Tageszusammenfassung - 02.09.2026

End-of-Day report

Timeframe: Dienstag 01-09-2026 18:00 - Mittwoch 02-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.

https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/

Bei Sandboxing-Tests: KI-Agent bricht mehrfach aus VM aus

Ein Forscher hat getestet, ob sich moderne KI-Modelle mit Virtualisierung sinnvoll isolieren lassen. Die KI ist mehrfach aus einer VM entkommen. [..] Der Forscher hatte die KI zwar explizit dazu angewiesen aus der VM auszubrechen, jedoch sind entsprechende Ausbrüche auch in anderen Situationen denkbar. [..] Zudem rät Dinaburg, für die Virtualisierung auf minimalistische Lösungen umzusteigen, die eine geringere Angriffsfläche bieten.

https://www.golem.de/news/bei-sandboxing-tests-ki-agent-bricht-mehrfach-aus-vm-aus-2608-212442.html

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026.

https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html

OpenAI Is About to Release Its First AI Model With -Critical- Cyber Abilities

The company will give select partners early access to its Astra AI model-so they have time to shore up their defenses.

https://www.wired.com/story/openai-astra-first-ai-model-with-critical-cyber-abilities/

Fremde Dropbox-Konten über Lenovo-ID zugänglich

Eine erstaunliche Sicherheitslücke ist Inhabern von rund 5.000 Dropbox-Konten zum Verhängnis geworden, die auf die Einrichtung von Zwei-Faktor-Authentifizierung (2FA) verzichtet hatten: Unbefugte haben sich mittels frisch angelegter Lenovo-Konten Zugriff verschafft.

https://www.heise.de/news/Fremde-Dropbox-Konten-ueber-Lenovo-ID-zugaenglich-11437565.html

The Vulnpocalypse Is Repricing the Bug Bounty Economy

The shape of the market may be changing, but there's no indication that the bug bounty as we know it is going away. Of the dozen executives, security experts and researchers Dark Reading spoke to, not one believed that the vulnpocalypse was an existential crisis for independent security research. It would challenge the ecosystem, reshape it, and could perhaps act as a reckoning for those companies that release insecure software, but this moment would be more akin to a storm that will pass.

https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy

Passkeys erklärt: wie sicher die Anmeldung ohne Passwort ist

Immer öfter erscheint beim Anmelden auf einer Website ein Fenster mit der Frage, ob Sie einen Passkey erstellen möchten. Viele klicken es weg, weil sie nicht wissen, was das eigentlich ist. Dahinter steckt eine Technologie, die das Potenzial hat, das Anmelden im Internet grundlegend sicherer zu machen.

https:\/\/www.zettasecure.com\/post\/sind-passkeys-sicher

Vulnerabilities

Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar

In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Authentifizierung, die Appliance dazu zu bringen, serverseitig Anfragen an eigentlich nicht erreichbare interne Endpunkte zu senden (Server-Side Request Forgery). Laut SonicWall PSIRT werden die in diesem Advisory beschriebenen Schwachstellen bereits aktiv ausgenutzt. CVE-2026-83548, CVE-2026-83549

https://www.cert.at/de/warnungen/2026/9/erneut-kritische-sicherheitslucken-in-sonicwall-sma1000-series-aktiv-ausgenutzt-updates-verfugbar

Plex: Important Security Update for Plex Media Server v1.43.2 and earlier

We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible. CVEs have been requested and we-ll reply to this thread with more details once they-re published.

https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319

LWN: Security updates for Wednesday

https://lwn.net/Articles/1092149/