Tageszusammenfassung - 02.10.2026

End-of-Day report

Timeframe: Donnerstag 01-10-2026 18:00 - Freitag 02-10-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

Microsoft-s X account hacked in crypto pump-and-dump scheme

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.

https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/

Hackerangriff: Pentagon verliert Daten von mehr als drei Millionen Personen

Unbefugte haben rund neun Monate lang Zugriff auf einen Server mit Personaldaten. Die Daten auf dem Server des Pentagon sind unverschlüsselt.

https://www.golem.de/news/hackerangriff-pentagon-verliert-daten-von-mehr-als-drei-millionen-personen-2610-213641.html

Warlock ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.

https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks

Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)

During a Purple Team engagement, we had to list and rank risky components across the network. One of them caught our attention: Cato Client, a VPN client program. It was installed everywhere. It runs privileged services. It talks to a GUI. It handles network configuration. From an attacker perspective, this is exactly the kind of software you want to understand. However, saying "this looks risky" is not enough. There is nothing better than PoC||GTFO. So the question was simple: can we find a real bug and turn it into something useful? This is how it started.

http://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html

Vulnerabilities

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.

https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/

FortiMail: Angriffe auf Zero-Day-Lücke laufen, Workaround verfügbar

Fortinet warnt vor Angriffen auf eine Zero-Day-Sicherheitslücke in FortiMail. Sie ermöglicht die Übernahme der Geräte aus dem Netz.

https://heise.de/-11473599

LWN Security updates for Friday

https://lwn.net/Articles/1098312/

[R1] Nessus Version 10.12.5 Fixes Multiple Vulnerabilities

https://www.tenable.com/security/tns-2026-26