CYBERSECURITYTRACKER
TRACKING
Permanent story citation

28th September – Threat Intelligence Report

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8719

As cited

Copy frozen at (site build).

vulnerabilities

28th September – Threat Intelligence Report

A threat intelligence bulletin reported multiple significant incidents during the week of September 28, 2026, including breaches at FBIjobs.gov, Astrana Health, Bitget cryptocurrency exchange, and Ludwig Maximilian University. Active exploitation of critical vulnerabilities in Check Point products (CVE-2026-85102 and CVE-2026-93616), F5 BIG-IP (CVE-2026-94127), and WordPress (CVE-2026-87902) posed remote code execution risks. Threat researchers identified campaigns leveraging artificial intelligence (AI) agents for automated retail attacks, ransomware affiliates operating across multiple ecosystems, and Azure-targeted destructive operations by compromised service principals.

Why it matters: Security teams must patch three actively exploited critical vulnerabilities in Check Point, F5, and WordPress immediately to prevent remote code execution. Defenders managing on-premises and cloud infrastructure should investigate the disclosed tactics, including AI-powered attacks, BYOVD-based security disabling, and service principal compromise in Azure environments. Organizations handling employee data, healthcare records, or cryptocurrency assets should assume similar attack patterns are in circulation.

VendorsMicrosoftCiscoCheck PointF5WordPress
Actorsqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary