# Today's Top Stories
September 24, 2026
-
1The Hacker News general Sep 23F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
F5 disclosed and patched CVE-2026-94127, a critical zero-day in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution on systems where APM is configured as an OAuth authorization server. Active exploitation was confirmed prior to the September 22 disclosure, with engineering hotfixes now available. Security teams running BIG-IP APM in OAuth server mode should treat this as an emergency patch given the pre-auth RCE impact.
-
2The Hacker News general Sep 23ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters claimed on September 23 to have breached the FBI, asserting they hold sensitive data on 'almost ALL FBI Agents' and job applicants, and temporarily defaced the FBIjobs.gov website with a Pokemon image associated with the group. The FBI confirmed it is investigating the claims, and the jobs site remained unavailable. This follows ShinyHunters' history of high-profile data theft and extortion, and the group is demanding retraction of an FBI threat report.
-
3The Hacker News general Sep 22Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Check Point confirmed active exploitation of CVE-2026-93616, a pre-authentication zero-day in its Security Management Server that allows attackers with web service access to execute arbitrary scripts without credentials. Targeted attacks were recorded as early as July 23, with a patch released September 22. Organizations running Check Point Security Management Server should apply the fix immediately given the unauthenticated code execution risk.
-
4The Hacker News general Sep 23Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Chinese threat actor UTA0565 exploited a chained zero-day combining two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC flaw (CVE-2026-85880) to deploy CLEANGULP malware via fake websites, with attacks detected on September 3–4, 2026. Volexity identified the group as sharing exploit kit infrastructure with multiple other Chinese threat actors. The use of browser-plus-OS exploit chains against targeted victims signals sophisticated, state-aligned offensive capability.
-
5The Hacker News general Sep 22Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft, acting under a U.S. District Court for the Eastern District of Virginia authorization, seized 50 websites and disabled 150+ domains belonging to EvilTokens, an AI-powered phishing-as-a-service platform linked to 12,000 Microsoft 365 inbox compromises. EvilTokens used AI throughout the attack chain — for crafting social engineering lures, selecting targets, and conducting device code phishing. The takedown involved Health-ISAC, Cloudflare, Coinbase, OpenAI, and SpyCloud.
-
ADSponsoredPenetration Testing
Comprehensive security assessments by certified professionals. Find vulnerabilities before attackers do.
Learn More → -
6The Hacker News general Sep 23MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
CERT Polska detailed 'MikroTrick,' a chained exploit combining an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in RouterOS login (CVE-2026-86060), enabling full administrative takeover of internet-exposed MikroTik routers without credentials or SSH keys. Attack logs confirm real-world exploitation is already occurring. Network defenders managing MikroTik RouterOS devices should patch immediately given the no-auth, full-control impact.
-
7The Hacker News general Sep 23Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
Security firm DepthFirst published a working exploit for CVE-2026-80521 (CVSS 7.8), a use-after-free in the Linux kernel's AF_UNIX socket subsystem that enables container escape to host root. Although the upstream kernel patch was merged August 6, Ubuntu 26.04, 24.04, and 22.04 LTS have not yet shipped the fix. Container-based deployments on Ubuntu are directly exposed until distro patches are released.
-
8BleepingComputer general Sep 23Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
A financially motivated threat actor is leveraging open-source AI agent frameworks to compromise online retail sites at scale, injecting payment card skimmers across 100+ sites and stealing more than 600,000 credit card records. The AI-assisted attack automation represents a significant escalation in Magecart-style campaign reach and speed. E-commerce security teams should audit third-party script integrity and CSP configurations urgently.
-
9BleepingComputer general Sep 23Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Check Point confirmed active exploitation of CVE-2026-85102, a critical pre-authentication RCE vulnerability in its Security Gateway product's VPN certificate-handling functionality. The flaw enables remote attackers to execute code without authentication, and Check Point has issued patches alongside a warning urging immediate action. Organizations using Check Point Security Gateway for VPN should prioritize patching given confirmed in-the-wild exploitation.
-
10BleepingComputer general Sep 23Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks released emergency patches for a zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem deployments that is actively being exploited, allowing remote attackers to access privileged internal functionality without authentication. The flaw is rated critical severity, and Arista urged immediate patching for all on-premises VCO deployments. SD-WAN administrators running Arista VeloCloud should treat this as an urgent remediation priority.