Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 23, 2026·5m

Cyber Security News for September 23 2026 - Daily DefSec Brief

Show notes

1. F5 BIG-IP APM zero-day exploited for code execution https://my.f5.com/manage/s/article/K000162605

2. Check Point management servers exploited since July https://support.checkpoint.com/results/sk/sk1000171

3. Device-code phishing kit registered its own devices ra — https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/

4. Arista VeloCloud orchestrator zero-day exploited https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183

5. Check Point VPN certificate flaw now exploited https://support.checkpoint.com/results/sk/sk1000117

6. Public tool freezes Defender's updates — Do: Alert on stale Defender signatures — https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html

7. Rogue Entra MFA provider keeps stealing passwords — Do: Alert on new external MFA methods — https://www.varonis.com/blog/trustsink

8. Public exploit for Veeam Agent's SYSTEM escalation — CVE-2026-32996 — Fixed: 13.0.2.29 — Do: Update Veeam Agent on Windows endpoints — https://www.veeam.com/kb4852

9. WordPress core flaw loads PHP with no login — CVE-2026-87902 — Fixed: 7.1.2 (backports down to 4.7.37) — Do: Check WordPress auto-updates really installed — https://wordpress.org/news/2026/09/wordpress-7-1-2-release/

10. ManageEngine logon-screen client gives SYSTEM — CVE-2026-74849 — Fixed: 7001 — Do: Upgrade ADSelfService Plus to the fixed build — https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-74849.html

11. SharePoint "spoofing" flaw is code execution — CVE-2026-65660 — Fixed: 16.0.10417.20198 (2019), 16.0.19725.20522 (SE), 16.0.5565.1001 (2016) — Do: Confirm August's SharePoint update is installed — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660

12. Next.js preview images can run server code — CVE-2026-94545 — Fixed: 16.3.6 — Do: Upgrade Next.js apps that generate preview images — https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j

13. Bifrost AI gateway runs commands without a login — CVE-2026-90898 — Fixed: 2.1.0 — Do: Upgrade Bifrost and rotate its provider keys — https://research.jfrog.com/vulnerabilities/bifrost-is-vulnerable-to-unauthenticated-remote-code-execution-via-mcp-stdio-client-registration-cve-2026-90898/

14. Malware has four AI models vote on its moves — Do: Alert on unexpected AI API calls from endpoints — https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/