End-of-Day report
Timeframe: Montag 21-09-2026 18:00 - Dienstag 22-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
"Bundesamt für Cybersicherheit" geht mit Oktober an den Start
Leiter Markus Kasinger war zuvor bei Austrian Power Grid. Zu den Aufgaben gehört die Weiterentwicklung der nationalen Cybersicherheitsstrategie.
https://www.derstandard.at/story/3000000340881/bundesamt-fuer-cybersicherheit-geht-mit-oktober-an-den-start
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
Politik: EU-Kommission will Europol-Datenbefugnisse ausweiten
Ein Verordnungsentwurf sieht den Abbau von Schutzmechanismen bei Europol vor, um KI-Systeme anlasslos mit Daten zu speisen.
https://www.golem.de/news/politik-eu-kommission-will-europol-datenbefugnisse-ausweiten-2609-213296.html
Smart-TVs: Youtuber entfernt WLAN-Modul aus neuem LG-TV
Nach Berichten über Spionagefunktionen entfernt ein Youtuber Hardwarekomponenten aus seinem LG OLED G6. Der Fernseher funktioniert weiterhin.
https://www.golem.de/news/smart-tvs-youtuber-entfernt-wlan-modul-aus-neuem-lg-tv-2609-213299.html
Unmasking EvilTokens: Getting to the root of device code phishing
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/
Microsoft wirft SMS-basierte Authentifizierung aus Entra ID raus
Microsofts Identitätsverwaltung und Login-Lösung Entra ID erlaubt die Authentifizierung mit SMS. Das soll bald ein Ende haben.
https://heise.de/-11461055
Vulnerabilities
Sicherheitsupdates: Click2Shell-Lücke zum Kompromittieren von WordPress-Websites
Aufgrund mehrerer Sicherheitslücken raten die WordPress-Entwickler zu einem zügigen Update. Bislang gibt es keine Hinweise auf Attacken.
https://heise.de/-11460973
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow
vulnerability that could result in arbitrary operating system (OS) command execution.
https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed. As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July.
https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
LWN Security updates for Tuesday
https://lwn.net/Articles/1096022/