Tageszusammenfassung - 08.09.2026

End-of-Day report

Timeframe: Montag 07-09-2026 18:00 - Dienstag 08-09-2026 18:00 Handler: Alexander Riepl Co-Handler: Michael Schlagenhaufer

News

Schwerwiegende Sicherheitslücke in N-able N-central - aktiv ausgenutzt

In N-able N-central, einer Remote-Monitoring- und Management-Plattform, die insbesondere von Managed Service Providern (MSPs) zur Verwaltung von Kund:innenumgebungen eingesetzt wird, wurde eine schwerwiegende Sicherheitslücke entdeckt. Die Schwachstelle, CVE-2026-86218, ist mit einem CVSS-Score von 10.0 bewertet, eine Ausnutzung ermöglicht entfernten, unauthentifizierten Angreifer:innen eine Ausführung von Code auf verwundbaren Systemen.

https://www.cert.at/de/aktuelles/2026/9/schwerwiegende-sicherheitslucke-in-n-able-n-central-aktiv-ausgenutzt


Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack.

https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/


Auch im Standby: LG-Fernseher wohl anfällig für weitreichende Spionageangriffe

Dass Smart TVs über Automatic Content Recognition (ACR) etwa zu Werbezwecken permanent die Sehgewohnheiten ihrer Nutzer tracken, ist schon seit Jahren bekannt. [..] Demnach scannen LG-Fernseher neben dem ACR-Tracking ständig im internen Netzwerk nach Smartphones, PCs, Druckern und anderen erreichbaren Endgeräten. Zudem sollen die TV-Geräte permanent Informationen über in Reichweite befindliche WLAN-Netze und deren Standorte und Signalstärken sammeln.

https://www.golem.de/news/auch-im-standby-lg-fernseher-wohl-anfaellig-fuer-weitreichende-spionageangriffe-2609-212761.html


Abo-Falle: Wenn NordicaLab automatisch über PayPal abbucht

-Danke, dass Sie mit PayPal gezahlt haben- - Flattert diese Mitteilung zu einem Zeitpunkt ins Mail-Postfach, an dem garantiert keine Zahlung freigegeben wurde, ist sprichwörtlich Feuer am Dach. Irgendetwas stimmt hier ganz und gar nicht. Was genau, das zeigt ein konkreter Fall aus der Praxis.

https://www.watchlist-internet.at/news/abo-falle-nordicalab/


Führerschein-Scans von Altersüberprüfungs-Dienst landeten über ein Jahr kontinuierlich im Darknet

Wie das Fachmedium Techdirt berichtet, ging vergangene Woche eine Plattform für Identitätsdiebstahl namens Nexus online. Auf der Seite werden mehr als 153 Millionen Scans von Bürgerinnen und Bürgern der USA und Kanada verkauft. Die Betreiber von Nexus behaupten, die Ausweisbilder stammten aus einem aktiven Datenleck bei "einem großen Unternehmen für Identitätsprüfung", zu dessen Kunden mehrere Fortune-500-Unternehmen zählen.

https://www.derstandard.at/story/3000000338691/fuehrerschein-scans-von-altersueberpruefungs-dienst-landeten-ueber-ein-jahr-kontinuierlich-im-darknet


ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.

https://blog.talosintelligence.com/clearfake-webdav-infection-chain/


The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim-s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker-s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim-s connected Gmail account and relayed it to the attacker.

https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/


I-ve factored the RSA keys of a Certificate Authority-from the 90s

I-ve been thinking about the security of RSA lately. RSA-s cryptography relies on the difficulty of factoring a large semiprime number, but what -large- means is an interesting question. The Web PKI deprecated 1024-bit RSA over a decade ago, and while I don-t know of anyone factoring a key of that size, it-s within the realm of possibility for a government or other organization with a large number of computers. Just a few days ago, someone factored the 862-bit RSA-260 key from the RSA factoring challenge.

https://mcpherrin.ca/2026/09/07/rsa.html

Vulnerabilities

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. [..] That only becomes dangerous because of the second flaw. 389 Directory Server has a rule type meant to say "only the authenticated owner of this entry." It compares the client's name against a stored value as plain text, and a client that has not logged in has an empty name, which matches an empty stored value.

https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html


Ivanti September 2026 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories: Ivanti Neurons for ITSM, Ivanti Endpoint Manager Mobile (EPMM), Ivanti Sentry

https://www.ivanti.com/blog/september-2026-security-update


SAP Security Patch Day September 2026 | RedRays

SAP Security Patch Day September 2026 brings 20 security notes, four of them HotNews rated up to CVSS 10.0, alongside five High priority issues, ten Medium priority fixes and one Low priority update. They span the NetWeaver stack, SAP S/4HANA, SAPUI5 and several cloud products. This release lands on the network-facing core of NetWeaver.

https://redrays.io/blog/sap-security-patch-day-september-2026/


VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

https://kb.cert.org/vuls/id/943094


VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

https://kb.cert.org/vuls/id/718077


TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands

https://news.typo3.com/security/advisory/typo3-core-sa-2026-023


TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard

https://news.typo3.com/security/advisory/typo3-core-sa-2026-022


Xen: XSA-513

https://xenbits.xen.org/xsa/advisory-513.html


Xen: XSA-512

https://xenbits.xen.org/xsa/advisory-512.html


Xen: XSA-511

https://xenbits.xen.org/xsa/advisory-511.html


Xen: XSA-510

https://xenbits.xen.org/xsa/advisory-510.html


Xen: XSA-509

https://xenbits.xen.org/xsa/advisory-509.html


LWN: Security updates for Tuesday

https://lwn.net/Articles/1093144/