TL;DR
Check Point's Security Management Server zero-day (CVE-2026-93616) is [exploitation unverified] in targeted attacks. WordPress patches a critical code-execution flaw in version 7.1.2. Microsoft disrupted EvilTokens, a device-code phishing service that compromised 12,000+ inboxes using AI.
Executive Summary
- Check Point disclosed a zero-day vulnerability (CVE-2026-93616) in its Security Management Server [exploitation unverified] in targeted attacks on July 23, allowing unauthenticated script execution.
- WordPress released patch 7.1.2 to fix a critical flaw enabling remote code execution on some servers; details indicate the fix became available September 22.
- Microsoft, with U.S. court authorization, disrupted EvilTokens—a phishing-as-a-service platform using AI throughout the attack chain—which had compromised 12,000+ inboxes.
- Bifrost AI gateway vulnerability (CVE-2026-90898, CVSS 9.8) permits unauthenticated remote command execution; the flaw affects gateways routing to over 20 LLM providers.
- Chinese-speaking threat actors exploited Zyxel GS1900 switches and WordPress vulnerabilities, exfiltrating data from 996 devices; CVE-2026-7273 added to CISA KEV on September 21.
Top Threats Today
1. Check Point Security Management Server Zero-Day Under Active Exploitation
Severity: CRITICAL Affected: Technology
Check Point disclosed CVE-2026-93616, a previously unknown vulnerability in its Security Management Server that allows attackers with access to the web service to execute scripts without authentication [1]. The company confirmed the flaw was actively exploited in a handful of targeted attacks on July 23 [1].
Sources:[1] The Hacker News
Recommended Action
- Immediately restrict network access to Check Point Security Management Server web interfaces to trusted administrative networks only
- Review access logs for July 23 and subsequent dates for suspicious script execution or unauthorized web service activity
- Contact Check Point support for patch availability and deployment guidance
- Monitor for indicators of compromise in downstream protected systems
2. Critical WordPress Core Vulnerability Patched; Code Execution Possible on Some Servers
Severity: HIGH Affected: Technology
WordPress patched a critical vulnerability in its core software via version 7.1.2, released September 22, that allows unauthenticated attackers to load PHP files from outside standard theme directories [1]. Depending on server configuration, this can enable remote code execution [1].
Sources:[1] The Hacker News
Recommended Action
- Update all WordPress installations to version 7.1.2 or later immediately
- Verify server PHP configuration restricts execution of user-uploaded or externally-loaded files
- Audit access logs for suspicious file-load requests targeting non-theme directories since the vulnerability disclosure
- Enable WordPress security plugins to monitor file integrity and unauthorized code execution
3. EvilTokens Phishing Infrastructure Disrupted; 12,000+ Inboxes Compromised
Severity: HIGH Affected: Technology
Microsoft announced the takedown of EvilTokens, a device-code phishing service operating as a phishing-as-a-service platform that deployed artificial intelligence at every stage of its attack chain [1]. The disruption, authorized by the U.S. District Court for the Eastern District of Virginia, resulted in seizure of 50 websites and disabling of more than 150 domains [2]. The service had compromised at least 12,000 inboxes [1].
Sources:[1] The Hacker News[2] Dark Reading
Recommended Action
- Force password reset for all Microsoft 365 users; prioritize accounts in affected organizations
- Review Microsoft 365 mailbox access logs for the past 90 days to identify suspicious forwarding rules, delegation changes, or new device code grants
- Enable phishing-resistant authentication (FIDO2 security keys or Windows Hello) across all critical roles
- Monitor for credential misuse indicators: unusual login locations, times, or bulk mail operations
4. Bifrost AI Gateway Remote Command Execution; 20+ LLM Providers Affected
Severity: HIGH Affected: Technology
A critical vulnerability in Bifrost, an open-source AI gateway, allows unauthenticated attackers to execute arbitrary commands on the gateway server with a single HTTP request via CVE-2026-90898 (CVSS 9.8) [1]. Bifrost routes requests to more than 20 LLM providers, amplifying the potential attack surface [1].
Sources:[1] The Hacker News
Recommended Action
- If Bifrost is deployed, isolate affected gateway instances from production networks pending patch verification
- Review gateway logs for suspicious HTTP requests or command execution patterns
- Apply authentication and rate-limiting controls to all gateway endpoints
- Monitor downstream LLM services for unauthorized queries or data exfiltration
5. Chinese Threat Actors Exploit Zyxel Switches and WordPress; 996 Devices Targeted
Severity: HIGH Affected: Government
A Chinese-speaking threat actor has been actively exploiting vulnerabilities in Zyxel GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and exfiltrate over 18,500 records from backend databases [1]. CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series, was added to the CISA Known Exploited Vulnerabilities catalog on September 21 with a federal remediation deadline of September 24 [1]. The campaign involved multiple CVE identifiers, including CVE-2026-63030, CVE-2026-60137, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-56271, and CVE-2022-0847 [1].
Sources:[1] BleepingComputer
Recommended Action
- URGENT (CISA deadline Sept 24): Patch or isolate all Zyxel GS1900 switches immediately; verify firmware version supports the stack-buffer-overflow fix
- Conduct forensic review of affected switches and connected systems for signs of data exfiltration; prioritize government and sensitive-data networks
- Update WordPress instances and apply all identified patches to related CVEs; restrict switch management access to secure administrative networks
- Enable network segmentation to isolate switch management traffic and monitor egress connections for data theft indicators
Today’s Action Checklist
- ☐ URGENT (CISA deadline Sept 24): Patch Zyxel GS1900 switches or take offline if patch unavailable
- ☐ URGENT: Update all WordPress installations to version 7.1.2 and audit file-load configurations
- ☐ Restrict network access to Check Point Security Management Servers; review July 23+ access logs for intrusion indicators
- ☐ Force password reset for Microsoft 365 users; review mailbox logs for forwarding rules and delegation changes
- ☐ Isolate or patch Bifrost AI gateways; apply authentication controls to all endpoints