CVE-2026-18963, CVE-2026-31431, CVE-2026-34223, CVE-2026-45498, CVE-2026-50093, CVE-2026-65660, CVE-2026-67367, CVE-2026-85046, CVE-2026-85102, CVE-2026-85880, CVE-2026-87121, CVE-2026-87491, CVE-2026-89207, CVE-2026-89775, CVE-2026-90898, CVE-2026-91018, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127
Domains:
149[.]77, 126[.]159., chinadigitaltimes[.]top, americanprgoress[.]top., thecovnresation[.]com, theconversation[.]com
IP Addresses:
5.2.3.16, 6.4.2.8, 0.0.0.0
Get tomorrow's brief in your inbox
Today: A Microsoft Defender zero-day blocks platform updates by filling disk space, four actively exploited vulnerabilities hit CISA's KEV list including critical F5 BIG-IP and Check Point flaws, and Chinese state actors chain Chrome-Windows zero-days to deploy CLEANGULP malware across government targets.
BigDiskBuster Zero-Day Blocks Microsoft Defender Updates (CVE-2026-45498)
Former Microsoft researcher Abdelhamid Naceri published a proof-of-concept tool on September 19 that prevents Microsoft Defender from installing platform and signature updates by filling available disk space. When Defender attempts an update, BigDiskBuster creates hidden temporary files sized to consume all free space, causing updates to fail with error 0x80070643. The tool also blocks Windows Malicious Software Removal Tool updates. No patch exists, and Microsoft has not issued an advisory. Naceri's previous Defender exploits UnDefend, BlueHammer, and RedSun were all exploited in live intrusions before patches arrived and added to CISA's KEV catalog. CVE-2026-45498 (UnDefend) was patched in May in Antimalware Platform 4.18.26040.7, but the different mechanism in BigDiskBuster suggests that patch does not cover this new technique.
Get-MpComputerStatus PowerShell cmdlet. Alert on repeated update failures, sustained low disk space on system volume, and large hidden files in temporary directories. Restrict execution of unknown binaries through WDAC or AppLocker.F5 BIG-IP APM Zero-Day Enables Unauthenticated RCE (CVE-2026-94127)
F5 disclosed a critical heap-based buffer overflow in BIG-IP Access Policy Manager on September 22 with evidence of active exploitation. The flaw affects systems where APM acts as an OAuth authorization server, allowing unauthenticated remote code execution when malicious traffic reaches the virtual server hosting OAuth profiles. CVSS 9.8 (v3.1) and 9.3 (v4.0). Affected versions: 21.1.0, 17.5.0-17.5.1, 17.1.0-17.1.3. Engineering hotfixes available for each branch. CISA added to KEV on September 22 with September 25 remediation deadline for federal agencies. Limiting access to the management interface does not mitigate this flaw since the attack targets the virtual server itself.
Check Point Management Server Zero-Day Exploited in Targeted Attacks (CVE-2026-93616)
Check Point patched a critical directory traversal and file upload flaw in Security Management Server on September 22 after detecting exploitation on July 23 targeting "a handful of customers." The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts on the management server via the web service (port TCP/19009). CVSS 9.8. Affected: R82.20 with no Jumbo Hotfix, R82.10 Take 44 or below, R82 Take 126 or below, R81.20 Take 166 or below, R81.10 Take 190 or below (EOL). Fixed in Jumbo Hotfix Accumulator R82.10 Take 45, R82 Take 127, R81.20 Take 170, R81.10 Take 192, and R82.20 Security Hotfix. CISA added to KEV September 22 with three-day remediation deadline.
Arista VeloCloud Orchestrator Zero-Day (CVE-2026-93952)
Arista released urgent patches for a CVSS 10.0 improper input validation flaw in on-premises VeloCloud Orchestrator that allows unauthenticated remote access to privileged internal functionality. Affects orchestrators configured for certificate-based Edge authentication. Attacker needs network access to VCO web interface and public portion of an Edge authentication certificate. Fixed releases available for 5.2 and 6.4 trains as of September 22; fixes for 6.1 and 7.0 trains pending. CISA added to KEV September 22 with three-day deadline.
Armenian National Sentenced for RYUK Ransomware Extortion
An Armenian citizen extradited from Ukraine was sentenced to federal prison for his role in RYUK ransomware attacks and an extortion conspiracy targeting US companies including victims in Oregon.
Scattered Spider Member Pleads Guilty
Ahmed Hossam Eldin Elbadawy, 24, from Texas, pleaded guilty to wire fraud conspiracy for his role as a core member of the Scattered Spider hacker group involved in extortion attacks from 2021 to 2023.
SharePoint RCE Flaw Misclassified as Spoofing (CVE-2026-65660)
A SharePoint Server vulnerability Microsoft initially rated as spoofing with CVSS 6.5 actually enables authenticated remote code execution according to technical details published September 22 by researcher Dinh Ho Anh Khoa. The flaw affects SharePoint 2016, 2019, and Subscription Edition. NVD scores it 8.8 as RCE, while Microsoft's advisory describes it as spoofing with no integrity or availability impact. The vulnerability sits in how SharePoint validates SafeControls, allowing attackers to inject Register directives through unescaped quotes and load arbitrary .NET classes. Exploitation triggers code execution through XamlServices.Parse() deserialization, with working in-memory webshell payloads demonstrated. Can be chained with a June-patched authentication bypass for pre-authentication RCE on servers allowing anonymous page access. Patched August 11.
Microsoft Disrupts EvilTokens Device Code Phishing Platform
Microsoft and partners seized 50 websites and disabled 150+ domains used by EvilTokens, a phishing-as-a-service platform that compromised 12,000+ inboxes across 10,000+ organizations globally since launching in February 2026. The service automated device code authentication flow abuse to steal Microsoft 365 session tokens, combined with AI-powered inbox analysis to identify high-value targets and craft follow-on BEC attacks. Two operators (Felix Utomi and Waidi Segun Adams) arrested by UK Metropolitan Police September 18, released on bail. Coinbase traced approximately $1.1 million in cryptocurrency revenue to EvilTokens operators. Primary victims in US, Canada, UK, Australia, India, and France.
TeamFiltration Campaign Targets Chilean Organizations
Proofpoint detected a concentrated Microsoft 365 brute-force campaign (UNK_CondorFiltration) targeting 5,700+ accounts across 28 tenants in Latin America, primarily Chilean organizations including major retailers and financial institutions. Campaign used TeamFiltration framework with hardcoded user agent from Microsoft Teams 1.3.00.30866. Seven confirmed compromises, all unmanaged service/functional accounts with default passwords never rotated and no MFA. Post-access activity included VPN authentication attempts and access to Azure apps (OfficeHome, Azure Portal, SharePoint). Campaign ran July 21-28 and August 13-16.
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880)
Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain on September 3-4 through fake websites masquerading as media organizations and NGOs. Attacks used BlueMoon exploit kit combining two Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) and one Windows ALPC flaw (CVE-2026-85880) to escape browser sandbox and achieve RCE. Targeted Asian government entities with phishing emails about Hong Kong activist Chow Hang-tung, using spoofed domains chinadigitaltimes[.]top and americanprgoress[.]top. Delivered CLEANGULP malware (C2: thecovnresation[.]com mimicking theconversation[.]com). Core exploit kit likely shared across multiple Chinese CNE groups. All three CVEs added to CISA KEV with September 18-23 deadlines.
Bifrost AI Gateway RCE (CVE-2026-90898)
Critical vulnerability in Bifrost AI gateway allows unauthenticated attackers to execute arbitrary commands on the gateway server with a single HTTP POST when management authentication is disabled (default configuration). CVSS 9.8. Affects all versions before transports/v2.1.0. Attacker can register stdio-type MCP client through /api/mcp/client endpoint, which starts specified command immediately before MCP handshake, granting access to all provider API keys stored by gateway. Official Docker image binds management API to 0.0.0.0 (externally reachable if port published). Fixed in transports/v2.1.0.
CrowdSec GitHub Breach via TanStack Supply Chain Attack
Security firm CrowdSec suffered breach of 170 private GitHub repositories in May after attacker stole OAuth token from former employee's computer via Shai-Hulud worm (TanStack npm supply chain attack). Token retained read access to private repos despite employee departure. Attack occurred May 22 over 9 minutes (5:52-6:01 AM UTC) from Toronto IP. Source code published to pwnforum September 16. No infrastructure, databases, or source code alterations detected.
CISA Adds Four KEV Entries (September 22)
CISA added CVE-2026-85102 (Check Point VPN certificate validation), CVE-2026-93616 (Check Point Management Server path traversal), CVE-2026-93952 (Arista VCO input validation), and CVE-2026-94127 (F5 BIG-IP APM buffer overflow) to Known Exploited Vulnerabilities catalog with three-day federal remediation deadline under BOD 26-04.
Siemens Industrial Edge Management Authentication Bypass (CVE-2026-18963)
Keycloak-based authentication flaw in Industrial Edge Management allows unauthenticated remote attacker to force password reset and perform full account takeover without email verification. Affects IEM Cloud (all versions), IEM Pro V1 1.14.9-1.15.20, IEM Pro V2 2.2.0-2.2.2, IEM Virtual 2.6.0-2.9.1. Fixed in IEM Pro V1.15.20, V2.2.2, IEM Virtual V2.9.1. IEM Cloud patched August 26 via firewall rules, fully fixed September 2.
Multiple Siemens ICS Vulnerabilities
CISA published advisories for vulnerabilities in Siemens SIPLUS/SIMATIC (CVE-2026-31431, Copy Fail vulnerability), Desigo CC (CVE-2026-34223, client code execution), Siveillance Control (CVE-2026-50093, arbitrary file upload), SIMOVE Fleetmanager/SIPLANT (CVE-2026-67367, path traversal), and WTV676/WTV776 (CVE-2026-89207, DoS). Patches available for most products.
lwIP TCP/IP Stack Flaws
Two vulnerabilities in lwIP TCP/IP stack: CVE-2026-91018 (double free in API 2.0.1-2.2.1) and CVE-2026-87121 (out-of-bounds write in MQTT client 2.0.1-2.2.1). Both could lead to system crash, DoS, memory corruption, or code execution. Fixes available via lwIP repository commits.
Linux Kernel ARM64 KVM Flaw (CVE-2026-89775)
Flaw in Linux kernel KVM virtualization for ARM64 allows guest VMs to read and write freed host memory on systems with nested virtualization enabled (experimental, requires Armv8.4 FEAT_NV2). Researcher claims guest-to-host escape possible. Fixed in Linux 6.18.51, 7.2.5, 7.3-rc1. Scored 7.8-9.3 depending on vendor. EPSS below 1%, not in CISA KEV. Nested virtualization is off by default on ARM64 and not offered on AWS or Google Cloud ARM instances.
The steady drumbeat of exploited zero-days continues with infrastructure vendors (F5, Check Point, Arista) all disclosing actively exploited flaws within the same 24-hour window. The BigDiskBuster Defender zero-day from serial exploit publisher Abdelhamid Naceri follows a pattern where his proof-of-concepts become weaponized before Microsoft patches arrive. EvilTokens demonstrates how AI is lowering the barrier to entry for sophisticated BEC campaigns, with 1,000+ cybercriminals using the service in its seven-month lifespan. The Chinese exploitation of Chrome-Windows zero-day chains against government targets shows state actors rapidly weaponizing newly disclosed vulnerabilities, with the core BlueMoon exploit kit likely shared across multiple APT groups.