Tageszusammenfassung - 23.09.2026

End-of-Day report

Timeframe: Dienstag 22-09-2026 18:00 - Mittwoch 23-09-2026 18:00 Handler: Guenes Holler Co-Handler: n/a

News

Ab 1.10: Meldepflicht für IT-Vorfälle in Österreich

Die NIS-2-Richtlinie beschert Österreich Registrierungspflichten für Unternehmen und Behörden. Diese erhalten Zuwachs: Das neue Bundesamt für Cybersicherheit.

https://www.heise.de/news/Ab-1-10-Meldepflicht-fuer-IT-Vorfaelle-in-Oesterreich-11462442.html


Gefälschter FinanzOnline-Mail: 3.612 Euro Steuererstattung versprochen

Mit einer neuen Variante des bekannten FinanzOnline-Phishings versuchen Kriminelle derzeit, an Bankdaten von Österreicher:innen zu gelangen. In einer gefälschten E-Mail wird eine Steuererstattung von 3.612 Euro versprochen.

https://www.watchlist-internet.at/news/gefaelschter-finanzonline-mail/


Hacker dringen in Systeme von Fresenius Medical Care ein

Medizinische Geräte, Patientenversorgung, Produktion und laufender Geschäftsbetrieb sollen laut Konzern nicht beeinträchtigt sein.

https://www.derstandard.at/story/3000000340976/hacker-dringen-in-systeme-von-fresenius-medical-care-ein


Microsoft: September Windows updates break Always On VPN connections

Microsoft has notified IT administrators that users may experience Always On VPN connection issues after installing the September 2026 Windows 11 security updates.

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/


Absturzgefahr: Exploit lässt Angreifer DJI-Drohnen mitten im Flug kapern

Mehrere Drohnenmodelle des Herstellers DJI sind anfällig für eine gefährliche Sicherheitslücke, die eine vollständige Kontrollübernahme ermöglicht. Nutzer sollten nach korrigierten Firmware-Versionen Ausschau halten.

https://www.golem.de/news/per-bluetooth-exploit-laesst-angreifer-dji-drohnen-mitten-im-flug-kapern-2609-213353.html


Macfinger ClickFix campaign, (Tue, Sep 22nd)

I've found several legitimate websites with injected script for a campaign using the ClickFix social engineering technique. This particular ClickFix campaign was documented earlier this month on the Ransom-ISAC Blog, but it doesn't appear to have a nickname yet. Since this campaign is targeting macOS environments through a fingerprinting process, I'm calling it the "Macfinger ClickFix" campaign. No, this is not related to the MacFinger utility from decades ago. Instead, think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore.

https://isc.sans.edu/diary/rss/33360


Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

A use-after-free in the Linux kernels AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases.

https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html


Recent Increase of Hybrid Attacks Against Defense Sector in Europe

Recently, a wave of sabotage attacks has been reported in Europe. In most cases Russia is suspected to be responsible. These events follow a broader pattern of hybrid activity directed at European infrastructure, logistics networks, and organizations supporting Ukraine.

https://www.truesec.com/hub/blog/recent-increase-of-hybrid-attacks-against-defense-sector-in-europe


Iranian Cyber Espionage Campaign

An Iranian threat actor is conducting a cyber espionage campaign targeting Iranian nationals abroad. The attacker reaches out to the victim on various messaging apps, like Telegram or Whatsapp. The actor often claims to be an individual previously known to the target or technical support from the social messaging platform.

https://www.truesec.com/hub/blog/iranian-cyber-espionage-campaign

Vulnerabilities

Cyberangriffe auf F5 BIG-IP, Check Point Security und Arista VeloCloud

IT-Verantwortliche müssen rasch handeln, um bereitgestellte Aktualisierungen zu installieren. Mehrere IT-Sicherheitsbehörden warnen vor derzeit laufenden Angriffen auf Sicherheitslücken in F5 BIG-IP, Check Point Security Gateway und Management sowie Arista VeloCloud Orchestrator On-Premise.

https://heise.de/-11462590


Patchday: Adobe Connect ist unter Android, macOS und Windows verwundbar

Es sind wichtige Sicherheitsupdates für verschiedene Adobe-Anwendungen erschienen.

https://heise.de/-11462802


NetBSD 10.2 stopft einige Sicherheitslücken

NetBSD ist jüngst als Point-Release 10.2 erschienen. Die Entwickler schließen damit einige Sicherheitslücken.

https://heise.de/-11463028


Gleich noch ein Sicherheitsupdate für WordPress

Angreifer können WordPress dazu bringen, nicht vorgesehene .php-Dateien aufzurufen. Das kann zur Ausführung von Code führen.

https://heise.de/-11462385


Ubiquiti schließt Denial-of-Service-Lücken in Firewalls und Gateways

In UniFi-Firewalls und -Gateways klaffen hochriskante Denial-of-Service-Lücken. Aktualisierte Firmware stopft die Lecks.

https://heise.de/-11463176


LWN Security updates for Wednesday

https://lwn.net/Articles/1096191/