CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (24 September 2026)

Published: Loading…

At a Glance

  • ShinyHunters claimed it breached the FBI's jobs site, stealing data on agents and job applicants, and threatened to leak it.
  • F5 patched CVE-2026-94127, a critical actively exploited BIG-IP APM zero-day enabling unauthenticated remote code execution via OAuth profiles.
  • Check Point confirmed active exploitation of CVE-2026-85102 and disclosed a second zero-day, CVE-2026-93616, in Security Management.
  • WordPress released 7.1.2 to fix CVE-2026-87902, a critical path traversal flaw now under active exploitation for code execution.
  • Malicious MemTensor npm and PyPI packages delivered the sckit Go implant, stealing credentials and CI publish tokens.
  • Microsoft disrupted the AI-powered EvilTokens phishing service, which had compromised over 12,000 inboxes across 10,000 organizations.

Editorial Analysis

Two more management-layer products join this week's run of exploited zero-days. F5's CVE-2026-94127 requires a specific configuration combining an APM access policy with an OAuth profile, but F5 confirmed active exploitation and CISA added it to the Known Exploited Vulnerabilities catalogue within a day of disclosure. Arista's VeloCloud Orchestrator flaw was also under attack before most administrators could patch. Both vulnerabilities affect centralised management platforms, where compromising a single system can provide access to the networks and policies it controls.

The sckit campaign against MemTensor's npm and PyPI packages targets several points in the software development process. Its npm payload activates during an AI memory plugin's normal recall function and captures the host environment and prompt text, while the PyPI version hides in a Python logging hook triggered during import. Malicious versions reappeared within minutes of clean releases, with configuration targeting npm publishing tokens as well as cloud and source-control credentials. A conditional GitHub Actions helper extends the campaign into CI, giving the attackers multiple routes through the same development environment.

AI branding and AI tooling also appeared in more conventional criminal operations. A fake Claude Max giveaway uses a browser-in-the-browser overlay to harvest Google credentials, built around a maintained third-party phishing widget. CARBONATO, meanwhile, incorporates a legitimate open-source AI agent framework into a Docker-targeting botnet, giving operators a Telegram-controlled post-compromise tool. The incidents show AI being incorporated into attacks at different stages, from the lure presented to victims to the tooling used after compromise.

Highlights of the Day

F5 Patches Actively Exploited BIG-IP APM Zero-Day

F5 disclosed CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP APM configured as an OAuth Authorisation Server, allowing unauthenticated remote code execution. F5 confirmed the flaw has been exploited in the wild and affects BIG-IP APM 21.1.0 and 17.1.0 through 17.5.1, including systems in Appliance mode. Engineering hotfixes are available for affected branches, while other BIG-IP modules, BIG-IQ, F5OS and NGINX products are not vulnerable.

Source: F5

ShinyHunters Claims FBI Jobs Site Breach, Threatens Data Leak

ShinyHunters defaced the FBIjobs.gov site, replacing images with its mascot, and claimed to have stolen data on current and former employees and applicants. The group threatened to leak information on FBI agents and applicants unless the FBI retracted a public service announcement disputing its earlier claims. The FBI confirmed it is investigating the incident, while the jobs portal remains unavailable.

Source: The Record

Fake Claude Max Giveaway Steals Google Account Logins

Malwarebytes identified a phishing campaign offering fake free Claude Max subscriptions to harvest Google account credentials. The site mimics Anthropic branding and uses a fabricated countdown, then directs visitors to a fake "browser-in-the-browser" Google sign-in window rather than a real login page. Researchers noted the technique reuses a maintained third-party phishing widget, with code comments written in Russian.

Malicious npm and PyPI Packages Hijack AI Memory Plugin

StepSecurity identified malicious versions of the @memtensor/memos-cloud-openclaw-plugin npm package and the MemoryOS 2.0.34 PyPI package, both bundling hidden credential-harvesting executables. The npm launcher activates during plugin startup and memory recall, capturing the host environment and user prompt text, while malicious content reappeared within minutes of clean releases. Both packages target home-directory files and package-publishing tokens, communicating with matching external command-and-control infrastructure.

Ryuk Ransomware Access Broker Sentenced to 24 Months

Karen Serobovich Vardanyan, an Armenian man extradited from Ukraine, was sentenced to 24 months in prison for hacking U.S. companies and deploying Ryuk ransomware between March 2019 and June 2020. He specialised in gaining initial network access, with victims including a Michigan firm that paid 200 BTC, a Texas school, and an Oregon technology company. Prosecutors said Vardanyan and co-conspirators received approximately 1,610 bitcoins, valued at over $15 million, in ransom payments.

Check Point Firewalls and Management Servers Under Active Attack

Check Point confirmed active exploitation of CVE-2026-85102, a critical pre-authentication RCE in Security Gateway VPN certificate handling, targeting Spark Firewall customers since September 12. It also disclosed CVE-2026-93616, a zero-day path traversal flaw in Security Management allowing arbitrary script execution, exploited in limited attacks observed on 23 July 2026. Fixes are available for both vulnerabilities, with CVE-2026-85102 patched since 9 September.

Critical WordPress Flaw Enables Unauthenticated Remote Code Execution

WordPress patched CVE-2026-87902, a critical path traversal vulnerability in page-template resolution allowing unauthenticated inclusion of arbitrary local PHP files. Exploitation requires a theme with a directory starting with "page-", affecting themes like Twenty Twelve, Neve and Hestia, plus a readable target file such as pearcmd.php. WordPress 7.1.2 fixes the issue, with patches backported to all versions back to 4.7.

Daily Coverage

Developments
Shinyhunters Fbi BreachF5 Big-Ip Apm Zero-DayCheck Point Zero-DaysWordpress Rce Exploited
Vulnerabilities
CVE-2026-94127Big-Ip 21.1.0 (Critical)CVE-2026-87902Wordpress (High)CVE-2026-85102Quantum Security Gateway R82.10 With Jumbo Hotfix Take 43 Or Below (Critical)CVE-2026-93616Quantum Security Management R82.20 With No Jumbo Hotfix (Critical)CVE-2026-85046Chrome 152.0.7977.82 (High)CVE-2026-87491Chrome 153.0.8010.36CVE-2026-85880Windows 10 Version 1607 10.0.14393.0 (High)CVE-2026-80521Linux 4090Fa373F0E763C43610853D2774B5979915959 (High)CVE-2025-39682Linux 84C61Fe1A75B4255Df1E1E7C054C9E6D048Da417 (Critical)CVE-2026-53266Linux 63137Bc5882A1882C553D389Fdeeeace86Ee1741 (High)
Threat Groups
LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.