Tageszusammenfassung - 09.09.2026

End-of-Day report

Timeframe: Dienstag 08-09-2026 18:00 - Mittwoch 09-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Patchday-Rekord: Fast 1.000 Sicherheitslücken in Windows, Office und Co.

Microsoft hat zum September-Patchday mal wieder einen neuen Rekord aufgestellt. Erstmals hat der Konzern über all seine Produkte hinweg innerhalb eines Monats fast 1.000 Sicherheitslücken geschlossen.

https://www.golem.de/news/patchday-rekord-fast-1-000-sicherheitsluecken-in-windows-office-und-co-2609-212793.html


New Microsoft Defender ShieldCrash zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [..] According to Nightmare Eclipse, the ShieldCrash proof-of-concept exploit lets attackers gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems, but will not give them write access to the compromised systems. [..] Nightmare Eclipse released these zero-day exploits as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices.

https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/


Chrome 153: Google wechselt zu Zweiwochen-Update-Zyklus

Bislang veröffentlichte Google seit 2021 im Regelfall alle vier Wochen eine neue Chrome-Hauptversion. Ab Version 153 erscheinen Stable- und Beta-Ausgaben nun alle zwei Wochen für Desktop, Android und iOS. Wöchentliche Sicherheitsupdates bleiben bestehen.

https://heise.de/-11446371


Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.

https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/


DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeeks open-source tool for running AI coding agents on a developers machine, let a sandboxed agent turn off its own sandbox with a single command.The tool runs an agents commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace.

https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html


Keine Panik: Zahlungsaufforderung vom Hansevia Forderungsmanagement ist ein Fake!

Eine E-Mail mit bedrohlich klingendem Betreff. Eine Forderung über mehrere tausend Euro. Ein angeblich bestehendes Dienstleistungsverhältnis mit Euromillion24. Aus diesen Bestandteilen bauen Kriminelle aktuell ein Phishing-Kartenhaus, das bei genauerem Hinsehen sehr rasch in sich zusammenfällt.

https://www.watchlist-internet.at/news/zahlungsaufforderung-hansevia-forderungsmanagement-fake/


Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. Tracked as CL-CRI-1171, in accordance with Unit 42-s attribution framework, the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads.

https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/


Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.

https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf


Reverse engineering my e-scooter and rewriting the firmware in rust

I reverse engineered the hardware and firmware of my Egret GT E-Scooter. I describe how I got in, analysed communication between components, and reverse engineered firmware. I speak about writing custom firmware for the display unit.

https://bensimms.moe/reverse-engineering-scooter/

Vulnerabilities

Microsoft Exchange Server: Sicherheitsupdates 8. September 2026

Microsoft hat zum 8. September 2026 Sicherheitsupdates (SU) für "September 2026" veröffentlicht. Diese Updates stehen für Exchange Server 2016 / 2019 (ESU) sowie für Exchange Server Subscription Edition (SE) zur Verfügung.

https://borncity.com/blog/2026/09/09/exchange-server-sicherheitsupdates-8-september-2026/


Microsoft Patchday: Windows Server-Updates (8. September 2026)

Zum 8. September 2026 (zweiter Dienstag im Monat, Patchday bei Microsoft) wurden verschiedene kumulative Updates für die unterstützten Versionen von Windows Server freigegeben. Nachfolgend habe ich die bereitgestellten Updates samt einigen Details für diese Windows Server-Versionen herausgezogen.

https://borncity.com/blog/2026/09/09/patchday-windows-server-updates-8-september-2026/


Microsoft Patchday: Windows 10/11 Updates (8. September 2026)

Am 8. September 2026 (zweiter Dienstag im Monat, Patchday bei Microsoft) hat Microsoft kumulative Updates für die noch unterstützten Client-Betriebssystem-Versionen von Windows 10 (mit ESU-Lizenz) und Windows 11 veröffentlicht. Hier einige Details zu diesen Updates, die Schwachstellen sowie Probleme beheben.

https://borncity.com/blog/2026/09/09/patchday-windows-10-11-updates-8-september-2026/


Adobe September-Patchday: Adobe schließt kritische Zero-Day-Lücke und 172 weitere

Im Zentrum der Adobe-Patch-Welle steht das Update für Adobe Commerce, das bereits akut angegriffen wird. Besonders viele Updates betreffen Experience Manager.

https://heise.de/-11446552


Android: Patchday: Kritische Lücken ermöglichen Attacken auf Android 14, 15, 16 und 17

Der September-Patchday für Android schließt über 90 Sicherheitslücken, darunter mehr als 25 kritische Schwachstellen in Framework, System und Kernel.

https://heise.de/-11446782


Samsung Sicherheits-Updates: Samsung verteilt Patches für Galaxy-Smartphones

Samsung hat sein Security-Bulletin für September 2026 veröffentlicht. Der Hersteller verteilt 90 Sicherheitspatches für zahlreiche Galaxy-Geräte.

https://heise.de/-11447042


cPanel: Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026

https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026


Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW


LWN: Security updates for Wednesday

https://lwn.net/Articles/1093342/


Fortinet: Improper Authentication of FortiPAM Server

https://fortiguard.fortinet.com/psirt/FG-IR-26-168


Fortinet: JWT used for authentication in web GUI signed with static key

https://fortiguard.fortinet.com/psirt/FG-IR-26-170


Fortinet: Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

https://fortiguard.fortinet.com/psirt/FG-IR-26-166