Tageszusammenfassung - 21.09.2026

End-of-Day report

Timeframe: Freitag 18-09-2026 18:00 - Montag 21-09-2026 18:00 Handler: Guenes Holler Co-Handler: n/a

News

Cyberangriff trifft Universität: LMU München bestätigt Abfluss von Studentendaten

Ein Angreifer ist an persönliche Daten von Studenten der Ludwig-Maximilians-Universität München gelangt. Auch Bankdaten sollen betroffen sein.

https://www.golem.de/news/cyberangriff-trifft-universitaet-lmu-muenchen-bestaetigt-abfluss-von-studentendaten-2609-213255.html

Hackerangriff auf die GUTcert; Kundendaten abgeflossen

Unschöne Nachricht für Kunden, die sich über die GUTcert einer Zertifizierung unterzogen haben. Der Anbieter ist Opfer eines Hackerangriffs geworden, bei dem auch Kundendaten abgeflossen sind. Betroffene scheinen vom Unternehmen gerade informiert zu werden, wie ein Leser mir heute mitteilte.

https://borncity.com/blog/2026/09/20/hackerangriff-auf-die-gutcert-kundendaten-abgeflossen/

Gyazo server flaw exploited to steal 23.6 million user records

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.

https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operations data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.

https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.

https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

https://securelist.com/tr/payload-ransomware-via-group-policy/121335/

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.

https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.

https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html

Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation

GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable intrusions we observed including the theft of more than 18,000 sensitive records from a western government.

https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation

EU prüft OpenAI nach nicht gemeldetem Sicherheitsvorfall

Nach einem Vorfall beim Software-Register RubyGems meldete OpenAI diesen nicht der EU. Die europäischen Behörden prüfen nun die Einhaltung des AI Acts.

https://heise.de/-11458971

Cisco Zero-Day Highlights API Endpoint Authentication Issues

The authentication bypass flaw CVE-2026-76460 impacts Ciscos Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues

Vulnerabilities

Behörde warnt: Angriffe auf Lücken im Linux-Kernel beobachtet

Die Cisa warnt vor laufenden Angriffen auf Linux-Systeme über drei gefährliche Sicherheitslücken in Kernel-Komponenten. Korrekturen sind verfügbar.

https://www.golem.de/news/behoerde-warnt-angriffe-auf-luecken-im-linux-kernel-beobachtet-2609-213261.html

Synology warnt: Kritische NAS-Lücken ermöglichen Datenklau

Angreifer können durch mehrere Sicherheitslücken lesend und schreibend auf NAS-Geräte von Synology zugreifen. Patches sind verfügbar.

https://www.golem.de/news/synology-warnt-kritische-nas-luecken-ermoeglichen-datenklau-2609-213268.html

Werbeblocker Pi-hole: Update stopft Codeschmuggel-Lücken

Ein Update für den DNS-basierten Werbeblocker Pi-hole schließt teils hochriskante Codeschmuggel-Lücken.

https://www.heise.de/news/Werbeblocker-Pi-hole-Update-stopft-Codeschmuggel-Luecken-11459820.html

Fremdzugriffe auf SolarWinds Access Rights Manager vorstellbar

Ein Sicherheitspatch schließt eine Schwachstelle in SolarWinds Access Rights Manager. Bislang gibt es keine Hinweise auf Attacken.

https://heise.de/-11459978

LWN Security updates for Monday

https://lwn.net/Articles/1095702/