End-of-Day report
Timeframe: Montag 31-08-2026 18:00 - Dienstag 01-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
News
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session - history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
https://isc.sans.edu/diary/rss/33298
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user.
https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
OpenClaw has unveiled what its makers call its largest ever update - large enough to earn a 2.0 moniker - with usability taking center stage, along with some security updates that critics are suggesting will be insufficient.
https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492
Password spraying campaign targets AWS root user accounts across 150+ organizations
Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.
https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
Socket-s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them. The injected code runs two operations against a site-s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware.
https://socket.dev/blog/packagist-themes-ios-spyware
EncryptedSharedPreferences is Dead: Here-s What You Should Use Instead
In this post we-ll explore why persisting data to disk introduces unnecessary risk, dissect the mechanics of storage systems on Android, and provide you with proven methods to safeguard your application data. Furthermore, we-ll cover common misconceptions and misunderstandings with a focus on Android, including Google-s current stance that unencrypted internal app storage is not a concern due to reliance on OS protections such as device encryption and sandboxing, alongside recommended alternatives such as Jetpack DataStore coupled with Google Tink for encryption.
https://blog.includesecurity.com/2026/08/encryptedsharedpreferences-is-dead-heres-what-you-should-use-instead/
Vulnerabilities
Sicherheitsupdates für Hoymiles-Wechselrichter (30.8. 2026)
Im Juli 2026 hatte der Chaos Computer Club (CCC) vor gravierenden Schwachstellen im DTU-Protokoll des Herstellers Hoymiles gewarnt. Nun hat der Anbieter Firmware-Updates für verschiedene Modelle bereitgestellt, die die Schwachstellen schließen.
https://borncity.com/blog/2026/09/01/sicherheitsupdates-fuer-hoymiles-wechselrichter-30-8-2026/
VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check
https://kb.cert.org/vuls/id/456290
Mozilla Security Advisories September 1, 2026
https://www.mozilla.org/en-US/security/advisories/
LWN: Security updates for Tuesday
https://lwn.net/Articles/1091919/