Tageszusammenfassung - 17.09.2026

End-of-Day report

Timeframe: Mittwoch 16-09-2026 18:00 - Donnerstag 17-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Fake-Webseiten: Kriminelle kopieren den Online-Auftritt echter Hotels

Die Absicht ist klar, die momentane Häufung hingegen ein wenig ungewöhnlich. In den letzten Wochen wurden besonders viele Fake-Webseiten gemeldet, die gezielt den Onlineauftritt von (Familien-)Hotels kopieren. Kriminelle wollen damit vorrangig an Kontaktdaten ihrer Opfer gelangen.

https://www.watchlist-internet.at/news/fake-webseiten-echte-hotels/

Cisco warns of max severity ISE zero-day exploited in attacks

The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration. [..] Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.

https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/

EU Plans -Article 4--Style Security Protocol for Cyberattacks and Hybrid Threats

European Commission President Ursula von der Leyen has proposed an Emergency Security Protocol that would allow any European Union member state to trigger a coordinated response to security incidents including cyberattacks, sabotage and drone incursions. [..] Under the proposed Emergency Security Protocol, a single member state could trigger the mechanism, prompting all 27 EU governments to convene. The proposed framework would be designed to coordinate a European response, deter further escalation and mitigate the consequences of an incident.

https://thecyberexpress.com/eu-emergency-security-protocol-targets-threats/

OpenAI führt Framework zur Meldung von KI-Sicherheitsvorfällen ein

OpenAI will dem Fehlverhalten seiner eigenen KI-Modelle systematischer auf den Grund gehen. Hierzu wurde jetzt ein neues Framework vorgestellt, das solche Fälle systematisch verfolgen, untersuchen und offenlegen soll. Bislang hatte das US-Unternehmen solche Sicherheitsvorfälle nur auf Ad-hoc-Basis bekanntgegeben. Im dazugehörigen Blogpost bekräftigt OpenAI zugleich Forderungen nach einer Verlangsamung der KI-Weiterentwicklung, wie sie zuletzt auch vom Rivalen Anthropic erhoben wurden, um den Sicherheitsrisiken Rechnung zu tragen, die aus den Fortschritten in der KI erwachsen.

https://www.heise.de/news/OpenAI-fuehrt-Framework-zur-Meldung-von-KI-Sicherheitsvorfaellen-ein-11456751.html

The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper. This report details the new crimeware campaign that began with the mass infection of users via compromised torrent tracker file storage. [..] Further analysis of the attack revealed that the threat actors did not compromise the torrent trackers themselves. Instead, they compromised a widely used public repository of torrent files - itorrents[.]org.

https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/

Revolut phishing texts appear days after data breach

Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen-s infrastructure and evidence of Qilins AI use

In Japan, The Gentlemen was the most active ransomware group in the first half of 2026. Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total - an increase of around 13% from the previous year.

https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/

GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk

GitHub has added cache-mode to GitHub Actions, a new setting that limits how workflows and jobs can access the Actions cache. It targets cache poisoning, the technique attackers used to compromise the Ultralytics PyPI package in 2024 and the TanStack npm packages in May 2026.

https://socket.dev/blog/github-actions-cache-mode

Vulnerabilities

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. CVE-2026-81642

https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature.

https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

https://www.drupal.org/sa-core-2026-013

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2022-005

https://www.drupal.org/sa-core-2022-005

LWN: Security updates for Thursday

https://lwn.net/Articles/1094962/