End-of-Day report
Timeframe: Donnerstag 24-09-2026 18:00 - Freitag 25-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
News
CRA - Reporting: The first two weeks
The CRA-SRP (Single Reporting Platform) started operating two weeks ago, and we now have some experience with the system. There are multiple angles to this.
https://www.cert.at/en/blog/2026/9/cra-reporting-the-first-two-weeks
Phishing-Angriffe mit echten Hotel-Buchungsdaten
Über eine Schwachstelle bei HotelNetSolutions wurden Buchungsdaten von Hotelgästen abgegriffen. Kriminelle nutzen sie für glaubhafte Phishing-Nachrichten.
https://heise.de/-11466446
Betreiber Kritischer Infrastruktur sollen in Österreich Flugdrohnen abschießen
Nähern sich verdächtige Flugdrohnen Kritischer Infrastruktur, soll deren Betreiber die Drohnen vom Himmel holen. Lizenzen dafür sind in Österreich geplant.
https://heise.de/-11465199
Bevorstehender Zero-Day-Angriff: KiteWorks drängt Kunden zur Serverabschaltung
Man habe konkrete Hinweise von Strafverfolgern auf eine Attacke, schreibt der Hersteller seinen Kunden. Auch hierzulande sind große Unternehmen betroffen.
https://www.heise.de/news/Bevorstehender-Zero-Day-Angriff-KiteWorks-draengt-Kunden-zur-Serverabschaltung-11466114.html
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.
https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads.
https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/
Muse leakt Systemdateien: Metas KI-Agent gibt auf Anfrage sein Dateisystem aus
Ein Entwickler hat Metas KI-Agent Muse 6,8 GByte an Daten aus seiner Betriebsumgebung entlockt. Laut Meta ist das ein erwartetes Verhalten.
https://www.golem.de/news/muse-leakt-systemdateien-metas-ki-agent-gibt-auf-anfrage-sein-dateisystem-aus-2609-213429.html
Beyond the ransomware: Tracking Storm-2570-s consistent tradecraft across deployments
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.The post Beyond the ransomware: Tracking Storm-2570-s consistent tradecraft across deployments appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
Cloudflare Fixes Flaw That Let One Container Read Another Customers Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.
https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
CVE flood pushes Ubuntu onto weekly kernel release cycle
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace.
https://www.theregister.com/os-platforms/2026/09/24/cve-flood-pushes-ubuntu-onto-weekly-kernel-release-cycle/5298912
Decades-old file security flaws found in Android, Linux, macOS, and Windows
Security researchers report that Microsoft considers the side-channel leak of file events to be by design.
https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
SalesBleed security flaws lead to very unexpected consequences.
https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958
It was a matter of when, not if...
Security people always say it-s not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we-re the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked.
https://csirt.divd.nl/2026/09/24/when-not-if/
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
https://socket.dev/blog/mini-shai-hulud-actions?utm_medium=feed
Vulnerabilities
VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise.
https://kb.cert.org/vuls/id/234131
Sicherheitslücken: GitLab-Server mit Schadcode attackierbar
Die GitLab-Entwickler raten zur zügigen Installation der jüngst veröffentlichten Sicherheitsupdates.
https://www.heise.de/news/Sicherheitsluecken-GitLab-Server-mit-Schadcode-attackierbar-11465889.html
Video-Tool VLC: Version 3.0.24 stopft über 130 Sicherheitslecks
Der Videoplayer VLC ist in Version 3.0.24 erschienen. Mehr als 130 Sicherheitslücken soll das Release schließen.
https://heise.de/-11465305
LWN Security updates for Friday
https://lwn.net/Articles/1096637/