Daily Briefing
Today's outlook
F5 BIG-IP APM under active attack via critical 0-day RCE — patch is out
Good morning. The Register reported that attackers are exploiting a critical zero-day remote code execution flaw in F5 BIG-IP APM, and that both CISA and F5 warn it is under active exploitation. The Register also reported that a patch is available. Prioritise this one: BIG-IP APM sits at the network edge as an access proxy, and a remotely exploitable RCE there is a route into everything behind it. Match your estate against F5's advisory and apply the vendor's fix.
Two more products were reported under active exploitation. BleepingComputer reported that Check Point has confirmed active exploitation of a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway product. BleepingComputer separately reported that threat actors have moved from probing WordPress sites affected by a critical flaw to exploiting it, writing files to disk that execute shell commands when accessed. Check your Check Point Security Gateway and WordPress installs against each vendor's advisory and patch.
Google shipped a Chrome stable channel update fixing six flaws. Google's advisory record lists CVE-2026-93374, CVE-2026-93373 and CVE-2026-93372, each carrying a CVSS base score of 9.6 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), and CVE-2026-93382, CVE-2026-93381 and CVE-2026-93377, each scored 8.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Google lists Chrome up to the fix in 153.0.8010.52 as affected. Update to 153.0.8010.52 and confirm your fleet has restarted to apply it (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html).
On the supply-chain and social-engineering front: The Hacker News reported, citing Aikido, Go-based malware distributed via two Go Modules and two Terraform providers — the first time threat actors have used HashiCorp's centralised registry as a distribution vector. The Hacker News also reported that the private email address GitLab gives users for filing issues by email is a credential: anyone who obtains it can email a patch that GitLab commits in the victim's name to any branch they can push to, including main, and can start CI/CD jobs that run as them. BleepingComputer reported that the "third-party.com" placeholder domain now serves a fake Cloudflare verification page that tries to trick Windows users into running PowerShell commands (a ClickFix attack), and separately that a new Android malware-as-a-service platform called RemControl is targeting users in Europe and Canada through malvertising impersonating the TVTap IPTV app. Treat that GitLab issue-by-email address as a secret, and review your Terraform provider and Go module sources against Aikido's findings.
For asset owners, CISA and the FBI published a joint fact sheet on considerations for critical-infrastructure operators working with third-party ICS integrators.
Zoom out: Three separate products — F5 BIG-IP APM, Check Point Security Gateway and WordPress — were reported under active exploitation.
Vulnerability in focus
CVE-2026-93374 — Google. CVSS 9.6
Affected: chrome.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- BleepingComputer: Placeholder domain used in dev docs now serves ClickFix attacks Read it
- Help Net Security: Americans’ views on data centers have turned more negative Read it
- The Record: UK regulator to investigate Pornhub parent company for alleged age verification failings Read it
- SecurityWeek: IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin Read it
Sources
- Placeholder domain used in dev docs now serves ClickFix attacks BleepingComputer
- Americans’ views on data centers have turned more negative Help Net Security
- UK regulator to investigate Pornhub parent company for alleged age verification failings The Record
- IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin SecurityWeek
- Someone's attacking a critical 0-day RCE in F5 BIG-IP APM The Register
- Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry The Hacker News
- Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators CISA
- Research on Models Engaging in Genie-Like Behavior Schneier on Security
- New RemControl Android banking malware targets users in Europe and Canada BleepingComputer
- Check Point warns of hackers exploiting Security Gateway VPN RCE flaw BleepingComputer
- No evidence of successful foreign meddling in 2024 election, spy agencies found The Record
- Hackers start exploiting critical WordPress flaw for code execution BleepingComputer
- Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios SecurityWeek
- A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You The Hacker News
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.