End-of-Day report
Timeframe: Donnerstag 03-09-2026 18:00 - Freitag 04-09-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
News
Critical Citrix NetScaler auth bypass now leveraged in attacks
Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. [..] While the company has yet to flag the vulnerability as actively exploited in its August 19 security advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Thursday that attackers have begun targeting CVE-2026-19490 in the wild after a "credible" proof-of-concept exploit was published online.
https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as -funding- to prevent email filters from parsing them.
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
Jetzt patchen! Angreifer führen Schadcode in der Sandbox von Chrome aus
Google hat mehrere Sicherheitslücken im Webbrowser Chrome geschlossen. [..] Die derzeit ausgenutzte Schwachstelle (CVE-2026-85046 -hoch-) ist eine Type-Confusion-Lücke in der JavaScript-Engine V8, führen die Entwickler in einer Warnmeldung aus. Bei dieser Art von Schwachstellen kommt es bei der Verarbeitung von inkompatiblen Objekten zu Speicherfehlern, über die Schadcode auf Systeme gelangt. In diesem konkreten Fall müssen entfernte Angreifer Opfer auf eine von ihnen präparierte Website locken.
https://www.heise.de/news/Jetzt-patchen-Angreifer-fuehren-Schadcode-in-der-Sandbox-von-Chrome-aus-11441030.html
Free streaming boxes may be routing criminal traffic through your home
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
https://www.malwarebytes.com/blog/news/2026/09/free-streaming-boxes-may-be-routing-criminal-traffic-through-your-home
Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026 [..]
https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/
Reproducing CVE-2026-75604: Next.js Path Traversal to RCE on Windows
Vulnerability research: CVE-2026-75604 A single un-escaped backslash in the Next.js incremental cache lets an unauthenticated attacker read and write files on Windows hosts, and, on the right versions and app shape, run commands. Here is the whole chain, reproduced end to end.
https://fortbridge.co.uk/research/next-js-path-traversal-to-rce/
Vulnerabilities
VU#889462: Casdoor authentication server is vulnerable to authorization bypass
https://kb.cert.org/vuls/id/889462
LWN: Security updates for Friday
https://lwn.net/Articles/1092659/