STORIES LAST WEEK
F5 BIG-IP zero-day under active attack
Attackers are exploiting CVE-2026-94127 against BIG-IP APM systems configured as OAuth authorization servers. The heap overflow reaches the data plane without authentication, so restricting management access does not mitigate exposed deployments. SecurityWeek, September 23, 2026
Check Point zero-day targets firewall management servers
Check Point patched CVE-2026-93616 after detecting targeted exploitation dating to July. The pre-authentication path traversal and file-upload flaw can execute arbitrary scripts on systems controlling enterprise firewall policies, logs, and managed gateways. Beazley Security, September 22, 2026
VeloCloud zero-day puts SD-WAN control plane at risk
Arista confirmed active exploitation of CVE-2026-93952, a maximum-severity flaw affecting certain certificate-authenticated VeloCloud Orchestrator deployments. Successful attacks can reach privileged orchestrator functions and potentially expose managed SD-WAN edge devices. SecurityWeek, September 23, 2026
AI agents steal 600,000 payment cards
A financially motivated operator used open-source AI agents for scanning, exploitation, and attack orchestration. Researchers documented 105 attack projects in six days, at least 27 compromised companies, and card skimmers across at least 119 websites. Canadian Cyber Security Journal, September 23, 2026
Microsoft shuts down AI-powered phishing operation
EvilTokens abused device-code authentication to capture Microsoft 365 sessions, then used AI to analyze inboxes, map trusted relationships, identify payment authorities, and prepare fraud. Microsoft seized 50 websites and disabled more than 150 supporting domains. Microsoft, September 22, 2026
Carbonato botnet puts AI agents on Docker hosts
Carbonato compromises unauthenticated Docker APIs, launches privileged containers, and installs the Hermes Agent framework for operator-directed post-compromise activity. The malware also scans neighboring networks every five minutes, turning exposed container infrastructure into a propagation point. ThreatDown, September 22, 2026
Chinese hackers share Chrome and Windows zero-day chain
Volexity identified UTA0565 using two Chrome flaws and a Windows privilege-escalation zero-day through spoofed websites. Reuse of the same exploit framework across multiple groups suggests rapid sharing and customization of high-value offensive tooling. Volexity, September 21, 2026
25-year-old TACACS+ flaw exposes network authentication
Researchers found a 25-year-old pre-authentication format-string flaw in the tac_plus daemon and a shared-secret oracle that makes exploitation practical. Compromise can expose administrative authentication traversing centralized AAA infrastructure for routers, switches, and firewalls. elttam, September 23, 2026
Ransomware gangs exploit critical TeamCity flaw
CISA now identifies ransomware use of CVE-2026-63077, which lets unauthenticated attackers execute operating system commands on TeamCity servers. Compromised CI/CD systems can expose credentials, alter build artifacts, and provide access to downstream software pipelines. BleepingComputer, September 24, 2026
Roundcube flaw comes under active attack
Attackers are exploiting CVE-2026-48842, a pre-authentication SQL injection in Roundcube’s virtuser_query plugin. More than 523,000 Roundcube instances remain internet-accessible, making patching or disabling the affected plugin an immediate operational priority. BleepingComputer, September 24, 2026
WordPress flaw exploited within hours of disclosure
Attackers began exploiting CVE-2026-87902 shortly after WordPress 7.1.2 was released. The path traversal flaw can let unauthenticated attackers include local PHP files and achieve code execution, sharply reducing the safe window for routine patch cycles. SecurityWeek, September 24, 2026
CrowdSec loses code from 300 repositories
CrowdSec traced the theft of about 170 private and 130 public repositories to the earlier TanStack supply-chain compromise. The incident shows how stolen developer credentials can preserve downstream access long after an upstream package attack ends. Security.io, September 21, 2026
Attackers target CI/CD pipelines and developer systems
Mandiant documented attacks against security scanners, programming tools, developer workstations, IDEs, and CI/CD systems to steal signing keys, API tokens, and sessions. The guidance emphasizes isolating build systems and treating developer identities as privileged infrastructure. Google Cloud, September 24, 2026
SolarWinds patches two unauthenticated RCE flaws
SolarWinds fixed CVE-2026-28324 and CVE-2026-28325 in Observability Self-Hosted 2026.2.3. Both permit unauthenticated remote code execution under affected configurations, placing monitoring infrastructure with broad environmental visibility and access at risk. The Clarity, September 24, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
