Tageszusammenfassung - 03.09.2026

End-of-Day report

Timeframe: Mittwoch 02-09-2026 18:00 - Donnerstag 03-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.

https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.

https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," [..] The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with Crowdstrike Falcon.

https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html

This Is Flock-s AI Search Tool for Cops

WIRED rebuilt Flock-s latest search tool from code the company sends to a police officer-s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description. [..] Police officers have already used Flock-s software to track people for reasons unrelated to police work. At least 50 officers in the US have recently been charged with or accused of misusing license plate readers, according to The Washington Post.

https://www.wired.com/story/flock-ai-search-user-interface/

WhatsApp-Sicherheitslücke: Zugriff auf Fotos bei gesperrtem Android-Handy

Die WhatsApp-App unter Android hat offenbar eine Schwachstelle. Unbefugte Nutzerinnen und Nutzer können auf einigen Geräten bei einem eingehenden Videoanruf im gesperrten Zustand auf private Fotoordner zugreifen. Meta hat nach eigenen Angaben inzwischen begonnen, einen Fix zu verteilen. Bis dieser flächendeckend ankommt, gibt es eine Übergangslösung.

https://www.heise.de/news/WhatsApp-Sicherheitsluecke-Zugriff-auf-Fotos-bei-gesperrtem-Android-Handy-11439291.html

WordPress All-in-One WP Migration: Angreifer können Admin-Falle auslegen

Das WordPress-Plug-in All-in-One WP Migration and Backup ist verwundbar und Angreifer können im schlimmsten Fall die volle Kontrolle über mit dem CMS erstellte Websites erlangen. [..] Die Sicherheitsforscher geben an, dass die Entwickler von All-in-One WP Migration and Backup Mitte August von der Schwachstelle erfahren haben. Der Sicherheitspatch war fünf Tage später fertig und steht seit dem 20. August 2026 zum Download bereit.

https://www.heise.de/news/WordPress-All-in-One-WP-Migration-Angreifer-koennen-Admin-Falle-auslegen-11439787.html

Why your data is safer than you think on public Wi-Fi

The coffee shop hacker Public Wi-Fi has acquired a slightly theatrical reputation. Join the network in a coffee shop, we are told, and a hacker in the corner can immediately steal your passwords and empty your bank account. It makes for good VPN advertising. It is not a particularly accurate picture of how the modern web works.

https://www.pentestpartners.com/security-blog/why-your-data-is-safer-than-you-think-on-public-wi-fi/

Analyse: Umfassendes Fake-Netzwerk aus Insolvenzverwaltern, IT-Anbietern, Unternehmensberatern und Zeitungen

Um den Anschein von Seriosität zu verstärken, bauen Kriminelle umfangreiche Onlinemagazine. In der dortigen Flut an angeblich realen Geschichten platzieren sie Artikel, die über vermeintlich seriöse Insolvenzverwalter, IT-Anbietern und Unternehmensberater berichten. Die gesamte Konstruktion ist auf Vorschussbetrug und das Sammeln von Daten ausgelegt.

https://www.watchlist-internet.at/news/analyse-umfassendes-fake-netzwerk/

Chamilo LMS... Its raining 0days, hallelujah, its raining 0days

Chamilo is an open source Learning Management System (LMS) widely deployed in schools and enterprises around the world. In this blogpost we explain how we were able to identify multiple vulnerabilities including a full unauthenticated Remote Code Execution chain in the latest version.

http://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-raining-0days.html

Vulnerabilities

VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)

VMware Workstation and Fusion contain an integer-overflow vulnerability. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. CVE-2026-59346, CVE-2026-59347

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288

HPE: HPESBNW05133 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer

Remote: Access Restriction Bypass, Authentication Bypass, Escalation of Privilege

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US

HPE: HPESBNW05134 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)

Local: Access Restriction Bypass

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv

Drupal Security Advisories 2026-September-02

https://www.drupal.org/security

LWN: Security updates for Thursday

https://lwn.net/Articles/1092419/