Tageszusammenfassung – 09.10.2026

End-of-Day report

Timeframe: Donnerstag 08-10-2026 18:00 – Freitag 09-10-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a

News

Microsoft: Outdated Windows devices will stop receiving security updates

Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation.

https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors.

https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a

Low-cost Android phones ship with residential proxy malware

A malware campaign dubbed Midnight Mimosa has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.

https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/

Cyberangriffe auf Banken: Hacker nutzt KI und hinterlässt Accountdaten

Der Angreifer ist aufgeflogen, weil er offene und ungesicherte Webverzeichnisse auf seiner Server-Infrastruktur betrieb.

https://www.golem.de/news/cyberangriffe-auf-banken-hacker-nutzt-ki-und-hinterlaesst-accountdaten-2610-213941.html

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security advisory.

https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html

Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware

IntroductionIn July 2026, Zscaler ThreatLabz uncovered a campaign linked to TraderTraitor (also tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces), an advanced persistent threat actor backed by the North Korean government that has targeted the cryptocurrency industry for years. This campaign also significantly overlaps with the previously reported KelpDAO incident, the analysis of which discussed both FLATROOF and ROOFDECK, two malware families also observed in this campaign.

https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver

Aktion gegen Phishing: Heuer bereits 19 Millionen Euro Schaden

5000 Fälle hat das Bundeskriminalamt bereits gezählt. Die Aktion "10 Tage gegen Phishing" ist am Freitag gestartet.

https://www.derstandard.at/story/3000000343493/aktion-gegen-phishing-heuer-bereits-19-millionen-euro-schaden

New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials

A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

https://socket.dev/blog/ghostaction-cloud-credentials?utm_medium=feed

Datenleck: 9 GByte Redaktions- und Nutzerdaten von Nius frei zugänglich

Unbekannte stellen die Nius-Daten nach einem Hackerangriff ins Netz. Sie enthalten auch Informationen über Gesprächspartner der Redaktion.

https://www.golem.de/news/datenleck-9-gbyte-redaktions-und-nutzerdaten-von-nius-frei-zugaenglich-2610-213910.html

Kostenlose TLS-Zertifikate: Lets Encrypt verkürzt Gültigkeit auf 64 Tage

Ab 2028 sinkt die Gültigkeitsdauer auf 45 Tage. Lets Encrypt will so das Risko von Schlüsselkompromittierungen reduzieren.

https://www.golem.de/news/kostenlose-tls-zertifikate-let-s-encrypt-verkuerzt-gueltigkeit-auf-64-tage-2610-213925.html

Vulnerabilities

Weitere kritische Sicherheitslücke in Citrix NetScaler ADC und NetScaler Gateway – Updates verfügbar

Citrix hat ein Security Bulletin zu einer kritischen Sicherheitslücke in Citrix NetScaler ADC und Citrix NetScaler Gateway veröffentlicht. Es handelt sich um einen Speicherüberlauf, der zur Ausführung von beliebigem Code aus der Ferne (Remote Code Execution) oder zu einem Denial-of-Service (DoS) führen kann. Voraussetzung ist, dass das Gerät als SAML Service Provider (SP) oder SAML Identity

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

Dieser Artikel wurde indexiert von CERT.at – All

Lesen Sie den originalen Artikel: