Tageszusammenfassung - 11.09.2026

End-of-Day report

Timeframe: Donnerstag 10-09-2026 18:00 - Freitag 11-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Gilt ab heute: CRA setzt 24-Stunden-Frist für Sicherheitsmeldungen

Der Cyber Resilience Act verpflichtet Hersteller von Produkten mit digitalen Elementen zu Mindeststandards für die Cybersicherheit. Betroffen sind nicht nur vernetzte Geräte wie Router oder industrielle Steuerungen, sondern auch Software. Die meisten Anforderungen gelten für Produkte, die ab dem 11. Dezember 2027 neu auf den EU-Markt kommen. Ab heute, also dem 11. September 2026, müssen Hersteller jedoch bereits aktiv ausgenutzte Schwachstellen und schwerwiegende Sicherheitsvorfälle melden.

https://heise.de/-11450208

Enisa: Anthropic öffnet Mythos-Modell für EU-Cyberagentur

Nach monatelangen Verhandlungen gibt Anthropic der EU-Agentur Enisa Zugang zu seinem KI-Modell Mythos. Doch die neueste Version gibt es nicht.

https://www.golem.de/news/enisa-anthropic-oeffnet-mythos-modell-fuer-eu-cyberagentur-2609-212904.html

Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329

Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control.

https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.

https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html

ClickFix attacks infecting PCs and Macs are going viral

It wasn-t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that-s required is a compromised website-a painless enough task-a fake CAPTCHA overlay, and the inclusion of a single terminal command.

https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/

Multiple crypto companies warn customers of phishing emails after alleged provider breach

Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use.

https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders

Portasplit-Sicherheitslücke: Midea verteilt Updates an Klimageräte

Midea aktualisiert in den nächsten Wochen automatisch alle PortaSplit-Klimageräte. Der Hersteller reagiert damit auf einen Hinweis von heise security und einem anonymen Whistleblower. Der hatte eine Android-App entwickelt, um ein Sicherheitsproblem zu demonstrieren. Mit ihr ließen sich beliebige Geräte per Bluetooth Low Energy (BLE) fernsteuern - auch gegen den Willen ihrer Besitzer.

https://heise.de/-11449892

Certificate Authority unter Windows mit PowerShell betreiben

Mit diesem Blog-Post hier demonstriere ich, wie unter Verwendung von Windows 11 Bordmitteln (Powershell, es wird kein OpenSSL benötigt) eine CA erstellt und daraus Code-Signing-Zertifikate, Webserver-Zertifikate ...

https://hitco.at/blog/certificate-authority-windows-powershell-ca-smime-codesigning/

Beliebige Dateien (z.B. 7z, zip, yaml, -) mittels Catalog-Files und PowerShell signieren

Die Nutzung eines Code-Signing-Zertifikats zur Authenticode-Signatur ist für zahlreiche Datei-Typen die dies unterstützen direkt inline möglich. Als Beispiele seien *.exe, *.dll, *.ps1, - genannt. Dieses kurze How-To beschäftigt sich allerdings mit Datei-Typen, die keine Signatur unterstützen. Beispielsweise ein YAML-Konfigurationsfile im Textformat, oder ZIP-Container sowie 7zip-Containerfiles.

https://hitco.at/blog/beliebige-dateien-7z-zip-yaml-mittels-catalogfiles-powershell-signieren/

A rant about phishing: Its not the users fault (and not DNS either)

"For safety, don't click suspicious links" Neither the username, password nor 2FA prompts are hosted on the company's own domain. Combine that with token expiration triggering random authetication pop-ups, it becomes nearly impossible to notice phishing... because the real thing looks identical to a scam [..] An organization MUST use a single, well recognized, root domain.

https://maurycyz.com/misc/domains/

Vulnerabilities

ARISTA Security Advisory 0158

Both CVE-2026-73456 and CVE-2026-73457 affect Arista EOS-based platforms with gRPC Network Packet Sampling Interface (gNPSI) configured. which is disabled by default. [..] Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.

https://www.arista.com/en/support/advisories-notices/security-advisory/24714-security-advisory-0158

GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE) and Enterprise Edition (EE). [..] For security fixes, the issues detailing each vulnerability are made public on our issue tracker 90 days after the release in which they were patched.

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/#recommended-action

Forgejo 16.0.4 has a critical security bug fix (RCE - Remote Code Execution)

https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md

LWN: Security updates for Friday

https://lwn.net/Articles/1093765/