Tageszusammenfassung - 22.09.2026

End-of-Day report

Timeframe: Montag 21-09-2026 18:00 - Dienstag 22-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

"Bundesamt für Cybersicherheit" geht mit Oktober an den Start

Leiter Markus Kasinger war zuvor bei Austrian Power Grid. Zu den Aufgaben gehört die Weiterentwicklung der nationalen Cybersicherheitsstrategie.

https://www.derstandard.at/story/3000000340881/bundesamt-fuer-cybersicherheit-geht-mit-oktober-an-den-start

New Windows Defender zero-day blocks Microsoft antivirus updates

Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.

https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/

Politik: EU-Kommission will Europol-Datenbefugnisse ausweiten

Ein Verordnungsentwurf sieht den Abbau von Schutzmechanismen bei Europol vor, um KI-Systeme anlasslos mit Daten zu speisen.

https://www.golem.de/news/politik-eu-kommission-will-europol-datenbefugnisse-ausweiten-2609-213296.html

Smart-TVs: Youtuber entfernt WLAN-Modul aus neuem LG-TV

Nach Berichten über Spionagefunktionen entfernt ein Youtuber Hardwarekomponenten aus seinem LG OLED G6. Der Fernseher funktioniert weiterhin.

https://www.golem.de/news/smart-tvs-youtuber-entfernt-wlan-modul-aus-neuem-lg-tv-2609-213299.html

Unmasking EvilTokens: Getting to the root of device code phishing

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.

https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/

Microsoft wirft SMS-basierte Authentifizierung aus Entra ID raus

Microsofts Identitätsverwaltung und Login-Lösung Entra ID erlaubt die Authentifizierung mit SMS. Das soll bald ein Ende haben.

https://heise.de/-11461055

Vulnerabilities

Sicherheitsupdates: Click2Shell-Lücke zum Kompromittieren von WordPress-Websites

Aufgrund mehrerer Sicherheitslücken raten die WordPress-Entwickler zu einem zügigen Update. Bislang gibt es keine Hinweise auf Attacken.

https://heise.de/-11460973

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution.

https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.

https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed. As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July.

https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html

LWN Security updates for Tuesday

https://lwn.net/Articles/1096022/