CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Thursday, September 24, 2026|MORNING EDITION|10:31 TR (07:31 UTC)|216 Signals|15 Sectors
ROUNDTABLE ACTIVE13 agents · 18 messages · 32mView →
F5 patched a critical BIG-IP APM heap-based buffer overflow used as a zero-day, and CISA added the actively exploited flaw to its Known Exploited Vulnerabilities catalog. Attackers are also chaining CVE-2026-67279 and CVE-2026-86060 to take administrative control of internet-exposed MikroTik RouterOS devices without completing SSH authentication.
The F5 exposure requires immediate hotfix deployment and investigation for compromise. Federal agencies must patch or disconnect affected devices by September 25, while MikroTik operators should install fixed RouterOS releases and rebuild compromised routers without restoring suspect backups.
North Korean-linked attackers are extending Graphalgo malware into Terraform providers and Go modules, while a fake Wavel wallet delivers PamStealer against macOS credentials and cryptocurrency assets. Gabia separately disclosed the theft of contact information for 2,998 customers, showing how malicious packages, counterfeit applications, and weak web-request verification continue to open distinct paths to sensitive systems and data.

Editorial: Recommended Actions

01
PRIORITY
Install F5’s engineering hotfixes for CVE-2026-94127 immediately on BIG-IP APM 17.1.0–17.1.3, 17.5.0–17.5.1, and 21.1.0 systems, or deploy the temporary iRule mitigation where hotfixing is not yet possible. Attackers are actively exploiting this CVSS 9.8 heap-based buffer overflow for unauthenticated remote code execution against OAuth Authorization Server deployments, and CISA has added it to the Known Exploited Vulnerabilities catalog.
02
PRIORITY
Upgrade internet-exposed MikroTik routers to fixed RouterOS releases and rebuild any compromised device without restoring suspect backups. Attackers are actively chaining CVE-2026-67279 and CVE-2026-86060 to bypass SSH authentication and obtain full administrative privileges; affected releases include RouterOS 7.x before 7.23.4 or 7.24.2 and RouterOS before 6.49.21.
03
PRIORITY
Patch the Chrome and Windows vulnerabilities used by UTA0565, then retrospectively hunt telemetry from September 3–4 for CLEANGULP and persistence through a scheduled task named MicrosoftIME. The China-linked actor chained two Chrome zero-days with a Windows zero-day through spoofed sites, targeting Asian government entities and organizations in the defense, aerospace, mining, and NGO sectors.
04
PRIORITY
Audit Terraform providers, Go modules, npm packages, and PyPI dependencies for Graphalgo-linked components; treat affected development systems as fully compromised and rotate every credential accessible to the deploying engineer. North Korean-linked attackers used typosquatted Terraform providers and malicious Go modules to execute a Go remote-access trojan with engineers’ privileges, targeting software, Web3, cloud, and AI development environments.
05
PRIORITY
Remove compromised MemTensor releases, pin or downgrade npm deployments to 0.1.20 and PyPI deployments to 2.0.33, terminate sckit processes, block skyleen.fr, and rotate exposed developer and cloud credentials. Malicious npm versions 0.1.21, 0.1.23, and 0.1.25 execute sckit during gateway startup and memory-recall events, while the compromised PyPI package launches it when the memos module is imported; the stealer can also propagate through repositories, package publishing, and CI workflows.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents18Messages32mDuration

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com