Tageszusammenfassung - 30.09.2026

End-of-Day report

Timeframe: Dienstag 29-09-2026 18:00 - Mittwoch 30-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

New Spectre v2 attack variant leaks Linux root password hash in minutes

A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.

https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/

Phishing Abuses RMM Tools for Persistent Access

In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. [..] This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities.

https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

The public still doesn-t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the unknown digital intruders have used CVE-2026-88772 to break into government agencies, financial services firms, education organizations, and legal and professional services sectors across North America and Europe. And everyone agrees that the vendor took way too long to disclose the security holes.

https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867

Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent

Students, job seekers and university staff, watch out for fake job offers sent from legitimate university email accounts.

https://hackread.com/hackers-hijacked-university-email-scam-students-fbi-agent/

Fake Express Packages on npm Spread a Linux Worm

Nine npm packages hide a self-spreading Linux worm. The npm account dirtyblanket published all nine on September 29, 2026, in 33 minutes. Eight of them copy the popular Express framework. One copies React.

https://safedep.io/dirtyblanket-express-impersonation-npm

CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode

Jamf Threat Labs uncovers CloudSyncD, a fake Zoom installer disguised as a legitimate application that uses a phished login password to launch an embedded backdoor while concealing the credential inside a decoy configuration file.

https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/

Vulnerabilities

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. [..] In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. CVE-2026-76504

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU

TeamViewer: Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services

TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services. These vulnerabilities have been resolved in the latest available versions. TeamViewer strongly recommends that all users update to the latest available version as soon as possible.

https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2026-1010/

MikroTik RouterOS

Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. [..] Initial Release Date: 2026-09-29 [..] CVE-2026-84411

https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06

Kritische Schwachstelle: Google stopft 32 Löcher in Chrome

Die kritische Lücke mit der Kennung CVE-2026-102331 beschreibt Google in den Versionshinweisen als Pufferüberlauf. Betroffen ist die Grafikkomponente Angle. Laut CVE.org kann der Fehler mithilfe einer speziell präparierten HTML-Datei ausgenutzt werden. Ein Angreifer müsste ein Opfer also lediglich dazu verleiten, eine von ihm kontrollierte Website mit Chrome zu öffnen.

https://www.golem.de/news/kritische-schwachstelle-google-stopft-32-loecher-in-chrome-2609-213576.html

OpenSSL Security Advisory [29th September 2026]

https://openssl-library.org/news/secadv/20260929.txt

LWN: Security updates for Wednesday

https://lwn.net/Articles/1097753/