End-of-Day report
Timeframe: Freitag 18-09-2026 18:00 - Montag 21-09-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
News
Cyberangriff trifft Universität: LMU München bestätigt Abfluss von Studentendaten
Ein Angreifer ist an persönliche Daten von Studenten der Ludwig-Maximilians-Universität München gelangt. Auch Bankdaten sollen betroffen sein.
https://www.golem.de/news/cyberangriff-trifft-universitaet-lmu-muenchen-bestaetigt-abfluss-von-studentendaten-2609-213255.html
Hackerangriff auf die GUTcert; Kundendaten abgeflossen
Unschöne Nachricht für Kunden, die sich über die GUTcert einer Zertifizierung unterzogen haben. Der Anbieter ist Opfer eines Hackerangriffs geworden, bei dem auch Kundendaten abgeflossen sind. Betroffene scheinen vom Unternehmen gerade informiert zu werden, wie ein Leser mir heute mitteilte.
https://borncity.com/blog/2026/09/20/hackerangriff-auf-die-gutcert-kundendaten-abgeflossen/
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operations data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.
https://securelist.com/tr/payload-ransomware-via-group-policy/121335/
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable intrusions we observed including the theft of more than 18,000 sensitive records from a western government.
https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation
EU prüft OpenAI nach nicht gemeldetem Sicherheitsvorfall
Nach einem Vorfall beim Software-Register RubyGems meldete OpenAI diesen nicht der EU. Die europäischen Behörden prüfen nun die Einhaltung des AI Acts.
https://heise.de/-11458971
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Ciscos Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
Vulnerabilities
Behörde warnt: Angriffe auf Lücken im Linux-Kernel beobachtet
Die Cisa warnt vor laufenden Angriffen auf Linux-Systeme über drei gefährliche Sicherheitslücken in Kernel-Komponenten. Korrekturen sind verfügbar.
https://www.golem.de/news/behoerde-warnt-angriffe-auf-luecken-im-linux-kernel-beobachtet-2609-213261.html
Synology warnt: Kritische NAS-Lücken ermöglichen Datenklau
Angreifer können durch mehrere Sicherheitslücken lesend und schreibend auf NAS-Geräte von Synology zugreifen. Patches sind verfügbar.
https://www.golem.de/news/synology-warnt-kritische-nas-luecken-ermoeglichen-datenklau-2609-213268.html
Werbeblocker Pi-hole: Update stopft Codeschmuggel-Lücken
Ein Update für den DNS-basierten Werbeblocker Pi-hole schließt teils hochriskante Codeschmuggel-Lücken.
https://www.heise.de/news/Werbeblocker-Pi-hole-Update-stopft-Codeschmuggel-Luecken-11459820.html
Fremdzugriffe auf SolarWinds Access Rights Manager vorstellbar
Ein Sicherheitspatch schließt eine Schwachstelle in SolarWinds Access Rights Manager. Bislang gibt es keine Hinweise auf Attacken.
https://heise.de/-11459978
LWN Security updates for Monday
https://lwn.net/Articles/1095702/