Timeframe: Mittwoch 07-10-2026 18:00 – Donnerstag 08-10-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
News
Pensionsleistung genehmigt: 723-Euro-Versprechen ist Phishing
Betrügerische Nachrichten im Namen der Pensionsversicherung gab es schon vor einiger Zeit per SMS, jetzt landen sie auch im E-Mail-Postfach. Die Masche: Eine angebliche Auszahlung soll Empfänger:innen zur Preisgabe ihrer Bankdaten bringen.
https://www.watchlist-internet.at/news/pensionsleistung-genehmigt-723-euro/
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself.
https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
Quoth the LLM, More and more.
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
https://socket.dev/blog/firefox-crypto-wallet-stealers?utm_medium=feed
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
https://socket.dev/blog/tensorlake-compromise?utm_medium=feed
Chinesische Wechselrichter: Nur ein Hack bis zum Blackout
250.000 Solaranlagen in Deutschland nutzen Wechselrichter mit einer kritischen Sicherheitslücke. Ein Kollaps des Stromnetzes wäre einfach.
https://www.golem.de/news/chinesische-wechselrichter-nur-ein-hack-bis-zum-blackout-2610-213859.html
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available.
https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
Vulnerabilities
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
Veeam stopft Schadcode-Lücke in Backup & Replication
Veeam hat Backup & Replication aktualisiert und dabei vier Sicherheitslücken geschlossen. Schmuggeln von Schadcode auf den Server ist möglich.
https://www.heise.de/news/Veeam-stopft-Schadcode-Luecke-in-Backup-Replication-11480790.html
Microsoft, Adobe, Apple, and Foxit vulnerabilities
Cisco Talos- Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.
https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabilities/
LWN Security updates for Thursday
https://lwn.net/Articles/1099388/
Zahlreiche kritische Schwachstellen in mehreren TP-Link Geräteserien
Lesen Sie den originalen Artikel: