Tageszusammenfassung - 24.09.2026

End-of-Day report

Timeframe: Mittwoch 23-09-2026 18:00 - Donnerstag 24-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

Theres a new way to break RSA thats faster than anything weve seen before

The world has known for decades that the RSA cryptosystem-s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold. The practical risk is limited, but still significant.

https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/

Hackers now exploit critical Roundcube flaw in code injection attacks

In May, the Roundcube security team patched the flaw (tracked as CVE-2026-48842), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.

https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored by you.

https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).

https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html

OpenAI-Agent knackt australisches Regierungsportal

Eine KI sollte Gesundheitsstatistiken suchen - und knackte dabei ein australisches Regierungsportal. Die Empörung ist groß.

https://heise.de/-11463920

Bypassing EDR with Local AI

How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.

https://projectblack.io/blog/bypassing-edr-with-local-ai/

Vulnerabilities

Foxit: Security updates available in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8

Foxit has released Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8, which addresses potential security and stability issues.

https://www.foxit.com/support/security-bulletins.html

Drupal Security Advisories 2026-September-23

Drupal released 36 new security advisories (5x critical).

https://www.drupal.org/security

Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted

In SolarWinds Observability Self-Hosted 2026.2.3 haben die Entwickler eigenen Angaben zufolge zwei Schwachstellen geschlossen (CVE-2026-28324 -kritisch- CVE-2026-28325, -hoch-). In beiden Fällen können Angreifer unter den jeweils genannten Bedingungen ohne Authentifizierung an den Schwachstellen ansetzen und Schadcode ausführen - bei CVE-2026-28324 übers Netz, bei CVE-2026-28325 nur aus einem benachbarten Netzsegment. Die Ursachen unterscheiden sich jedoch: Bei CVE-2026-28324 sind Integritätsprüfungen unzureichend; CVE-2026-28325 betrifft die Verarbeitung nicht vertrauenswürdiger Daten durch Deserialisierung. Hinweise auf laufende Attacken gibt es bislang nicht.

https://heise.de/-11464112

Imprivata Enterprise Access Management (EAM) does not rotate RSA keys

https://kb.cert.org/vuls/id/273940

LWN: Security updates for Thursday

https://lwn.net/Articles/1096407/