September 23, 2026 by sig9
Hacker Wars - September 23, 2026
Your daily dose of infosec chaos
Three infrastructure zero-days walk into your perimeter, and all of them are already exploited in the wild. F5, Check Point, and Arista all shipped emergency fixes for gear that literally runs your security posture, Chinese operators are chaining browser and OS bugs into a full combo attack, and ShinyHunters decided the best response to an FBI threat report is extortion. Busy day. Patch accordingly.
F5 BIG-IP APM Zero-Day Delivers Unauthenticated RCE on OAuth Servers
F5 confirmed that CVE-2026-94127, a critical flaw in BIG-IP Access Policy Manager, is being exploited as a zero-day for unauthenticated remote code execution. The catch: it only bites when APM acts as an OAuth authorization server, which is exactly the kind of box that mints tokens for your entire environment.
What to do: Patch BIG-IP immediately and audit any APM instance serving OAuth before it serves attackers.
Check Point Management Server Zero-Day Exposed To Script Upload Attacks
Check Point pushed a fix for a critical zero-day in its Security Management Server that lets unauthenticated attackers upload and execute arbitrary scripts. When the console that manages all your firewalls becomes the attack surface, your defense-in-depth has quietly become defense-in-one-box.
What to do: Update management servers now and make sure they are not reachable from the internet, where they never belonged.
Arista CloudVision Orchestra Zero-Day Under Active Exploitation
Arista is urging immediate patching of a critical zero-day in CloudVision Orchestra (VCO) that hands remote attackers access to privileged internal functionality. Your network automation platform just demonstrated that “infrastructure as code” includes “vulnerability as a feature.”
What to do: Apply the VCO patch across all controllers and lock down management access in the meantime.
Chinese Hackers Chain Chrome And Windows Zero-Days To Drop CLEANGULP
A Chinese threat actor tracked as UTA0565 was caught exploiting a Chrome-Windows zero-day chain through fake websites to deploy new malware dubbed CLEANGULP. It is a drive-by special: the victim browses to the wrong page and the browser bug hands off to an OS bug, no download needed.
What to do: Confirm Chrome and Windows are fully patched everywhere, including those laptops that “just browse the web.”
ShinyHunters Claims FBI Breach And Demands A Retraction
ShinyHunters claims it hacked the FBI and wants the bureau to retract an unflattering description in a recent threat report, threatening to leak stolen data otherwise. Attempting to extort your own law enforcement profiler over hurt feelings is certainly a novel crisis communications strategy.
What to do: Treat the breach claim as unverified, but monitor leak sites for any of your data riding along.
That’s the chaos for today. Stay sharp out there.
Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown
This bulletin is provided for informational purposes. Contact us for tailored security analysis.