Tageszusammenfassung - 01.10.2026

End-of-Day report

Timeframe: Mittwoch 30-09-2026 18:00 - Donnerstag 01-10-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Over 543,000 valid credentials exposed in public GitHub repositories

More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platforms security measures to prevent accidental leaks of sensitive data.

https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/

Revolut zahlt kein Lösegeld: Hackergruppe erpresst Revolut-Kunden direkt

Die Geschichte rund um den Revolut-Hack aus dem vergangenen Monat geht weiter, bei dem Unbefugte an Bankdaten von Kunden gelangt sind. Nachdem die Neobank ein gefordertes Lösegeld von 3 Millionen US-Dollar nicht zahlte, versuchen Kriminelle, die erbeuteten Daten zu Geld zu machen, indem Revolut-Kunden direkt erpresst werden, berichtet unter anderem das Cybergrant-Blog. Nach derzeitigem Kenntnisstand sind 680 Revolut-Kunden von dem Vorfall betroffen.

https://www.golem.de/news/revolut-zahlt-kein-loesegeld-hackergruppe-erpresst-revolut-kunden-direkt-2610-213607.html

From: anyone@icloud.com - Absenderfälschung in Apple iCloud

Eine Fallstudie über die Entdeckung zweier E-Mail-Spoofing-Schwachstellen in Apple iCloud.

https://sec-consult.com/de/blog/detail/from-anyoneicloudcom-absenderfaelschung-in-apple-icloud/

SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor

During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we-ll refer to this family of malware as SC, named after the -SC_- markers found in the injected content.What makes SC worth documenting is how it survives.

https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of-loaders-drop-ins-and-a-blockchain-controlled-backdoor.html

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate.

https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html

NIS2 Registrierung in Österreich. Wie gehe ich richtig vor?

Seit dem 1. Oktober 2026 gelten für viele österreichische Unternehmen neue Vorgaben durch NIS2. Betroffene Unternehmen müssen dann technische und organisatorische Sicherheitsmaßnahmen umsetzen, die Verantwortung der Geschäftsführung beachten und sich beim Bundesamt für Cybersicherheit (BCS) registrieren. Dieser Leitfaden erklärt, wer sich registrieren muss, welche Informationen dafür nötig sind und wie Unternehmen dabei am besten vorgehen.

https://www.zettasecure.com/post/nis2-registrierung-%C3%B6sterreich-anleitung

Zu viele KI-Vorfälle: US-Behörde untersucht Anthropic, METR, OpenAI

Zu häufig richten große Sprachmodelle Schaden an. Daher führt die US-Handelsbehörde FTC eine Untersuchung gegen große KI-Betreiber.

https://heise.de/-11471857

Vulnerabilities

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [..] Successful exploitation can let remote threat actors without privileges gain code execution and take over the targeted EPG appliance by exploiting a chain of path traversal, code injection, and missing authentication in low-complexity attacks that don't require user interaction. CVE-2026-54154

https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/

Vulnerabilities in Zammad during investigation of case DIVD-2026-00014

During the investigation of case DIVD-2026-00014, two new CVEs were identified. CVE-2026-102489 - Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. [..] CVE-2026-102490 - In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root.

https://csirt.divd.nl/cases/DIVD-2026-00015/

WatchGuard schließt teils kritische Lücken in Fireware OS

Das Betriebssystem Fireware OS von WatchGuard weist Sicherheitslücken auf, die Angreifern aus dem Netz unter anderem das Einschleusen und Ausführen von Schadcode oder Denial-of-Service-Attacken ermöglichen. Sie gelten zum größten Teil als hochriskant und in einem Fall sogar als kritisch.

https://www.heise.de/news/WatchGuard-schliesst-teils-kritische-Luecken-in-Fireware-OS-11472101.html

NVIDIA GPU Display Driver - September 2026

https://nvidia.custhelp.com/app/answers/detail/a_id/5861

LWN: Security updates for Thursday

https://lwn.net/Articles/1098067/

Mozilla Foundation Security Advisories September 30, 2026

https://www.mozilla.org/en-US/security/advisories/