Tageszusammenfassung - 14.09.2026

End-of-Day report

Timeframe: Freitag 11-09-2026 18:00 - Montag 14-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a

News

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118. [..] The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.

https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/

Security through obscurity is dead, and AI delivered the fatal blow

The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. [..] During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS).

https://www.theregister.com/security/2026/09/13/security-through-obscurity-is-dead-and-ai-delivered-the-fatal-blow/5296000

Perfect-10 GitLab bug under attack days after patch lands

CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10.

https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands/5296176

Wie ein Wiener eine KI-Spionagesoftware von Anthropic stoppte

Künstliche Intelligenz lud Schadsoftware auf eine Plattform mit Millionen Nutzern. Ein Cybersicherheitsforscher aus Österreich verhinderte, dass sie sich weiter verbreiten konnte.

https://www.derstandard.at/story/3000000339589/wie-ein-wiener-eine-ki-spionagesoftware-von-anthropic-stoppte

Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.

https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/

Webseite BGP.Exchange kompromittiert (12. Sept. 2026)

Der Anbieter der Seite BGP.Exchange ist gehackt worden, die Webseite ist kompromittiert. Zum 12. September 2026 zeigt die Webseite ein "Defacement" und es wird wohl auch "Schund" über deren Mail-System verschickt.

https://borncity.com/blog/2026/09/12/webseite-bgp-exchange-kompromittiert-12-sept-2026/

Datenleck: Revolut gibt sensible Nutzerdaten an Angreifer

ie Bank ist auf eine gefälschte Datenanforderung einer angeblichen Behörde hereingefallen und hat sensible Kundendaten (Ausweiskopien etc.) an Betrüger herausgegeben. [..] Die potenziell offengelegten Daten umfassen Kopien von Pässen und Führerscheinen, Selfies zur Identitätsprüfung sowie persönliche Informationen (Namen, Geburtsdaten, Berufe, Postadressen, E-Mail-Adressen und Telefonnummern). Auch finanzielle Daten (IBAN, Kontoauszüge und vollständige Transaktionshistorien, einschließlich Bitcoin-Operationen) sind angeblich betroffen.

https://borncity.com/blog/2026/09/13/datenleck-revolut-gibt-sensible-nutzerdaten-an-angreifer/

The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37]

Until May 2025, I liked PGP, and the GNU Privacy Guard. I poked at it in my free time a lot. One day, that suddenly changed, when I flew too close to the sun and ended up uncovering a vulnerability that allows you to easily spoof a PGP signature when opened naively with the GPG tool. [..] I disclosed these a few weeks before 39c3 in December 2025. And while some of the vulnerabilities - like the memory corruption in the message parser - got addressed properly, this was not the case for all of them.

https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-disclosure-gpg-and-the-state-of-security-in-2026

Vulnerabilities

LWN: Security updates for Monday

https://lwn.net/Articles/1094211/