Timeframe: Dienstag 06-10-2026 18:00 – Mittwoch 07-10-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
News
Betrug in zwei Akten: Die nächste Runde im Klimabonus-Phishing
Sie hat sich als neuer Stammgast in unseren Warnmeldungen etabliert: Die Klimabonus-Phishingattacke. In der aktuellen Welle stehen nicht vordergründig Geld oder Kontozugriff im Mittelpunkt. Im ersten Schritt geht es zunächst um das Abgreifen sensibler Daten. Im zweiten Schritt läutet dann das Telefon. Am anderen Ende: Die Kriminellen.
https://www.watchlist-internet.at/news/datenfalle-naechste-runde-klimabonus/
Hackers obtain counterfeit TLS certificates for Google and other large services
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
Hackers exploit critical Atlassian flaw after public PoC release
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. [..] In a security advisory on Monday, Atlassian warned system administrators managing self-hosted instances to apply the security updates as soon as possible, noting it cannot determine whether individual customer instances have been compromised.
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.
https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries.
KVM 0-Day-Schwachstelle ermöglicht Host-Zugriff
Ein Sicherheitsforscher will eine 0-Day-Schwachstelle aufgedeckt haben, die einen Ausbruch aus KVM auf den Host ermöglicht. Meinen Informationen nach hat ein weiterer Sicherheitsforscher das Ganze bestätigt. Eine CVE-Nummer gibt es m.W. noch nicht. [..] Derzeit sind aber noch keine Details bekannt (welche Linux-Kernel-Versionen betroffen sind), und es gibt noch keinen CVE. Auch ist der Exploit nicht öffentlich, und es gibt keine bestätigte Ausnutzung in der Praxis. Vercel kündigt einen vollständigen technischen Bericht an.
https://borncity.com/blog/2026/10/06/kvm-0-day-schwachstelle-ermoeglicht-host-zugriff/
Sicherheitslücke in Sungrow-Komponente ermöglichte Solaranlagen abzuschalten
Viele Solaranlagen weltweit, aber auch in Deutschland, verwenden Wechselrichter und Bauteile der chinesischen Anbieter Huawei und Songrow (ist billiger als SMA). Und natürlich muss alles "in der Cloud" der betreffenden Anbieter hängen. Beim chinesischen Anbieter Sungrow nennt sich die Cloud iSolarCloud. Einem aufmerksamen Sicherheitsforscher ist aufgefallen, dass er über eine Schwachstelle die Kontrolle über europäische Solaranlagen mit ca. 10 Gigawatt Nennleistung erlangen konnte.
Vulnerabilities
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls.
WordPress 7.1.3 Maintenance and Security Release
https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-secu
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Lesen Sie den originalen Artikel: