Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Security news weekly round-up - 19th September 2025

Throughout history, attackers have shown that they are ready to compromise users using malware, vulnerabilities, or exploiting poor security practices. Whichever method they chose, it's known that determined attackers always seem to find a…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Throughout history, attackers have shown that they are ready to compromise users using malware, vulnerabilities, or exploiting poor security practices. Whichever method they chose, it's known that determined attackers always seem to find a way into a target network or system.









ChatGPT Targeted in Server-Side Data Theft Attack



Don't even think that you're going to try and exploit the flaw. Why? At the time of writing, OpenAI has fixed the bug. Nonetheless, you can ask: What's the bug about? The excerpt below will surely answer your question.




The attack, dubbed ShadowLeak, targeted ChatGPT’s Deep Research capability, which is designed to conduct multi-step research for complex tasks.



Unlike client-side attacks, ShadowLeak exfiltrates data through the parameters of a request to an attacker-controlled URL. A harmless-looking URL such as ‘hr-service.net/{parameters}’, where the parameter value is the exfiltrated information.







How weak passwords and other failings led to catastrophic breach of Ascension



We all know that organizations can suffer breaches and ransomware attacks. Meanwhile, it gets interesting when a company like Microsoft is pulled into the mix for alleged negligence that played a role in the breach at Ascension.



The following is a quick lesson from the article:




All the boring, unsexy but effective security stuff was missing—network segmentation, principle of least privilege, need to know and even the kind of asset tiering recommended by Microsoft.



It's obviously not great that obsolete ciphers are still in use and they do help with this attack, but excessive privileges are much more dangerous.







SystemBC malware turns infected VPS systems into proxy highway



SystemBC is not new (it's been observed since around 2019), and it serves multiple threat actors. Its infected servers act as stable, high-capacity proxies for activities such as scraping the web, brute-forcing WordPress credentials, and hiding command-and-control operations.



From the article:




Based on the researchers’ findings, neither customers nor operators of SystemBC care about keeping a low profile, since the bots’ IP addresses are not protected in any way (e.g. through obfuscation or rotation).



One malicious service called REM Proxy relies on around 80% of SystemBC’s bots, providing tiered services to its customers, depending on the required proxy quality.







Threat Actor Infests Hotels With New RAT



Reading this article reminds me of Kaspersky's 2014 report titled DarkHotel: A Story of Unusual Hospitality. There is no real connection between these incidents. But it shows that threat actors are still targeting hotels in 2025 and Kaspersky is still exposing them to the world.



According to Kaspersky, here is how this attack unfolds:




The attacks started with phishing emails with invoicing lures targeting hotel reservations, urging the recipient to take care of overdue payments. More recently, the attackers started using fake job applications, sending résumés to the targeted hotels.



The victims were redirected to websites hosting malicious scripts containing code generated by AI. These scripts were designed to load additional scripts that would trigger malware infection.







Credits



Cover photo by Debby Hudson on Unsplash.






That's it for this week, and I'll see you next time.

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Ransomware Outbreak Containment
Syntax validiert (0 Fehler)
title: Detect Exploitation - Security news weekly round-up - 19th September 2025
id: fcd8594d-cb51-4f57-8057-8ed14c0367f2
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
  - attack.t1486
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "Security news weekly round-up " ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Security news weekly round-up - 19th Sep")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Security news weekly round-up - 19th Sep*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Security news weekly round-up - 19th Sep"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph5 Knoten / 4 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Identifiziert: T1486Data Encrypted for Impact (Ransomware)
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Security news weekly round-up - 19th Sep.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Security news weekly round-up - 19th September 2025

Thematisch verwandte Begriffe: Security, news, weekly, roundup · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-63208 | Zammad is a web based open source helpdesk/customer support system. Prio…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag