Summary: F5 released engineering hotfixes for CVE-2026-94127, a heap-based buffer overflow (CVSS 9.8) in BIG-IP Access Policy Manager when configured as an OAuth Authorization Server with an access policy and OAuth profile on the same virtual server. The flaw enables unauthenticated remote code execution via crafted traffic to the virtual server; Appliance mode is also affected. F5 confirmed exploitation in the wild; CISA added it to the KEV catalog with a Sept. 25 remediation deadline for federal agencies.
Key takeaway / Actionable note: Immediately identify APM OAuth Authorization Server virtual servers, apply the matching Hotfix-BIGIP builds (or temporary iRule from F5 Support), and hunt for repeated OAuth failures followed by suspicious commands and TMM SIGABRT.
Summary: Check Point released urgent fixes for CVE-2026-93616 (CVSS 9.8), a pre-authentication directory traversal and file-upload vulnerability in Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Unauthenticated attackers can upload and execute arbitrary scripts; the company confirmed a handful of customers were attacked, with exploitation observed as early as July. Fixes are available as R82.20 Security Hotfix and specific Jumbo Hotfix Takes; LivePatch does not address it.
Key takeaway / Actionable note: Apply the relevant hotfix immediately, restrict Management Server access (especially TCP/19009) to trusted IPs, and check for the IoCs provided in Check Point’s advisory.
Summary: ShinyHunters claimed on its dark-web site that it compromised FBI systems (including Criminal Justice, HR, and Medlink services) and holds sensitive data on nearly all agents and job applicants. The group said it used a new Oracle PeopleSoft zero-day for RCE and defaced the FBI jobs portal; the site currently shows a maintenance page. The FBI stated it is aware of claims of unauthorized activity affecting FBIjobs.gov and is investigating. The claim was framed as retaliation for a May 2026 IC3 PSA about the group’s Canvas attacks.
Key takeaway / Actionable note: Treat the claim as high-priority until confirmed or refuted; organizations using PeopleSoft should review for related activity and ensure patches/monitoring for known PeopleSoft RCEs.
Summary: Microsoft’s Digital Crimes Unit, working with partners and law enforcement, disrupted EvilTokens, a phishing-as-a-service platform that abused Microsoft device-code authentication and featured an AI chatbot to analyze compromised inboxes for fraud opportunities. The service, launched in February 2026, was linked to more than 12,000 compromised inboxes across over 10,000 organizations. Microsoft seized 50 websites and disabled more than 150 domains; UK police arrested two suspects.
Key takeaway / Actionable note: Block or tightly restrict device-code authentication where not required, revoke refresh tokens for suspected compromises, and monitor for related BEC activity.
Summary: A Chinese-speaking threat actor (linked by GreyNoise to Red Heron activity) exploited the wp2shell chain (CVE-2026-63030 and CVE-2026-60137) in WordPress to breach at least 49 organizations in 29 countries and a Zyxel GS1900 Smart Managed Switch flaw (CVE-2026-7273) to compromise 996 devices in 48 countries. From one Western government backend the actor stole more than 18,500 records containing accounts, plaintext passwords, and PII tied to government and law-enforcement entities. CISA added the Zyxel CVE to KEV.
Key takeaway / Actionable note: Patch WordPress core/plugins and Zyxel GS1900 firmware immediately; hunt for web shells, unexpected admin accounts, and exfiltrated switch configs/credentials.
Summary: cPanel disclosed CVE-2026-87899 (and related issues) in its CalDAV and CardDAV service that allows an authenticated hosting account holder to escalate to root-level code execution and full server control. A second flaw in the WP Toolkit plugin enables changing other accounts’ databases; a third allows local reading of other accounts’ calendar/contact data. Fixed versions include 11.134.0.57+, 11.136.0.41+, 11.138.0.8+, and corresponding WP Squared builds.
Key takeaway / Actionable note: Update all cPanel/WHM instances to the listed patched versions without delay, especially on shared hosting platforms.
Summary: Chinese threat actor UTA0565 exploited the Chrome-Windows zero-day chain (CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880) via fake websites impersonating media and NGO entities in early September while the flaws were still zero-days for Chrome users. The chain broke out of the browser sandbox to deliver CLEANGULP malware, a previously undocumented C-based family supporting shell, process listing, upload, and download commands. Volexity documented the activity.
Key takeaway / Actionable note: Ensure Chrome and Windows are fully patched for the September updates; monitor for CLEANGULP indicators and unusual browser-process activity.
Summary: An Armenian man was sentenced to 24 months in prison and three years of supervised release for participating in Ryuk ransomware attacks that encrypted systems at U.S. companies. The case highlights continued law-enforcement pressure on ransomware affiliates.
Key takeaway / Actionable note: Maintain strong offline backups, network segmentation, and rapid detection capabilities against ransomware groups that still leverage older toolsets.
Also Noted:
Bottom line: Two critical, actively exploited zero-days in widely deployed network and security-management appliances (F5 BIG-IP APM and Check Point Management Server) dominate the last 24 hours and demand immediate inventory and patching.
Parallel claims of a high-profile federal compromise, a major AI-assisted phishing platform takedown, and continued Chinese exploitation of edge and CMS flaws underscore that both nation-state and cybercrime operators are moving quickly against unpatched internet-facing infrastructure. Prioritize the KEV items and identity-related controls today.

