CISA flags four actively exploited flaws — in Check Point, Arista, and F5 gear — as WordPress and Chrome ship urgent fixes
Tuesday brought confirmed active exploitation of internet-facing management and network appliances alongside critical patches for WordPress and Chrome and a fresh crop of breach claims.
CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation. Per CISA, the four affect Check Point (an improper certificate validation flaw and a path traversal flaw across multiple products), Arista VeloCloud Orchestrator (improper input validation), and F5 BIG-IP APM. If you run any of these, prioritise them.
The Check Point entries connect to a separate disclosure. The Hacker News reported that Check Point warned attackers exploited a previously unknown flaw in its Security Management Server in a handful of targeted attacks on July 23. The Hacker News says the flaw lets an attacker who can access the server's web service run scripts on it without logging in, and that Check Point released a fix on September 2.
WordPress patched a critical core flaw. The Hacker News reported that the flaw lets an attacker with no account make a site load a PHP file from outside its theme folders, and on some servers run their own code; the fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch.
Google's Chrome advisory lists six flaws — CVE-2026-93374, CVE-2026-93373 and CVE-2026-93372, each carrying a CVSS 3.1 score of 9.6, and CVE-2026-93382, CVE-2026-93381 and CVE-2026-93377 at 8.8 — affecting Chrome up to the fix in 153.0.8010.52. Google's advisory directs administrators to the fixed release.
On breaches: BleepingComputer reported that the ShinyHunters extortion gang claims it breached FBI systems using an Oracle PeopleSoft zero-day and stole data on employees and applicants. BleepingComputer also reported a Chinese-speaking threat actor exploiting flaws in ZyXEL GS1900 switches and WordPress to steal government data from 996 devices and more than 18,500 records. SecurityWeek reported BigCommerce data was stolen after attackers used a compromised application key held by Ribon.
On AI-driven threats, BleepingComputer, The Register and Help Net Security reported ClosedQuorum, Windows malware that uses Google Gemini, DeepSeek, Qwen and Mistral models to choose post-compromise actions; Help Net Security notes Cisco Talos released an open-source framework, CAIRN, to classify it from file metadata alone.
Two supply-chain and identity items: The Hacker News detailed a malicious npm package, "tw-pkgprobe-7731," posing as a Twilio security tool while harvesting data, and BleepingComputer reported research showing attackers with privileged access can register a rogue external MFA provider that steals passwords during legitimate logins.
Sources
- BleepingComputer — Rogue external MFA providers can steal passwords during logins
- The Register — Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
- The Record — Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
- The Hacker News — Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
- SecurityWeek — BigCommerce Data Stolen via Ribon Apps Hack
- Help Net Security — Researchers uncover malware that uses AI to choose its next move
- CISA — CISA Adds Four Known Exploited Vulnerabilities to Catalog
- Schneier on Security — GPT-6 Astra Breaks an Old Enigma Message
- BleepingComputer — Sweden fines Miljödata $183,000 over breach affecting 2.2 million
- BleepingComputer — Chinese hackers exploit multiple technologies to steal govt data
- BleepingComputer — ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
- BleepingComputer — New ClosedQuorum Windows malware uses AI for attack decisions
- The Hacker News — WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
- The Hacker News — Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials