-compromise?utm_medium=feed
∗∗∗ Chinesische Wechselrichter: Nur ein Hack bis zum Blackout ∗∗∗ --------------------------------------------- 250.000 Solaranlagen in Deutschland nutzen Wechselrichter mit einer kritischen Sicherheitslücke. Ein Kollaps des Stromnetzes wäre einfach. --------------------------------------------- https://www.golem.de/news/chinesische-wechselrichter-nur-ein-hack-bis-zum-bl...
∗∗∗ Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely ∗∗∗ --------------------------------------------- A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. --------------------------------------------- https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
===================== = Vulnerabilities = =====================
∗∗∗ Cisco warns of critical flaws allowing Nexus switch takeover ∗∗∗ --------------------------------------------- Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. --------------------------------------------- https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws...
∗∗∗ Veeam stopft Schadcode-Lücke in Backup & Replication ∗∗∗ --------------------------------------------- Veeam hat Backup & Replication aktualisiert und dabei vier Sicherheitslücken geschlossen. Schmuggeln von Schadcode auf den Server ist möglich. --------------------------------------------- https://www.heise.de/news/Veeam-stopft-Schadcode-Luecke-in-Backup-Replicatio...
∗∗∗ Microsoft, Adobe, Apple, and Foxit vulnerabilities ∗∗∗ --------------------------------------------- Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. --------------------------------------------- https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabi...
∗∗∗ LWN Security updates for Thursday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1099388/
∗∗∗ Zahlreiche kritische Schwachstellen in mehreren TP-Link Geräteserien ∗∗∗ --------------------------------------------- https://sec-consult.com/de/vulnerability-lab/advisory/zahlreiche-kritische-s...