🛡️ InfoSec Blue Team Briefing

Wednesday, September 23, 2026

🎧 Audio Briefing

Download MP3

Security news from the BlueTeamSec community for Wednesday the 23rd of September 2026. It's a busy one, with thirteen stories to get through — and we're starting with four urgent CISA alerts.

CISA has added a critical F5 BIG-IP vulnerability to the Known Exploited list. CVE-2026-94127 is a heap overflow in the Access Policy Manager that allows unauthenticated remote code execution, but only on systems configured with both APM policies and OAuth profiles. Active exploitation in the wild, so if you're running BIG-IP with that setup, F5's emergency hotfix and compromise assessment are both priorities.

And another one in the wild — this time affecting Check Point Quantum gateways. CVE-2026-85102 is a certificate validation flaw in VPN negotiation allowing remote code execution without authentication. Check Point's Jumbo Hotfix patches are out, and they've provided hunting queries in their advisory. Worth flagging if you've got internet-exposed VPN gateways.

Third Check Point issue on the KEV list: CVE-2026-93616, a directory traversal and file upload vulnerability in the Quantum Security Management Server. Unauthenticated attackers can upload and execute malicious scripts, which gives them full control over the management server and everything it manages. Also actively exploited — the advice is to apply the hotfix, isolate management from the internet, and audit your logs.

And rounding out the KEV alerts, there's CVE-2026-93952 in Arista VeloCloud Orchestrator — a maximum severity authentication bypass that grants full compromise of internet-facing orchestrator hosts. Active exploitation again. Patches are available for some release trains; for the others, restrict access to trusted IPs while you wait.

Volexity have written up a Chinese threat actor, UTA0565, who exploited zero-days in Chrome and Windows via typosquatted websites to deploy malware called CLEANGULP against Asian government entities earlier this month. The piece notes that the exploit kit appears to be shared across multiple Chinese actors, which is useful context if you're tracking that ecosystem.

InfoGuard have published part one of a deep dive into the 'Iranopasmigitim' campaign — targeted credential theft against Iranian dissidents outside Iran in mid-June. The attackers used a Rust-based infostealer called ParsaStealer, delivered via malicious shortcuts and DLL sideloading, to harvest browser credentials, cloud tokens, and SSH keys. Data went out to Telegram. One for those tracking espionage operations targeting activists.

Qrator Labs reported a BGP hijack from an Iranian network, AS197207, which announced 190 unauthorised prefixes on the 20th of September. The malicious announcements propagated globally and created over ten thousand routing conflicts across more than fifteen hundred autonomous systems. It's a textbook case of how BGP can be abused for traffic interception or service disruption.

Sekoia's Threat Detection and Research team have documented Exvicy, a ClickFix malware-as-a-service framework advertised on Russian forums as a competitor to ErrTraffic. Turns out it's largely a copycat using stolen client-side code. The framework uses compromised WordPress sites to serve fake Cloudflare security challenges that trick users into running malicious PowerShell. Adds useful context to the ClickFix landscape.

Datadog have published a threat hunting guide for GitHub environments, focusing on reconnaissance and compromise detection. It covers audit log gaps, API rate limiting tricks, and attribution challenges, then provides strategies for baselining service account behaviour and monitoring git protocol usage alongside API activity. Particularly relevant if you're trying to tighten up GitHub security posture.

The LOLRMM project has added documentation for Lavawall, a legitimate remote management platform from ThreeShield. The entry provides detection criteria to help defenders spot this tool when it's abused for living-off-the-land attacks. One for the detection engineering pile.

The NCSC has published a framework for evaluating the risks of agentic AI in defensive cyber operations. It introduces five dimensions — Potency, Scope, Criticality, Rollout confidence, and Recoverability — to help teams avoid self-inflicted damage from compromised or erroneous autonomous agents. Worth a look if you're considering AI-driven automation in your SOC.

Nationwide Building Society have released Cryptoptic, an open-source tool that uses CodeQL and GitHub Actions to scan repositories or entire organisations and inventory every cryptographic function in use. It's designed to help with post-quantum migration planning by showing you where cryptographic operations live in your codebase.

And finally, the Apple Root Program has announced a strategic transition to post-quantum cryptography for TLS and S/MIME through a new Multi-Tier Certificate policy. The policy requires triple cosignatures using ML-DSA and ECDSA from multiple operators with HSM-backed keys, seven-day certificate validity, and enhanced operational transparency. Flag this if you're tracking the post-quantum transition across major certificate programmes.

That's all for today. As always, the articles are the work of their original authors — the analysis here was automated.

📰 Articles Covered