End-of-Day report
Timeframe: Mittwoch 02-09-2026 18:00 - Donnerstag 03-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
News
Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.
https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
"FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," [..] The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with Crowdstrike Falcon.
https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
This Is Flock-s AI Search Tool for Cops
WIRED rebuilt Flock-s latest search tool from code the company sends to a police officer-s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description. [..] Police officers have already used Flock-s software to track people for reasons unrelated to police work. At least 50 officers in the US have recently been charged with or accused of misusing license plate readers, according to The Washington Post.
https://www.wired.com/story/flock-ai-search-user-interface/
WhatsApp-Sicherheitslücke: Zugriff auf Fotos bei gesperrtem Android-Handy
Die WhatsApp-App unter Android hat offenbar eine Schwachstelle. Unbefugte Nutzerinnen und Nutzer können auf einigen Geräten bei einem eingehenden Videoanruf im gesperrten Zustand auf private Fotoordner zugreifen. Meta hat nach eigenen Angaben inzwischen begonnen, einen Fix zu verteilen. Bis dieser flächendeckend ankommt, gibt es eine Übergangslösung.
https://www.heise.de/news/WhatsApp-Sicherheitsluecke-Zugriff-auf-Fotos-bei-gesperrtem-Android-Handy-11439291.html
WordPress All-in-One WP Migration: Angreifer können Admin-Falle auslegen
Das WordPress-Plug-in All-in-One WP Migration and Backup ist verwundbar und Angreifer können im schlimmsten Fall die volle Kontrolle über mit dem CMS erstellte Websites erlangen. [..] Die Sicherheitsforscher geben an, dass die Entwickler von All-in-One WP Migration and Backup Mitte August von der Schwachstelle erfahren haben. Der Sicherheitspatch war fünf Tage später fertig und steht seit dem 20. August 2026 zum Download bereit.
https://www.heise.de/news/WordPress-All-in-One-WP-Migration-Angreifer-koennen-Admin-Falle-auslegen-11439787.html
Why your data is safer than you think on public Wi-Fi
The coffee shop hacker Public Wi-Fi has acquired a slightly theatrical reputation. Join the network in a coffee shop, we are told, and a hacker in the corner can immediately steal your passwords and empty your bank account. It makes for good VPN advertising. It is not a particularly accurate picture of how the modern web works.
https://www.pentestpartners.com/security-blog/why-your-data-is-safer-than-you-think-on-public-wi-fi/
Analyse: Umfassendes Fake-Netzwerk aus Insolvenzverwaltern, IT-Anbietern, Unternehmensberatern und Zeitungen
Um den Anschein von Seriosität zu verstärken, bauen Kriminelle umfangreiche Onlinemagazine. In der dortigen Flut an angeblich realen Geschichten platzieren sie Artikel, die über vermeintlich seriöse Insolvenzverwalter, IT-Anbietern und Unternehmensberater berichten. Die gesamte Konstruktion ist auf Vorschussbetrug und das Sammeln von Daten ausgelegt.
https://www.watchlist-internet.at/news/analyse-umfassendes-fake-netzwerk/
Chamilo LMS... Its raining 0days, hallelujah, its raining 0days
Chamilo is an open source Learning Management System (LMS) widely deployed in schools and enterprises around the world. In this blogpost we explain how we were able to identify multiple vulnerabilities including a full unauthenticated Remote Code Execution chain in the latest version.
http://blog.quarkslab.com/chamilo-lms-its-raining-0days-hallelujah-its-raining-0days.html
Vulnerabilities
VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)
VMware Workstation and Fusion contain an integer-overflow vulnerability. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. CVE-2026-59346, CVE-2026-59347
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
HPE: HPESBNW05133 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer
Remote: Access Restriction Bypass, Authentication Bypass, Escalation of Privilege
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US
HPE: HPESBNW05134 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)
Local: Access Restriction Bypass
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv
Drupal Security Advisories 2026-September-02
https://www.drupal.org/security
LWN: Security updates for Thursday
https://lwn.net/Articles/1092419/