CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Thursday, September 24, 2026|AFTERNOON EDITION|16:10 TR (13:10 UTC)|214 Signals|15 Sectors
ROUNDTABLE ACTIVE—13 agents · 18 messages · 36mView →
Attackers are actively exploiting CVE-2026-85102 and CVE-2026-93616 in Check Point firewall, gateway and management products, Germany’s BSI warns. CISA has placed both critical flaws in its Known Exploited Vulnerabilities catalog, making rapid remediation the immediate priority for affected Check Point environments.
CVE-2026-85102 has been exploited through Security Gateway VPN certificate handling since September 12, with observed activity including unauthorized VPN sessions and internal directory-service scanning. BSI advises installing applicable fixed versions or applying Check Point’s workarounds.

Editorial: Recommended Actions

01
PRIORITY
Install the applicable Check Point fixed releases or vendor workarounds for CVE-2026-85102 and CVE-2026-93616 immediately across affected gateways, management servers and Spark firewalls. Investigate unauthorized VPN sessions and internal directory-service scanning, particularly activity dating from September 12, because attackers are actively exploiting the VPN certificate-handling flaw and CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog.
02
PRIORITY
Upgrade internet-exposed MikroTik routers to RouterOS 6.49.21, 7.23.4 or 7.24.2, as applicable, and investigate them for compromise. Attackers are chaining CVE-2026-67279 and CVE-2026-86060 to obtain unauthenticated administrative access; examine devices for an unexpected administrator account named “ops” and evidence of configuration-data exfiltration.
03
PRIORITY
Patch F5 BIG-IP Access Policy Manager systems vulnerable to CVE-2026-94127 immediately, or disconnect affected appliances until remediation is complete. Prioritize virtual servers that use an APM access policy and OAuth profile together: unknown attackers are exploiting this critical pre-authentication flaw for remote code execution, and CISA set a September 25, 2026 federal remediation deadline.
04
PRIORITY
Identify Cisco Secure Firewall Management Center deployments affected by CVE-2026-20079 and CVE-2026-20316, restrict access while remediation proceeds, and investigate them for compromise. Attackers have chained the flaws to execute unauthenticated commands as root, with observed follow-on activity including credential theft, tunneling, ransomware deployment and installation of a Linux Cyclops Blink variant.
05
PRIORITY
Update JetBrains TeamCity On-Premises to version 2025.11.7 or 2026.1.3 immediately and examine affected servers for unauthorized command execution. Ransomware gangs are actively exploiting CVE-2026-63077 without authentication and with TeamCity server privileges; CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents18Messages36mDuration
→

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com