ARCHIVED READING · PERMANENT RECORD
WEEK OF SEPTEMBER 28, 2026
73/ 100HIGH PRESSURE
Zero-days in F5 and Check Point management planes keep exploitation at its peak, a takedown dents device-code phishing, and the dial holds.
UNCHANGED SINCE LAST WEEK2026-W40ISSUED 2026-09-28 · 14:00 UTCMETHODOLOGY V1.1
SIGNALS
ACTIVE EXPLOITATION→
STEADY
A third week at peak: an F5 BIG-IP APM zero-day hits OAuth-fronting access gateways, Check Point's management server and VPN gateway are exploited, and a WordPress flaw is worked within hours of disclosure.
RATIONALE & SOURCE TYPES
Ten KEV additions, led by F5 BIG-IP APM (zero-day, unauthenticated RCE against OAuth-serving access infrastructure), two Check Point flaws (management-server zero-day in targeted attacks; Security Gateway VPN RCE exploited), and a CVSS 10.0 Arista VeloCloud Orchestrator flaw — the security-infrastructure pattern of recent weeks continuing. CISA reports ransomware gangs now exploiting the critical TeamCity flaw, a WordPress vulnerability was exploited within hours of disclosure, and the Chrome-Windows zero-day chain remains in use (CLEANGULP). Intensity comparable to the prior two weeks — held at peak, not above it. Confidence is high.
CISA KEVVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
Microsoft dismantles the EvilTokens device-code phishing service tied to 12,000 inbox compromises — validating last week's raise while reducing forward capacity; package-registry credential theft continues.
RATIONALE & SOURCE TYPES
Microsoft's takedown of EvilTokens — a device-code phishing service tied to roughly 12,000 compromised inboxes — both confirms the scale behind last week's identity raise and removes standing attacker capacity, logged as a pressure-reducing receipt. Package-registry credential theft continues (a malicious npm package posing as a Twilio bug-bounty probe; compromised MemTensor packages delivering a credential stealer via npm and PyPI). Net: steady at the raised level. Confidence is medium.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO→
STEADY
ShinyHunters claims an FBI jobs-portal breach — under investigation, scope unverified; a state-linked supply-chain intrusion at an IT provider; no material-incident filings this window.
RATIONALE & SOURCE TYPES
ShinyHunters claims theft of FBI agent and applicant data; the FBI confirms it is investigating unauthorized activity affecting its jobs portal and journalists have verified a sample of the data, but the claimed scope is unverified — held pending confirmation, consistent with how unevidenced claims have been treated before. Jade Sleet is linked to a backdoored Indian IT provider (supply-chain vector), and ransomware crews are converting the TeamCity exploitation into deployments. No Item 1.05 filings this window. Confidence is medium: disclosure lag and the unverified claim.
INCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch the exploited access set — F5 BIG-IP APM, Check Point management and VPN gateways, VeloCloud — and hunt for pre-patch access on OAuth and VPN paths.
02Patch TeamCity again and audit build agents and their credentials — ransomware crews are now working the CI/CD path CISA flagged.
03Assume disclosure-to-exploitation is hours, not days: pre-stage emergency change windows for internet-facing CMS, mail, and collaboration platforms.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 409 RECEIPTS
REVISION HISTORY
2026-09-28 · 14:00 UTCOriginal publication.
← FULL ARCHIVE