Tageszusammenfassung - 10.09.2026

End-of-Day report

Timeframe: Mittwoch 09-09-2026 18:00 - Donnerstag 10-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

ID-Austria Phishing als Türöffner für falschen Bankanruf

-Jemand aus dem Ausland möchte Geld von Ihrem Konto abbuchen!- Mit dieser Behauptung schrecken Kriminelle derzeit auf. Sie geben sich am Telefon als Bankmitarbeiter:innen aus und überreden ihre Opfer, Geld auf ein vermeintlich sicheres Konto zu überweisen.

https://www.watchlist-internet.at/news/id-austria-phishing-bankanruf/


OpenAI-Agenten haben auf mehr als 10 weiteren Websites unerlaubt kommuniziert

KI-Agenten, die von OpenAI lediglich mit Internetrecherchen beauftragt und denen das Veröffentlichen eigener Beiträge untersagt war, haben weit mehr als nur eine Website zur Diskussion genutzt. Verschiedene unabhängige Sicherheitsforscher haben die ausgebrochenen OpenAI-Agenten auf mehr als zehn weiteren Webseiten gefunden. Dort haben diese größtenteils Wiki-Bereiche zum unerlaubten Austausch von Nachrichten verwendet.

https://www.heise.de/news/OpenAI-Agenten-haben-auf-mehr-als-10-weiteren-Websites-unerlaubt-kommuniziert-11448157.html


Vierter Hacking-Vorfall: Weiteres Anthropic-Modell bricht aus Testumgebung aus

In einem aktuellen Blog-Beitrag meldet Anthropic einen weiteren Hacking-Vorfall, der sich im Januar mit einer Vorabversion von Claude Opus 4.6 ereignet haben soll. Es ist der vierte Vorfall dieser Art.

https://www.heise.de/news/Vierter-Hacking-Vorfall-Weiteres-Anthropic-Modell-bricht-aus-Testumgebung-aus-11449182.html


Scans for Proxmox Servers, (Wed, Sep 9th)

About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.

https://isc.sans.edu/diary/rss/33324


Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco-s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco-s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account. [..] IOCs for these threat clusters are also available on our GitHub repository here.

https://blog.talosintelligence.com/fmc-ongoing-exploitation/


Sicherheitslücken: 36.000 Plex-Media-Server-Instanzen potenziell angreifbar

In aktuellen Versionen von Plex Media Server und Plex Desktop wurden mehrere Schwachstellen geschlossen. Weltweit sind zehntausende Instanzen angreifbar.

https://heise.de/-11448584


Safe word: What is it and why do you need one?

AI scams are now hyper-realistic. But there-s one simple way to see through them.

https://www.welivesecurity.com/en/cybersecurity/safe-word-what-why-need-one/


Passkey-themed social engineering leads to identity and cloud compromise

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance.

https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/


Threat matrix: Mapping threats across cloud web applications

Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.

https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/


SloppyRAT: A New Tool For Ransomware Attacks

In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques. [..] In the following sections, ThreatLabz provides a technical analysis of SloppyRAT, including its infection vector, anti-analysis techniques, network protocol, and command execution functionality.

https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks


The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

This research demonstrates post-exploitation techniques that could allow an attacker with root access on a compromised Kubernetes node to misuse an open standard and reference implementation for machine identity known as SPIFFE/SPIRE to impersonate co-located workloads and harvest SPIFFE Verifiable Identity Documents (SVIDs).

https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/


Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise

How default keys, unauthenticated MCP sessions, and custom code guardrails expose cloud AI infrastructure to root-level remote code execution and IAM theft.

https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise

Vulnerabilities

Palo Alto Networks Security Advisories 09.09.2026

Palo Alto released 10 new security advisories (2x high severity).

https://security.paloaltonetworks.com/


Drupal Security Advisories 2026-September-09

Drupal released 20 new security advisories (9x critical severity).

https://www.drupal.org/security


Checkpoint: CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN

Product: Security Gateway, Spark Firewall (Centrally Managed), Spark Firewall (Locally Managed). Issue: Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway. This issue received the ID CVE-2026-85102 with CVSS: 9.8.

https://support.checkpoint.com/results/sk/sk1000117/


Checkpoint: CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution

Product: Security Gateway, Security Management Server, Spark Firewall (Centrally Managed), Spark Firewall (Locally Managed). Issue: A heap overflow in the VPN certificate ASN.1 decoding flow may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway. This issue received the ID CVE-2026-85103 with CVSS: 9.8.

https://support.checkpoint.com/results/sk/sk1000118/


ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-26-657/


LWN: Security updates for Thursday

https://lwn.net/Articles/1093566/