Tageszusammenfassung - 02.10.2026
End-of-Day report
Timeframe: Donnerstag 01-10-2026 18:00 - Freitag 02-10-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
Microsoft-s X account hacked in crypto pump-and-dump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/
Hackerangriff: Pentagon verliert Daten von mehr als drei Millionen Personen
Unbefugte haben rund neun Monate lang Zugriff auf einen Server mit Personaldaten. Die Daten auf dem Server des Pentagon sind unverschlüsselt.
https://www.golem.de/news/hackerangriff-pentagon-verliert-daten-von-mehr-als-drei-millionen-personen-2610-213641.html
Warlock ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks
Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)
During a Purple Team engagement, we had to list and rank risky components across the network. One of them caught our attention: Cato Client, a VPN client program. It was installed everywhere. It runs privileged services. It talks to a GUI. It handles network configuration. From an attacker perspective, this is exactly the kind of software you want to understand. However, saying "this looks risky" is not enough. There is nothing better than PoC||GTFO. So the question was simple: can we find a real bug and turn it into something useful? This is how it started.
http://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html
Vulnerabilities
Dell asks admins to patch max severity CSM flaws as soon as possible
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.
https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/
FortiMail: Angriffe auf Zero-Day-Lücke laufen, Workaround verfügbar
Fortinet warnt vor Angriffen auf eine Zero-Day-Sicherheitslücke in FortiMail. Sie ermöglicht die Übernahme der Geräte aus dem Netz.
https://heise.de/-11473599
LWN Security updates for Friday
https://lwn.net/Articles/1098312/
[R1] Nessus Version 10.12.5 Fixes Multiple Vulnerabilities
https://www.tenable.com/security/tns-2026-26