End-of-Day report
Timeframe: Dienstag 01-09-2026 18:00 - Mittwoch 02-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
News
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.
https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/
Bei Sandboxing-Tests: KI-Agent bricht mehrfach aus VM aus
Ein Forscher hat getestet, ob sich moderne KI-Modelle mit Virtualisierung sinnvoll isolieren lassen. Die KI ist mehrfach aus einer VM entkommen. [..] Der Forscher hatte die KI zwar explizit dazu angewiesen aus der VM auszubrechen, jedoch sind entsprechende Ausbrüche auch in anderen Situationen denkbar. [..] Zudem rät Dinaburg, für die Virtualisierung auf minimalistische Lösungen umzusteigen, die eine geringere Angriffsfläche bieten.
https://www.golem.de/news/bei-sandboxing-tests-ki-agent-bricht-mehrfach-aus-vm-aus-2608-212442.html
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026.
https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html
OpenAI Is About to Release Its First AI Model With -Critical- Cyber Abilities
The company will give select partners early access to its Astra AI model-so they have time to shore up their defenses.
https://www.wired.com/story/openai-astra-first-ai-model-with-critical-cyber-abilities/
Fremde Dropbox-Konten über Lenovo-ID zugänglich
Eine erstaunliche Sicherheitslücke ist Inhabern von rund 5.000 Dropbox-Konten zum Verhängnis geworden, die auf die Einrichtung von Zwei-Faktor-Authentifizierung (2FA) verzichtet hatten: Unbefugte haben sich mittels frisch angelegter Lenovo-Konten Zugriff verschafft.
https://www.heise.de/news/Fremde-Dropbox-Konten-ueber-Lenovo-ID-zugaenglich-11437565.html
The Vulnpocalypse Is Repricing the Bug Bounty Economy
The shape of the market may be changing, but there's no indication that the bug bounty as we know it is going away. Of the dozen executives, security experts and researchers Dark Reading spoke to, not one believed that the vulnpocalypse was an existential crisis for independent security research. It would challenge the ecosystem, reshape it, and could perhaps act as a reckoning for those companies that release insecure software, but this moment would be more akin to a storm that will pass.
https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy
Passkeys erklärt: wie sicher die Anmeldung ohne Passwort ist
Immer öfter erscheint beim Anmelden auf einer Website ein Fenster mit der Frage, ob Sie einen Passkey erstellen möchten. Viele klicken es weg, weil sie nicht wissen, was das eigentlich ist. Dahinter steckt eine Technologie, die das Potenzial hat, das Anmelden im Internet grundlegend sicherer zu machen.
https:\/\/www.zettasecure.com\/post\/sind-passkeys-sicher
Vulnerabilities
Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar
In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Authentifizierung, die Appliance dazu zu bringen, serverseitig Anfragen an eigentlich nicht erreichbare interne Endpunkte zu senden (Server-Side Request Forgery). Laut SonicWall PSIRT werden die in diesem Advisory beschriebenen Schwachstellen bereits aktiv ausgenutzt. CVE-2026-83548, CVE-2026-83549
https://www.cert.at/de/warnungen/2026/9/erneut-kritische-sicherheitslucken-in-sonicwall-sma1000-series-aktiv-ausgenutzt-updates-verfugbar
Plex: Important Security Update for Plex Media Server v1.43.2 and earlier
We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible. CVEs have been requested and we-ll reply to this thread with more details once they-re published.
https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319
LWN: Security updates for Wednesday
https://lwn.net/Articles/1092149/