Tageszusammenfassung – 08.10.2026

End-of-Day report

Timeframe: Mittwoch 07-10-2026 18:00 – Donnerstag 08-10-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a

News

Pensionsleistung genehmigt: 723-Euro-Versprechen ist Phishing

Betrügerische Nachrichten im Namen der Pensionsversicherung gab es schon vor einiger Zeit per SMS, jetzt landen sie auch im E-Mail-Postfach. Die Masche: Eine angebliche Auszahlung soll Empfänger:innen zur Preisgabe ihrer Bankdaten bringen.

https://www.watchlist-internet.at/news/pensionsleistung-genehmigt-723-euro/

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself.

https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

Quoth the LLM, More and more.

https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers/5301672

16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials

Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

https://socket.dev/blog/firefox-crypto-wallet-stealers?utm_medium=feed

TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack

Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

https://socket.dev/blog/tensorlake-compromise?utm_medium=feed

Chinesische Wechselrichter: Nur ein Hack bis zum Blackout

250.000 Solaranlagen in Deutschland nutzen Wechselrichter mit einer kritischen Sicherheitslücke. Ein Kollaps des Stromnetzes wäre einfach.

https://www.golem.de/news/chinesische-wechselrichter-nur-ein-hack-bis-zum-blackout-2610-213859.html

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available.

https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html

Vulnerabilities

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.

https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/

Veeam stopft Schadcode-Lücke in Backup & Replication

Veeam hat Backup & Replication aktualisiert und dabei vier Sicherheitslücken geschlossen. Schmuggeln von Schadcode auf den Server ist möglich.

https://www.heise.de/news/Veeam-stopft-Schadcode-Luecke-in-Backup-Replication-11480790.html

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos- Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.

https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabilities/

LWN Security updates for Thursday

https://lwn.net/Articles/1099388/

Zahlreiche kritische Schwachstellen in mehreren TP-Link Geräteserien

https://sec-consult.com/de/vulnerability-lab/advisory/zahlreiche-kritische-schwachstellen-in-mehreren-tp-link-geraeteserien/

Dieser Artikel wurde indexiert von CERT.at – All

Lesen Sie den originalen Artikel: