Tageszusammenfassung - 07.09.2026

End-of-Day report

Timeframe: Freitag 04-09-2026 18:00 - Montag 07-09-2026 18:00 Handler: Alexander Riepl Co-Handler: n/a

News

Attackers conceal phishing lures using invisible Unicode characters

Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.

https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.

https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/

Shadowserver 2025: Highlights of the Year in Review

A review of Shadowserver-s 21st year as the world-s largest provider of free, timely, actionable, daily cyber threat intelligence. Covering the latest improvements in our public benefit services, responses to emerging cyber threats, and detection and reporting of the latest vulnerabilities to National CSIRTs and system defenders ..

https://www.shadowserver.org/news/shadowserver-2025-highlights-of-the-year-in-review/

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Every on-premises N-central build below 2026.3.1.14 - including servers updated to Hotfix 3 a day earlier - needs Hotfix 4. N-ables incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a ..

https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html

Peers ask why UK cyber bill leaves execs off the personal liability hook

Ministers say £17M corporate fines and forthcoming board-level governance rules provide sufficient accountability

https://www.theregister.com/security/2026/09/07/peers-ask-why-uk-cyber-bill-leaves-execs-off-the-personal-liability-hook/5294586

Hackers drain $320M in Bitcoin from Liquid Network, claim theyre the good guys

Self-described white hats promise to return most of the 4,000 BTC once the vulnerability is fixed

https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770

Microsoft bremst alte Exchange-Server aus

Microsoft verschärft die Regeln für alte Exchange-Server: In Hybridumgebungen drohen Drosselung und blockierte E-Mails.

https://www.heise.de/news/Alte-Exchange-Server-riskieren-Mailblockaden-11443696.html

Zero-Day-Lücke StyleSmuggler in Magento und Adobe Commerce wird aktiv ausgenutzt

Onlineshops auf Basis von Magento und Adobe Commerce sind offenbar aufgrund einer ungepatchten Sicherheitslücke namens StyleSmuggler angreifbar.

https://www.heise.de/news/Zero-Day-Luecke-StyleSmuggler-in-Magento-und-Adobe-Commerce-wird-aktiv-ausgenutzt-11444217.html

Gefahr für die nationale Sicherheit: Berliner Datenleck schlägt hohe Wellen

Nach dem Darknet-Leak streiten Bezirke über Forensik-Software von Crowdstrike. Die Datenschutzbeauftragte warnt und gibt Verhaltensregeln für Betroffene heraus.

https://www.heise.de/news/Gefahr-fuer-die-nationale-Sicherheit-Berliner-Datenleck-schlaegt-hohe-Wellen-11444301.html

Steuerausgleich da? Vorsicht vor gefälschten Finanzamt-Mails

-Ihr Steuerausgleich ist da!" Eine solche Nachricht klingt zunächst vielversprechend. Wer derzeit eine solche E-Mail erhält, sollte allerdings genau hinsehen. Denn dahinter könnten Kriminelle stecken, die an sensible Daten gelangen wollen.

https://www.watchlist-internet.at/news/steuerausgleich-gefaelschten-mails/

OpenAI verheimlichte Angriff von tausenden KI-Agenten auf in Österreich betriebenes Wiki

Das DseWiki war bereits im Mai 2026 übernommen worden. Nun verspricht OpenAI neue Regeln für Umgang mit solchen Vorfällen

https://www.derstandard.at/story/3000000338604/openai-verheimlichte-angriff-von-tausenden-ki-agenten-auf-in-oesterreich-betriebenes-wiki

How a hole in Lenovo-s login system let hackers walk into 5,000 Dropbox accounts

If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed.

https://www.bitdefender.com/en-us/blog/hotforsecurity/lenovo-login-system-hackers-dropbox

Angriffe gegen Mikrotik-Router ("MikroTrick")

Laut einer Warnung von CERT Polska nutzen Angreifer:innen aktuell großflächig Sicherheitslücken in Geräten des Herstellers Mikrotik aus um die Kontrolle über verwundbare Geräte zu erlangen. Betroffen sind Versionen vor 7.25beta3, 7.24.2, 7.23.4, 6.49.21. Laut der Shadowserver Foundation sind weltweit über 100.000 Mikrotik-Systeme direkt aus dem Internet erreichbar. Systemadministrator:innen sind dringend dazu angehalten die zur Verfügung ..

https://www.cert.at/de/aktuelles/2026/9/angriffe-gegen-mikrotik-router-mikrotrick

The hidden risks of shadow AI

Understanding why staff use unapproved AI tools is key to managing the security challenges they can create.

https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai

No Hacking Required: The Manchester Airports Group Data Breach

On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and passport control, along with airport WiFi sign-ups across Manchester, Stansted and East Midlands. Roughly 8.8 million

https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach/

Have the frontier labs mixed up AI safety and security?

The highly publicised sandbox agent escapes have certainly made news, and I wrote about the issues with sandboxing agents back in January - though I certainly didn't foresee they would escape the frontier labs. I assumed the real risk was poorly configured sandboxes for end users, so I was surprised to see this happening at the frontier labs. I think it might tell us something about the security philosophy of these organisations.

https://martinalderson.com/posts/ai-safety-vs-security/

Vulnerabilities

Security updates 1.6.19 and 1.7.4 released

We just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail.They both contain fixes for recently reported security vulnerabilities.Security fixes Fix CSS declaration smuggling via un-encoded ampersand emission, reported by Zach Hanley of Horizon3.ai Fix CSS property injection via body background attribute, reported by zenithhostingevan ..

https://roundcube.net/news/2026/09/06/security-updates-1.6.19-and-1.7.4