End-of-Day report
Timeframe: Mittwoch 30-09-2026 18:00 - Donnerstag 01-10-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
News
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platforms security measures to prevent accidental leaks of sensitive data.
https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/
Revolut zahlt kein Lösegeld: Hackergruppe erpresst Revolut-Kunden direkt
Die Geschichte rund um den Revolut-Hack aus dem vergangenen Monat geht weiter, bei dem Unbefugte an Bankdaten von Kunden gelangt sind. Nachdem die Neobank ein gefordertes Lösegeld von 3 Millionen US-Dollar nicht zahlte, versuchen Kriminelle, die erbeuteten Daten zu Geld zu machen, indem Revolut-Kunden direkt erpresst werden, berichtet unter anderem das Cybergrant-Blog. Nach derzeitigem Kenntnisstand sind 680 Revolut-Kunden von dem Vorfall betroffen.
https://www.golem.de/news/revolut-zahlt-kein-loesegeld-hackergruppe-erpresst-revolut-kunden-direkt-2610-213607.html
From: anyone@icloud.com - Absenderfälschung in Apple iCloud
Eine Fallstudie über die Entdeckung zweier E-Mail-Spoofing-Schwachstellen in Apple iCloud.
https://sec-consult.com/de/blog/detail/from-anyoneicloudcom-absenderfaelschung-in-apple-icloud/
SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor
During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we-ll refer to this family of malware as SC, named after the -SC_- markers found in the injected content.What makes SC worth documenting is how it survives.
https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of-loaders-drop-ins-and-a-blockchain-controlled-backdoor.html
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate.
https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html
NIS2 Registrierung in Österreich. Wie gehe ich richtig vor?
Seit dem 1. Oktober 2026 gelten für viele österreichische Unternehmen neue Vorgaben durch NIS2. Betroffene Unternehmen müssen dann technische und organisatorische Sicherheitsmaßnahmen umsetzen, die Verantwortung der Geschäftsführung beachten und sich beim Bundesamt für Cybersicherheit (BCS) registrieren. Dieser Leitfaden erklärt, wer sich registrieren muss, welche Informationen dafür nötig sind und wie Unternehmen dabei am besten vorgehen.
https://www.zettasecure.com/post/nis2-registrierung-%C3%B6sterreich-anleitung
Zu viele KI-Vorfälle: US-Behörde untersucht Anthropic, METR, OpenAI
Zu häufig richten große Sprachmodelle Schaden an. Daher führt die US-Handelsbehörde FTC eine Untersuchung gegen große KI-Betreiber.
https://heise.de/-11471857
Vulnerabilities
Kiteworks patches max severity code injection vulnerability
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [..] Successful exploitation can let remote threat actors without privileges gain code execution and take over the targeted EPG appliance by exploiting a chain of path traversal, code injection, and missing authentication in low-complexity attacks that don't require user interaction. CVE-2026-54154
https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/
Vulnerabilities in Zammad during investigation of case DIVD-2026-00014
During the investigation of case DIVD-2026-00014, two new CVEs were identified. CVE-2026-102489 - Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. [..] CVE-2026-102490 - In all versions of Zammad including the latest alpha has an vulnerability which enables the local zammad user to escalate privileges to root.
https://csirt.divd.nl/cases/DIVD-2026-00015/
WatchGuard schließt teils kritische Lücken in Fireware OS
Das Betriebssystem Fireware OS von WatchGuard weist Sicherheitslücken auf, die Angreifern aus dem Netz unter anderem das Einschleusen und Ausführen von Schadcode oder Denial-of-Service-Attacken ermöglichen. Sie gelten zum größten Teil als hochriskant und in einem Fall sogar als kritisch.
https://www.heise.de/news/WatchGuard-schliesst-teils-kritische-Luecken-in-Fireware-OS-11472101.html
NVIDIA GPU Display Driver - September 2026
https://nvidia.custhelp.com/app/answers/detail/a_id/5861
LWN: Security updates for Thursday
https://lwn.net/Articles/1098067/
Mozilla Foundation Security Advisories September 30, 2026
https://www.mozilla.org/en-US/security/advisories/