End-of-Day report
Timeframe: Montag 07-09-2026 18:00 - Dienstag 08-09-2026 18:00
Handler: Alexander Riepl
Co-Handler: Michael Schlagenhaufer
News
Schwerwiegende Sicherheitslücke in N-able N-central - aktiv ausgenutzt
In N-able N-central, einer Remote-Monitoring- und Management-Plattform, die insbesondere von Managed Service Providern (MSPs) zur Verwaltung von Kund:innenumgebungen eingesetzt wird, wurde eine schwerwiegende Sicherheitslücke entdeckt. Die Schwachstelle, CVE-2026-86218, ist mit einem CVSS-Score von 10.0 bewertet, eine Ausnutzung ermöglicht entfernten, unauthentifizierten Angreifer:innen eine Ausführung von Code auf verwundbaren Systemen.
https://www.cert.at/de/aktuelles/2026/9/schwerwiegende-sicherheitslucke-in-n-able-n-central-aktiv-ausgenutzt
Hackers build AI frameworks for widescale credential theft
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.
https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
Auch im Standby: LG-Fernseher wohl anfällig für weitreichende Spionageangriffe
Dass Smart TVs über Automatic Content Recognition (ACR) etwa zu Werbezwecken permanent die Sehgewohnheiten ihrer Nutzer tracken, ist schon seit Jahren bekannt. [..] Demnach scannen LG-Fernseher neben dem ACR-Tracking ständig im internen Netzwerk nach Smartphones, PCs, Druckern und anderen erreichbaren Endgeräten. Zudem sollen die TV-Geräte permanent Informationen über in Reichweite befindliche WLAN-Netze und deren Standorte und Signalstärken sammeln.
https://www.golem.de/news/auch-im-standby-lg-fernseher-wohl-anfaellig-fuer-weitreichende-spionageangriffe-2609-212761.html
Abo-Falle: Wenn NordicaLab automatisch über PayPal abbucht
-Danke, dass Sie mit PayPal gezahlt haben- - Flattert diese Mitteilung zu einem Zeitpunkt ins Mail-Postfach, an dem garantiert keine Zahlung freigegeben wurde, ist sprichwörtlich Feuer am Dach. Irgendetwas stimmt hier ganz und gar nicht. Was genau, das zeigt ein konkreter Fall aus der Praxis.
https://www.watchlist-internet.at/news/abo-falle-nordicalab/
Führerschein-Scans von Altersüberprüfungs-Dienst landeten über ein Jahr kontinuierlich im Darknet
Wie das Fachmedium Techdirt berichtet, ging vergangene Woche eine Plattform für Identitätsdiebstahl namens Nexus online. Auf der Seite werden mehr als 153 Millionen Scans von Bürgerinnen und Bürgern der USA und Kanada verkauft. Die Betreiber von Nexus behaupten, die Ausweisbilder stammten aus einem aktiven Datenleck bei "einem großen Unternehmen für Identitätsprüfung", zu dessen Kunden mehrere Fortune-500-Unternehmen zählen.
https://www.derstandard.at/story/3000000338691/fuehrerschein-scans-von-altersueberpruefungs-dienst-landeten-ueber-ein-jahr-kontinuierlich-im-darknet
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim-s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker-s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim-s connected Gmail account and relayed it to the attacker.
https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
I-ve factored the RSA keys of a Certificate Authority-from the 90s
I-ve been thinking about the security of RSA lately. RSA-s cryptography relies on the difficulty of factoring a large semiprime number, but what -large- means is an interesting question. The Web PKI deprecated 1024-bit RSA over a decade ago, and while I don-t know of anyone factoring a key of that size, it-s within the realm of possibility for a government or other organization with a large number of computers. Just a few days ago, someone factored the 862-bit RSA-260 key from the RSA factoring challenge.
https://mcpherrin.ca/2026/09/07/rsa.html
Vulnerabilities
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. [..] That only becomes dangerous because of the second flaw. 389 Directory Server has a rule type meant to say "only the authenticated owner of this entry." It compares the client's name against a stored value as plain text, and a client that has not logged in has an empty name, which matches an empty stored value.
https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
Ivanti September 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories: Ivanti Neurons for ITSM, Ivanti Endpoint Manager Mobile (EPMM), Ivanti Sentry
https://www.ivanti.com/blog/september-2026-security-update
SAP Security Patch Day September 2026 | RedRays
SAP Security Patch Day September 2026 brings 20 security notes, four of them HotNews rated up to CVSS 10.0, alongside five High priority issues, ten Medium priority fixes and one Low priority update. They span the NetWeaver stack, SAP S/4HANA, SAPUI5 and several cloud products. This release lands on the network-facing core of NetWeaver.
https://redrays.io/blog/sap-security-patch-day-september-2026/
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
https://kb.cert.org/vuls/id/943094
VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
https://kb.cert.org/vuls/id/718077
TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands
https://news.typo3.com/security/advisory/typo3-core-sa-2026-023
TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard
https://news.typo3.com/security/advisory/typo3-core-sa-2026-022
Xen: XSA-513
https://xenbits.xen.org/xsa/advisory-513.html
Xen: XSA-512
https://xenbits.xen.org/xsa/advisory-512.html
Xen: XSA-511
https://xenbits.xen.org/xsa/advisory-511.html
Xen: XSA-510
https://xenbits.xen.org/xsa/advisory-510.html
Xen: XSA-509
https://xenbits.xen.org/xsa/advisory-509.html
LWN: Security updates for Tuesday
https://lwn.net/Articles/1093144/