End-of-Day report
Timeframe: Dienstag 22-09-2026 18:00 - Mittwoch 23-09-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
News
Ab 1.10: Meldepflicht für IT-Vorfälle in Österreich
Die NIS-2-Richtlinie beschert Österreich Registrierungspflichten für Unternehmen und Behörden. Diese erhalten Zuwachs: Das neue Bundesamt für Cybersicherheit.
https://www.heise.de/news/Ab-1-10-Meldepflicht-fuer-IT-Vorfaelle-in-Oesterreich-11462442.html
Gefälschter FinanzOnline-Mail: 3.612 Euro Steuererstattung versprochen
Mit einer neuen Variante des bekannten FinanzOnline-Phishings versuchen Kriminelle derzeit, an Bankdaten von Österreicher:innen zu gelangen. In einer gefälschten E-Mail wird eine Steuererstattung von 3.612 Euro versprochen.
https://www.watchlist-internet.at/news/gefaelschter-finanzonline-mail/
Hacker dringen in Systeme von Fresenius Medical Care ein
Medizinische Geräte, Patientenversorgung, Produktion und laufender Geschäftsbetrieb sollen laut Konzern nicht beeinträchtigt sein.
https://www.derstandard.at/story/3000000340976/hacker-dringen-in-systeme-von-fresenius-medical-care-ein
Microsoft: September Windows updates break Always On VPN connections
Microsoft has notified IT administrators that users may experience Always On VPN connection issues after installing the September 2026 Windows 11 security updates.
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/
Absturzgefahr: Exploit lässt Angreifer DJI-Drohnen mitten im Flug kapern
Mehrere Drohnenmodelle des Herstellers DJI sind anfällig für eine gefährliche Sicherheitslücke, die eine vollständige Kontrollübernahme ermöglicht. Nutzer sollten nach korrigierten Firmware-Versionen Ausschau halten.
https://www.golem.de/news/per-bluetooth-exploit-laesst-angreifer-dji-drohnen-mitten-im-flug-kapern-2609-213353.html
Macfinger ClickFix campaign, (Tue, Sep 22nd)
I've found several legitimate websites with injected script for a campaign using the ClickFix social engineering technique. This particular ClickFix campaign was documented earlier this month on the Ransom-ISAC Blog, but it doesn't appear to have a nickname yet. Since this campaign is targeting macOS environments through a fingerprinting process, I'm calling it the "Macfinger ClickFix" campaign. No, this is not related to the MacFinger utility from decades ago. Instead, think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore.
https://isc.sans.edu/diary/rss/33360
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernels AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases.
https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html
Recent Increase of Hybrid Attacks Against Defense Sector in Europe
Recently, a wave of sabotage attacks has been reported in Europe. In most cases Russia is suspected to be responsible. These events follow a broader pattern of hybrid activity directed at European infrastructure, logistics networks, and organizations supporting Ukraine.
https://www.truesec.com/hub/blog/recent-increase-of-hybrid-attacks-against-defense-sector-in-europe
Iranian Cyber Espionage Campaign
An Iranian threat actor is conducting a cyber espionage campaign targeting Iranian nationals abroad. The attacker reaches out to the victim on various messaging apps, like Telegram or Whatsapp. The actor often claims to be an individual previously known to the target or technical support from the social messaging platform.
https://www.truesec.com/hub/blog/iranian-cyber-espionage-campaign
Vulnerabilities
Cyberangriffe auf F5 BIG-IP, Check Point Security und Arista VeloCloud
IT-Verantwortliche müssen rasch handeln, um bereitgestellte Aktualisierungen zu installieren. Mehrere IT-Sicherheitsbehörden warnen vor derzeit laufenden Angriffen auf Sicherheitslücken in F5 BIG-IP, Check Point Security Gateway und Management sowie Arista VeloCloud Orchestrator On-Premise.
https://heise.de/-11462590
Patchday: Adobe Connect ist unter Android, macOS und Windows verwundbar
Es sind wichtige Sicherheitsupdates für verschiedene Adobe-Anwendungen erschienen.
https://heise.de/-11462802
NetBSD 10.2 stopft einige Sicherheitslücken
NetBSD ist jüngst als Point-Release 10.2 erschienen. Die Entwickler schließen damit einige Sicherheitslücken.
https://heise.de/-11463028
Gleich noch ein Sicherheitsupdate für WordPress
Angreifer können WordPress dazu bringen, nicht vorgesehene .php-Dateien aufzurufen. Das kann zur Ausführung von Code führen.
https://heise.de/-11462385
Ubiquiti schließt Denial-of-Service-Lücken in Firewalls und Gateways
In UniFi-Firewalls und -Gateways klaffen hochriskante Denial-of-Service-Lücken. Aktualisierte Firmware stopft die Lecks.
https://heise.de/-11463176
LWN Security updates for Wednesday
https://lwn.net/Articles/1096191/