Tageszusammenfassung - 25.09.2026

End-of-Day report

Timeframe: Donnerstag 24-09-2026 18:00 - Freitag 25-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler

News

CRA - Reporting: The first two weeks

The CRA-SRP (Single Reporting Platform) started operating two weeks ago, and we now have some experience with the system. There are multiple angles to this.

https://www.cert.at/en/blog/2026/9/cra-reporting-the-first-two-weeks

Phishing-Angriffe mit echten Hotel-Buchungsdaten

Über eine Schwachstelle bei HotelNetSolutions wurden Buchungsdaten von Hotelgästen abgegriffen. Kriminelle nutzen sie für glaubhafte Phishing-Nachrichten.

https://heise.de/-11466446

Betreiber Kritischer Infrastruktur sollen in Österreich Flugdrohnen abschießen

Nähern sich verdächtige Flugdrohnen Kritischer Infrastruktur, soll deren Betreiber die Drohnen vom Himmel holen. Lizenzen dafür sind in Österreich geplant.

https://heise.de/-11465199

Bevorstehender Zero-Day-Angriff: KiteWorks drängt Kunden zur Serverabschaltung

Man habe konkrete Hinweise von Strafverfolgern auf eine Attacke, schreibt der Hersteller seinen Kunden. Auch hierzulande sind große Unternehmen betroffen.

https://www.heise.de/news/Bevorstehender-Zero-Day-Angriff-KiteWorks-draengt-Kunden-zur-Serverabschaltung-11466114.html

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.

https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads.

https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/

Muse leakt Systemdateien: Metas KI-Agent gibt auf Anfrage sein Dateisystem aus

Ein Entwickler hat Metas KI-Agent Muse 6,8 GByte an Daten aus seiner Betriebsumgebung entlockt. Laut Meta ist das ein erwartetes Verhalten.

https://www.golem.de/news/muse-leakt-systemdateien-metas-ki-agent-gibt-auf-anfrage-sein-dateisystem-aus-2609-213429.html

Beyond the ransomware: Tracking Storm-2570-s consistent tradecraft across deployments

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.The post Beyond the ransomware: Tracking Storm-2570-s consistent tradecraft across deployments appeared first on Microsoft Security Blog.

https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/

Cloudflare Fixes Flaw That Let One Container Read Another Customers Leftover Disk Data

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.

https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html

CVE flood pushes Ubuntu onto weekly kernel release cycle

AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace.

https://www.theregister.com/os-platforms/2026/09/24/cve-flood-pushes-ubuntu-onto-weekly-kernel-release-cycle/5298912

Decades-old file security flaws found in Android, Linux, macOS, and Windows

Security researchers report that Microsoft considers the side-channel leak of file events to be by design.

https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

SalesBleed security flaws lead to very unexpected consequences.

https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958

It was a matter of when, not if...

Security people always say it-s not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we-re the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked.

https://csirt.divd.nl/2026/09/24/when-not-if/

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

https://socket.dev/blog/mini-shai-hulud-actions?utm_medium=feed

Vulnerabilities

VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise

ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise.

https://kb.cert.org/vuls/id/234131

Sicherheitslücken: GitLab-Server mit Schadcode attackierbar

Die GitLab-Entwickler raten zur zügigen Installation der jüngst veröffentlichten Sicherheitsupdates.

https://www.heise.de/news/Sicherheitsluecken-GitLab-Server-mit-Schadcode-attackierbar-11465889.html

Video-Tool VLC: Version 3.0.24 stopft über 130 Sicherheitslecks

Der Videoplayer VLC ist in Version 3.0.24 erschienen. Mehr als 130 Sicherheitslücken soll das Release schließen.

https://heise.de/-11465305

LWN Security updates for Friday

https://lwn.net/Articles/1096637/