Tageszusammenfassung - 16.09.2026

End-of-Day report

Timeframe: Dienstag 15-09-2026 18:00 - Mittwoch 16-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Account-Takeover: Tanz-Voting-Masche hat wieder WhatsApp-Konten im Visier

Eine aus dem Vorjahr bekannte Falle wird aktuell verstärkt ausgespielt. Kriminelle versenden über gehackte WhatsApp-Accounts Nachrichten, die zur Teilnahme an einem Voting drängen. Ziel ist die Übernahme weiterer Konten, die später für den Versand verschiedenster Phishing-Messages missbraucht werden. Was ein Zahnarztbesuch mit der ganzen Sache zu tun hat, verrät der Artikel.

https://www.watchlist-internet.at/news/account-takeover-whatsapp-konten/

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin-s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites. After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too.

https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/

Windows Server 2022 reaches end of mainstream support next month

Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031.

https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-next-month/

Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works

A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.

https://www.wired.com/story/hackers-flock-camera-data-shows-how-system-works/

Atomic macOS (AMOS) Stealer Activity

This article reviewed an Atomic stealer malware infection from early August 2026. The resulting analysis includes behavior from the infected macOS host, malware samples, post-infection artifacts and traffic patterns that indicate the types of information collected by this malware.

https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/

Securing the unpatchable in an age of AI-driven vulnerabilities

Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.

https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/

Angreifer attackieren Acronis Backup für cPanel/WHM und Plesk

Aufgrund von laufenden Attacken müssen Admins Acronis Backup für cPanel/WHM und Plesk aktualisieren.

https://heise.de/-11454681

Vulnerabilities

Cisco Security Advisories 2026 Sep 16

Cisco has release 13 new CRITICAL security advisories for Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard.

https://sec.cloudapps.cisco.com/security/center/publicationListing.x

Oracle Critical Security Patch Update Advisory - September 2026

This Critical Security Patch Update contains 673 new security patches across the product families listed below.

https://www.oracle.com/security-alerts/cspusep2026.html

Google Pixel owners urged to patch actively exploited modem flaw

Google-s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.

https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw

LWN: Security updates for Wednesday

https://lwn.net/Articles/1094720/