Cybersecurity Threat Digest — September 23, 2026
This cybersecurity threat digest September 23 2026 covers active exploitation of F5 BIG-IP APM and Check Point Management Server flaws, along with ransomware, AI-enabled malware, MFA abuse, and data theft campaigns.
TL;DR - F5 BIG-IP APM and Check Point Management Server flaws are in CISA KEV with September 25 deadlines. - Teams should patch or isolate exposed identity, firewall, network, and remote-administration systems. - Investigate suspected data theft, rogue MFA providers, and malware using external AI services.
Analyst’s Take: The first move is to close the F5 and Check Point exposure before the September 25 CISA deadlines, then validate the remediation with configuration review and telemetry. The remaining activity reinforces the need to investigate identity-control changes, appliance exposure, and post-compromise behavior rather than relying on endpoint scans or known malware hashes alone.
Top Stories
F5 patches exploited BIG-IP APM zero-day
F5 released fixes for CVE-2026-94127, a critical BIG-IP Access Policy Manager vulnerability exploited in remote code execution attacks. The issue affects deployments where APM and an OAuth profile are configured on a virtual server, with BIG-IP acting as an OAuth Authorization Server.
Under the affected configuration, unauthenticated malicious traffic can achieve remote code execution. F5’s advisory is available through its security advisory, and the issue is listed in CISA’s Known Exploited Vulnerabilities catalog.
Defender priority: identify all internet-facing BIG-IP systems, confirm whether the affected OAuth configuration is enabled, apply F5’s update or mitigation, and investigate for post-exploitation activity.
Chinese-speaking actor targeted Zyxel switches and WordPress
A Chinese-speaking threat actor reportedly exploited vulnerabilities in Zyxel GS1900 Smart Managed Switches and WordPress to steal sensitive information from 996 devices and more than 18,500 backend records. The campaign shows why network appliances and content-management systems need to be investigated together when they share an intrusion path.
The reported activity is covered by BleepingComputer.
Correlate WordPress access logs, switch administration events, database queries, and outbound transfers. Rotate credentials and tokens if vulnerable systems were exposed or accessed during the suspected intrusion window.
ShinyHunters claims FBI breach involving PeopleSoft
The ShinyHunters extortion group claimed it breached FBI systems using an alleged Oracle PeopleSoft zero-day and stole employee and applicant information. The claim requires independent validation; without evidence from the affected organization or reliable incident reporting, it should not be treated as a confirmed breach.
The allegation is reported by BleepingComputer.
PeopleSoft administrators should review authentication events, administrative changes, application-server logs, unusual data exports, and access to employee or applicant records. Preserve evidence before making broad configuration changes.
ClosedQuorum malware uses multiple AI models
Researchers reported that new ClosedQuorum Windows malware can use external generative-AI models to make post-compromise decisions. The reported models include Google Gemini, DeepSeek, Qwen, and Mistral.
That behavior could allow parts of an intrusion to adapt to local conditions rather than follow a fixed command sequence. The details are covered by BleepingComputer.
Security teams should not rely only on known hashes. Hunt for suspicious processes that combine scripting, reconnaissance, credential access, and outbound connections to model APIs or other unusual cloud services.
Rogue external MFA providers can intercept passwords
Researchers demonstrated that an attacker with sufficient administrative privileges can register a rogue external MFA provider. During legitimate login attempts, that provider may be able to intercept passwords or influence the authentication flow.
This is a control-plane risk. An attacker may not need to compromise every user account if they can modify identity-provider configuration. The research is summarized by BleepingComputer.
Audit who can add or modify authentication providers, require approval for provider changes, and alert on new registrations, policy changes, and unusual administrative activity. Strong phishing-resistant MFA remains valuable, but it does not eliminate the need to protect identity administration.
Ryuk ransomware member sentenced
An Armenian man received a 24-month prison sentence and three years of supervised release for hacking U.S. companies and encrypting systems in Ryuk ransomware attacks. The case is reported by BleepingComputer.
Ransomware investigations can remain active long after an incident. Organizations should retain endpoint, identity, VPN, email, and backup logs according to legal and operational requirements.
Security vendors expand AI offerings
Anthropic announced Claude Opus 5.5, describing stricter safeguards for cybersecurity use cases. The announcement was reported by The Verge.
Palo Alto Networks also introduced an AI-powered cybersecurity service using Claude and GPT models, according to Reuters.
Security teams evaluating these tools should define data-handling boundaries, logging requirements, human approval points, and controls for model-generated actions.
Critical Vulnerabilities
CVE-2026-94127 — F5 BIG-IP APM
- Severity: CVSS 9.8
- Status: Listed in CISA KEV
- CISA date added: September 22, 2026
- CISA remediation deadline: September 25, 2026
- Impact: Unauthenticated remote code execution under specific APM and OAuth Authorization Server configurations
- References: F5 advisory, CISA KEV entry
Prioritize internet-facing BIG-IP systems and verify remediation at the configuration level, not only by checking software version.
CVE-2026-93616 — Check Point Management Server
- Severity: CVSS 9.8
- Status: Listed in CISA KEV
- CISA date added: September 22, 2026
- CISA remediation deadline: September 25, 2026
- Impact: Unauthenticated directory traversal and file upload that can enable arbitrary script execution
- References: Check Point advisory, vendor guidance, CISA KEV entry
Inspect management servers for unexpected files, script execution, new administrative activity, and unexplained outbound connections.
CVE-2026-80155 — Lantronix SLC and EMG devices
- Severity: CVSS 10.0
- Status: Not listed in CISA KEV in the supplied advisory data
- Impact: Authentication bypass in the web management upload endpoint, exposure of sensitive configuration files, arbitrary file writes, and possible remote code execution
- Affected product families: Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02
- References: technical analysis, Lantronix EMG7500 update, Lantronix EMG8500 update, Lantronix SLC8000 update, VulnCheck advisory
Patch these devices where updates are available. Otherwise, isolate management interfaces, restrict access to trusted administration networks, and monitor for unexpected configuration-file access.
CVE-2026-74849 — ManageEngine ADSelfService Plus
- Severity: CVSS 9.8
- Affected versions: Versions before build 7001
- Impact: Remote code execution through the GINA client
- Reference: ManageEngine advisory
Upgrade to build 7001 or later according to the vendor’s guidance. Review endpoint and server telemetry for suspicious activity involving the GINA client and associated ADSelfService Plus components.
CVE-2026-95675 — D-Link DAP-1360
- Severity: CVSS 9.8
- Affected versions: Firmware 6.14 and earlier
- Impact: Unauthenticated command execution as root through the web management interface
- References: D-Link advisory, technical analysis, VulnCheck advisory
Replace or update affected devices where supported. Disable internet-facing web administration and restrict management access to a dedicated administration network.
What Defenders Should Do Today
1. Close the two CISA KEV priorities first
Immediately inventory:
- F5 BIG-IP APM systems
- Check Point Management Servers
- Internet-facing management interfaces
- Systems using identity, access, firewall, or remote-administration functions
Apply vendor fixes or mitigations before the September 25 CISA deadlines. Confirm the result with authenticated vulnerability scanning, configuration review, and a service-owner sign-off.
2. Review F5 and Check Point telemetry
For F5 BIG-IP, examine:
- Requests to exposed virtual servers
- OAuth and APM policy changes
- Unexpected administrative sessions
- New or unusual process execution
- Outbound connections from the appliance
- Configuration exports or changes made outside approved windows
For Check Point Management Server, search for:
- Directory traversal patterns
- Unexpected uploaded files
- Script execution from unusual directories
- New administrative accounts or permissions
- Changes to security policies
- Outbound connections not associated with normal management activity
Do not assume a clean endpoint scan proves that an appliance was not exploited.
3. Isolate vulnerable network appliances
For Lantronix and D-Link devices:
- Remove management interfaces from the public internet.
- Permit administration only from trusted hosts or jump servers.
- Apply the appropriate firmware update.
- Replace devices that cannot be securely updated.
- Export and inspect configurations for unexpected accounts, endpoints, or changes.
- Rotate credentials if configuration files may have been exposed.
4. Patch WordPress and review Zyxel systems
Build a current inventory of WordPress instances, plugins, themes, administrator accounts, and exposed management paths. Review web-server logs for unusual requests, file changes, new administrative users, and unexpected database access.
For Zyxel GS1900 switches, identify exposed administration services, apply available updates or vendor mitigations, and check for configuration changes. Rotate credentials and tokens associated with affected systems when compromise cannot be ruled out.
5. Protect identity-provider administration
Audit all accounts that can:
- Register or remove external MFA providers
- Modify authentication policies
- Change conditional-access rules
- Reset credentials
- Alter federation or trust settings
- Approve new applications or integrations
Require dual approval for provider changes where possible. Alert on new provider registrations, authentication-policy changes, and administrative actions from unusual locations or devices. For teams reviewing privileged access, a managed password vault such as Try 1Password → can help centralize credentials and access controls.
6. Hunt for AI-assisted malware behavior
Use endpoint, DNS, proxy, and firewall telemetry to identify:
- Office or scripting processes making unexpected internet connections
- PowerShell, Python, or command-shell activity followed by cloud API access
- Connections to model APIs from systems that do not normally use them
- Rapid changes in process behavior after reconnaissance
- Suspicious child processes spawned by browsers or unsigned binaries
- Credential access followed by automated lateral-movement activity
External AI traffic alone is not proof of malware. Correlate it with execution, persistence, discovery, credential access, and data-transfer signals.
7. Treat breach claims as investigation leads
The PeopleSoft allegation and other extortion claims should trigger a structured validation process. Use established incident response guidance when coordinating technical, legal, and communications teams.
- Identify potentially affected applications and data stores.
- Preserve logs and relevant forensic images.
- Review privileged access and bulk-download activity.
- Compare claimed data with authoritative records without unnecessarily exposing sensitive information.
- Coordinate with legal, privacy, and incident-response teams.
- Communicate confirmed facts separately from unverified threat-actor claims.
8. Preserve evidence before disruptive remediation
Before rebooting or rebuilding systems, collect available:
- Authentication and administrative logs
- Web-server and application logs
- Firewall, proxy, DNS, and VPN records
- Endpoint process and network telemetry
- Appliance configuration backups
- Cloud audit events
- File timestamps and integrity data
Document the time, scope, and rationale for each containment or remediation action.
Technical Deep Dive
Verify internet exposure and management paths
Use approved asset-management and scanning tools first. A basic port check can help validate whether a known management service is reachable, but it does not establish whether a device is vulnerable. For a broader assessment process, see this penetration testing overview.
# Replace the target with an approved internal or external asset.
nmap -Pn -sV -p 80,443,22,8443 TARGET
# Check HTTP response headers without sending exploit payloads.
curl -k -I --max-time 10 https://TARGET/
Do not scan systems without authorization. Management interfaces should generally be reachable only from controlled administration networks.
Search web and proxy logs for traversal and upload activity
Log formats vary by platform. Adapt the following patterns to your SIEM and confirm matches against normal application behavior.
../
%2e%2e%2f
%252e%252e%252f
POST requests to management upload endpoints
unexpected script extensions in uploaded-file paths
Example searches using common command-line tools:
grep -Eia '\.\./|%2e%2e|upload|multipart/form-data' \
/var/log/nginx/access.log /var/log/apache2/access.log
A match is an investigation lead, not proof of exploitation. Correlate the source address, response code, requested path, file creation time, and subsequent process activity.
Hunt for suspicious child processes
For Windows telemetry, prioritize process trees involving web servers, management agents, scripting interpreters, and unsigned binaries.
web service
└── powershell.exe / cmd.exe / wscript.exe / mshta.exe
└── rundll32.exe / regsvr32.exe / unusual unsigned binary
Useful fields include:
- Parent and child process names
- Command line
- User and integrity level
- File hash and signature status
- Network destinations
- First-seen and execution times
- Persistence changes
Validate external MFA-provider changes
Export identity-provider audit logs for a period covering the last approved configuration change. Search for provider registration, deletion, policy modification, and privileged role changes.
event.action IN (
"provider.add",
"provider.update",
"provider.delete",
"authentication-policy.update",
"privileged-role.assign"
)
Require the identity team to reconcile every event with a change ticket or approved emergency action. Investigate unexplained provider changes as potential credential-compromise indicators.
Priority Checklist
- [ ] Patch or mitigate F5 BIG-IP APM deployments affected by CVE-2026-94127.
- [ ] Patch or mitigate Check Point Management Servers affected by CVE-2026-93616.
- [ ] Meet the September 25 CISA KEV remediation deadlines.
- [ ] Isolate and update affected Lantronix devices.
- [ ] Upgrade ManageEngine ADSelfService Plus to build 7001 or later.
- [ ] Update or replace vulnerable D-Link DAP-1360 devices.
- [ ] Review WordPress and Zyxel exposure, access logs, and configuration changes.
- [ ] Audit external MFA-provider administration.
- [ ] Hunt for suspicious AI API use combined with post-compromise behavior.
- [ ] Preserve evidence and separate confirmed incidents from unverified breach claims.
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.