DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-09-28 · 14:00 UTC
ARCHIVED READING · PERMANENT RECORD

WEEK OF SEPTEMBER 28, 2026

73/ 100HIGH PRESSURE

Zero-days in F5 and Check Point management planes keep exploitation at its peak, a takedown dents device-code phishing, and the dial holds.

UNCHANGED SINCE LAST WEEK2026-W40ISSUED 2026-09-28 · 14:00 UTCMETHODOLOGY V1.1

SIGNALS

ACTIVE EXPLOITATION→
STEADY

A third week at peak: an F5 BIG-IP APM zero-day hits OAuth-fronting access gateways, Check Point's management server and VPN gateway are exploited, and a WordPress flaw is worked within hours of disclosure.

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY

Microsoft dismantles the EvilTokens device-code phishing service tied to 12,000 inbox compromises — validating last week's raise while reducing forward capacity; package-registry credential theft continues.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO→
STEADY

ShinyHunters claims an FBI jobs-portal breach — under investigation, scope unverified; a state-linked supply-chain intrusion at an IT provider; no material-incident filings this window.

CONFIDENCE · MEDIUM

THREE MOVES THIS WEEK
01Patch the exploited access set — F5 BIG-IP APM, Check Point management and VPN gateways, VeloCloud — and hunt for pre-patch access on OAuth and VPN paths.
02Patch TeamCity again and audit build agents and their credentials — ransomware crews are now working the CI/CD path CISA flagged.
03Assume disclosure-to-exploitation is hours, not days: pre-stage emergency change windows for internet-facing CMS, mail, and collaboration platforms.

WHY WE BELIEVED THIS

RECEIPT LOG · WEEK 409 RECEIPTS
CISA KEV · ANCHORCISA adds VeloCloud, F5 BIG-IP APM, and two Check Point CVEs to the KEV catalog — F5 APM and the Check Point management flaw exploited as zero-days; VeloCloud rated CVSS 10.0. Ten KEV additions in the window overall→ EXPLOITATION · 2026-09-22
VENDOR ADVISORY · CORROB.F5 advisory K000162605: BIG-IP APM heap overflow (exploited)→ EXPLOITATION · 2026-09-22
INCIDENT REPORTING · CORROB.BleepingComputer: Check Point warns of Security Gateway VPN RCE exploitation→ EXPLOITATION · 2026-09-23
INCIDENT REPORTING · ANCHORThe Hacker News: Microsoft takes down the EvilTokens device-code phishing service (12,000 inbox compromises) — Enforcement takedown: confirms the scale behind last week's raise while removing standing attacker capacity↓ IDENTITY · 2026-09-22
INCIDENT REPORTING · ANCHORThe Hacker News: ShinyHunters claims FBI breach of agent and applicant data — FBI confirms investigating unauthorized activity on its jobs portal; journalists verified a data sample; claimed scope unverified — held pending confirmation→ INTRUSION · 2026-09-23
REVISION HISTORY
2026-09-28 · 14:00 UTCOriginal publication.
READINGS ARE IMMUTABLE ONCE PUBLISHED · CORRECTIONS APPEND TO THE REVISION HISTORY ABOVE · RUBRIC AT /METHODOLOGY
← FULL ARCHIVE