End-of-Day report
Timeframe: Mittwoch 23-09-2026 18:00 - Donnerstag 24-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
Theres a new way to break RSA thats faster than anything weve seen before
The world has known for decades that the RSA cryptosystem-s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold. The practical risk is limited, but still significant.
https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/
Hackers now exploit critical Roundcube flaw in code injection attacks
In May, the Roundcube security team patched the flaw (tracked as CVE-2026-48842), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored by you.
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).
https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html
OpenAI-Agent knackt australisches Regierungsportal
Eine KI sollte Gesundheitsstatistiken suchen - und knackte dabei ein australisches Regierungsportal. Die Empörung ist groß.
https://heise.de/-11463920
Bypassing EDR with Local AI
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
https://projectblack.io/blog/bypassing-edr-with-local-ai/
Vulnerabilities
Foxit: Security updates available in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8
Foxit has released Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8, which addresses potential security and stability issues.
https://www.foxit.com/support/security-bulletins.html
Drupal Security Advisories 2026-September-23
Drupal released 36 new security advisories (5x critical).
https://www.drupal.org/security
Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted
In SolarWinds Observability Self-Hosted 2026.2.3 haben die Entwickler eigenen Angaben zufolge zwei Schwachstellen geschlossen (CVE-2026-28324 -kritisch- CVE-2026-28325, -hoch-). In beiden Fällen können Angreifer unter den jeweils genannten Bedingungen ohne Authentifizierung an den Schwachstellen ansetzen und Schadcode ausführen - bei CVE-2026-28324 übers Netz, bei CVE-2026-28325 nur aus einem benachbarten Netzsegment. Die Ursachen unterscheiden sich jedoch: Bei CVE-2026-28324 sind Integritätsprüfungen unzureichend; CVE-2026-28325 betrifft die Verarbeitung nicht vertrauenswürdiger Daten durch Deserialisierung. Hinweise auf laufende Attacken gibt es bislang nicht.
https://heise.de/-11464112
Imprivata Enterprise Access Management (EAM) does not rotate RSA keys
https://kb.cert.org/vuls/id/273940
LWN: Security updates for Thursday
https://lwn.net/Articles/1096407/