Tageszusammenfassung – 05.10.2026

End-of-Day report

Timeframe: Freitag 02-10-2026 18:00 – Montag 05-10-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer

News

Cyberangriff: Antriebssystem eines Öl-Supertankers gehackt

Unbekannte haben offenbar im Sommer Zugriff auf das Antriebssystem eines Öl-Supertankers gehabt, als dieser sich der Küste des US-Bundestaats Texas näherte. Das berichtet Transport Topics unter Berufung auf nicht näher genannte Quellen bei US-Behörden. Der Vorfall, der als Cyberangriff eingestuft wird, wird demnach von der US-Bundespolizei FBI sowie der US-Küstenwache untersucht.

https://www.golem.de/news/cyberangriff-antriebssystem-eines-oel-supertankers-gehackt-2610-213707.html

OpenAI alerts 100+ orgs that its misaligned models attempted to break in – or worse

OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman-s company saying it has notified more than 100 organizations about potentially problematic model activity.

https://www.theregister.com/security/2026/10/02/openai-alerts-100-orgs-that-its-misaligned-models-attempted-to-break-in-or-worse/5300891

Create automatic IP blocklist in OPNsense based on MISP data

This blog post is about creating an automatic IP blocklist in OPNsense based on MISP data, including data retention.

https://lithilion.at/blog/2026-10-misp-blocklisting.html

Nach Muse: Auch ChatGPT-App für macOS war angreifbar

Agentische Tools, die direkt auf dem Rechner laufen, benötigen oft weitreichende Zugriffsrechte. Das macht sie potenziell angreifbar. Nachdem der macOS-Security-Spezialist Patrick Wardle kürzlich eine potenziell durch Dritte ausnutzbare Hintertür in Metas Muse-App für den Mac entdeckt hatte, warnt dieser nun vor einem ähnlichen Problem in der konkurrierenden ChatGPT-App für macOS von OpenAI: Auch hier war es Angreifern möglich, sensible Informationen abzugreifen. [..] OpenAI hat das Problem Ende September mit einer Aktualisierung behoben, nachdem Wardle das Unternehmen darüber informiert hatte.

https://www.heise.de/news/Nach-Muse-Auch-ChatGPT-App-fuer-macOS-war-angreifbar-11475385.html

Raiffeisen-Phishing: Vorsicht bei Mitteilung zu neuem Dauerauftrag

Aktuell kursiert eine Phishing-Mail im Namen von Raiffeisen. Sie behauptet, ein neuer Dauerauftrag sei eingerichtet worden und müsse geprüft werden. Wer dem Link folgt, landet auf einer gefälschten Seite und soll dort seine Daten preisgeben.

https://www.watchlist-internet.at/news/raiffeisen-mail-zu-dauerauftrag/

N0n ransomware: what you need to know

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow.

https://www.fortra.com/blog/n0n-ransomware-what-you-need-know

Japan Plans Major Cyber Hunt to Detect Hidden Attacks on Critical Infrastructure

Japan is stepping up its plans to find cyber attackers who may already be inside the networks that keep essential services running. Under a new fiscal 2027 initiative, the government plans to work with private companies to strengthen Japan threat hunting across critical infrastructure, including power utilities and telecommunications operators.

https://thecyberexpress.com/japan-threat-hunting-plan/

Google Suspends Open Source Bug Bounty Over AI-Generated Reports

Google has suspended its Open Source Software Vulnerability Rewards Program (OSS VRP), a vulnerability search initiative that paid researchers for finding flaws in the companys open-source software. The pause took effect on October 1, 2026. Google blamed a "significant rise" in automated and AI-generated reports, most of which turned out to be invalid.

https://thecyberexpress.com/google-pauses-oss-vrp-over-ai-submissions/

Vulnerabilities

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0." [..] For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP).

https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html

Microsoft schiebt Exchange-Update nach

Zum Wochenende hat Microsoft weitere Exchange-Updates nachgelegt. [..] Aufgrund einer schwachen Autorisierung in Microsofts Exchange-Server können authentifizierte Angreifer aus dem Netz ihre Rechte ausweiten. Die Entwickler führen aus, dass bösartige Akteure dadurch unbefugten Zugriff auf Mailboxen anderer User erlangen und E-Mails und Anhänge daran lesen können. Tenant-Grenzen lassen sich dadurch jedoch nicht

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

Dieser Artikel wurde indexiert von CERT.at – All

Lesen Sie den originalen Artikel: