End-of-Day report
Timeframe: Montag 05-10-2026 18:00 - Dienstag 06-10-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
News
Breite Betrugswellen: Trojaner- und Phishing-Attacken im Namen der WKO
Momentan sind besonders viele Betrugsversuche im Namen der Wirtschaftskammer Österreich unterwegs. Die Kriminellen gehen dabei zweigleisig vor: Sie wollen sowohl Schadsoftware auf die Endgeräte ihrer Opfer schleusen als auch deren Login-Daten für das WKO-Portal abgreifen. Ein (unvollständiger) Überblick über aktuelle Fallen.
https://www.watchlist-internet.at/news/breite-betrugswellen-wko/
Nach Sicherheitsvorfall: Vorsicht vor touriDat-Hotelbuchungs-Phishing
Der nächste Fall aus der Hotel-Buchungs-/Reisebranche, bei dem Buchungsdaten in Phishing-Nachrichten genutzt werden, um Opfer zu täuschen. Dieses Mal trifft es die touriDat-Plattform, deren Nutzer mit Phishing-Mails und oder WhatsApp-Phishing-Nachrichten kontaktiert werden, um Zahlungsdaten zu ergattern.
https://borncity.com/blog/2026/10/06/nach-sicherheitsvorfall-vorsicht-vor-touridat-hotelbuchungs-phishing/
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
The publisher of Wikipedia said Monday that OpenAI agents attempted to hack a note-taking tool it hosts, made unauthorized edits, and sent millions of resource-intensive requests to its infrastructure, in the latest instance of OpenAI systems taking harmful and potentially dangerous actions.
https://arstechnica.com/security/2026/10/openai-agents-tried-to-hack-wikipedia-tools-and-flooded-it-with-traffic/
Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [..] CVE-2026-61500, first published on July 13, 2026, is a session-cookie signing weakness and leakage issue fixed in Rejetto HFS version 3.2.1.
https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/
More RMM Tools In the Wild, (Tue, Oct 6th)
It seems that a trend started- I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found another one.
https://isc.sans.edu/diary/rss/33400
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browsers cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
Inside RevStealers Sandbox-Aware Anti-Analysis System
We recently came across an interesting Joe Sandbox analysis on Joe Sandbox Cloud Basic that was confirmed as malicious but showed surprisingly little malicious behavior. Samples like this are often particularly interesting because limited activity does not necessarily mean that execution failed.
https://www.joesecurity.org/blog/6469689575970038406
Vulnerabilities
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each products web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.
https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
Kritische Auth-Bypass-Schwachstelle CVE-2026-103956 (CVSS 10.0) in Loom for AWS
Eine kritische Schwachstelle führte dazu, dass Dritte ohne Authentifizierung auf Loom for AWS zugreifen konnten. Die kritische Auth-Bypass-Schwachstelle CVE-2026-103956 wurde mit einem CVSS Base-Score von 10.0 klassifiziert. [..] Wer Loom for AWS verwendet, sollten auf die Version 1.6.1 oder höher upgraden.
https://borncity.com/blog/2026/10/06/kritische-auth-bypass-schwachstelle-cve-2026-103956-cvss-10-0-in-loom-for-aws/
LibreOffice und OpenOffice: Warnung vor Codeschmuggel-Lücke, Updates kommen
In den Bürosoftwarepaketen LibreOffice und OpenOffice klafft eine hochriskante Sicherheitslücke, durch die Angreifer mit manipulierten Dokumenten Schadcode einschleusen können. LibreOffice stopft außerdem weitere Sicherheitslücken.
https://heise.de/-11477059
Android-Patchday: Google stopft sieben kritische Löcher
https://www.golem.de/news/android-patchday-google-stopft-sieben-kritische-loecher-2610-213746.html
LWN: Security updates for Tuesday
https://lwn.net/Articles/1098979/
Mozilla Foundation Security Advisories October 6, 2026
https://www.mozilla.org/en-US/security/advisories/
Libreswan: IKEv2 Use-After-Free bug when using IKE-over-TCP
https://libreswan.org/security/CVE-2026-94453/CVE-2026-94453.txt
Zyxel security advisory for command injection vulnerability in the WiFi SSID field of certain DSL/Ethernet CPE, fiber ONTs, and Wireless Extenders
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-the-wifi-ssid-field-of-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-10-06-2026
Veeam: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4
https://www.veeam.com/kb4934