End-of-Day report
Timeframe: Dienstag 29-09-2026 18:00 - Mittwoch 30-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
Phishing Abuses RMM Tools for Persistent Access
In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. [..] This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities.
https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/
Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
The public still doesn-t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the unknown digital intruders have used CVE-2026-88772 to break into government agencies, financial services firms, education organizations, and legal and professional services sectors across North America and Europe. And everyone agrees that the vendor took way too long to disclose the security holes.
https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent
Students, job seekers and university staff, watch out for fake job offers sent from legitimate university email accounts.
https://hackread.com/hackers-hijacked-university-email-scam-students-fbi-agent/
Fake Express Packages on npm Spread a Linux Worm
Nine npm packages hide a self-spreading Linux worm. The npm account dirtyblanket published all nine on September 29, 2026, in 33 minutes. Eight of them copy the popular Express framework. One copies React.
https://safedep.io/dirtyblanket-express-impersonation-npm
CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode
Jamf Threat Labs uncovers CloudSyncD, a fake Zoom installer disguised as a legitimate application that uses a phished login password to launch an embedded backdoor while concealing the credential inside a decoy configuration file.
https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/
Vulnerabilities
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. [..] In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. CVE-2026-76504
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
TeamViewer: Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services
TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services. These vulnerabilities have been resolved in the latest available versions. TeamViewer strongly recommends that all users update to the latest available version as soon as possible.
https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2026-1010/
MikroTik RouterOS
Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. [..] Initial Release Date: 2026-09-29 [..] CVE-2026-84411
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
Kritische Schwachstelle: Google stopft 32 Löcher in Chrome
Die kritische Lücke mit der Kennung CVE-2026-102331 beschreibt Google in den Versionshinweisen als Pufferüberlauf. Betroffen ist die Grafikkomponente Angle. Laut CVE.org kann der Fehler mithilfe einer speziell präparierten HTML-Datei ausgenutzt werden. Ein Angreifer müsste ein Opfer also lediglich dazu verleiten, eine von ihm kontrollierte Website mit Chrome zu öffnen.
https://www.golem.de/news/kritische-schwachstelle-google-stopft-32-loecher-in-chrome-2609-213576.html
OpenSSL Security Advisory [29th September 2026]
https://openssl-library.org/news/secadv/20260929.txt
LWN: Security updates for Wednesday
https://lwn.net/Articles/1097753/