The Matthew Chapman Podcast

F5 APM OAuth Zero-Day Is Live Ahead of Friday's Deadline

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 6:15
Here is your briefing for Wednesday, September 23, 2026. F5 says attackers are already exploiting a critical heap overflow in BIG-IP Access Policy Manager when it acts as an OAuth authorization server. C.V.E. twenty twenty-six dash ninety-four thousand one hundred twenty-seven scores nine point eight, needs no login, and hits the data plane on the virtual server itself, so locking down the management interface does nothing. CISA dropped it on the Known Exploited list the same day F5 disclosed, with a September twenty-fifth deadline for federal agencies. Affected trains are twenty-one point one, seventeen point five, and seventeen point one when an APM access policy and an OAuth authorization server profile sit on the same virtual server. Appliance mode is in scope. F5 shipped engineering hotfixes and an iRule stopgap through support. Hunt repeated invalid-token UserInfo failures in the APM log, weird audit commands, and a TMM SIGABRT in short order. If your edge hands out OAuth tokens through BIG-IP, patch before Friday's calendar becomes the incident ticket. cPanel patched a CalDAV and CardDAV flaw, C.V.E. twenty twenty-six dash eighty-seven thousand eight hundred ninety-nine, that lets any logged-in hosting account run code as root and take full control of the shared server. On a box that sells accounts to the public, that is any customer, or anyone who stole a customer's login. Same release also fixes a WP Toolkit bug that lets one account modify other accounts' databases, plus a local calendar-and-contacts read across tenants. Fixed builds start at eleven point one thirty-four point oh point fifty-seven, eleven point one thirty-six point oh point forty-one, and eleven point one thirty-eight point oh point eight, with WP Toolkit six point eleven point three for the cross-account database issue. No workaround, no exploit status published, and researcher Ali Mustafa keeps finding these panel-to-root paths. Shared hosting control planes are still the cheapest path from one rented account to every neighbor on the machine. Run upcp and update WP Toolkit before your next customer becomes your rootkit. Volexity says Chinese actor U.T.A. zero five six five exploited a Chrome-to-Windows zero-day chain in early September through fake media and N.G.O. sites. Two Chrome bugs, C.V.E. twenty twenty-six dash eighty-five thousand forty-six and eighty-seven thousand four hundred ninety-one, plus a Windows Advanced Local Procedure Call flaw, C.V.E. twenty twenty-six dash eighty-five thousand eight hundred eighty, broke the sandbox and landed remote code execution. Phishing lures aimed at Asian government targets, including spoofed China Digital Times and Center for American Progress pages. The BlueMoon kit dropped chrome_cleanup.exe, a Visual C implant Volexity calls CLEANGULP, with shell, process list, file transfer, and beacon-object execution over a Conversation-lookalike C-two domain. Multiple Chinese crews appear to be sharing and customizing the same kit. Browser plus O.S. zero-days delivered through lookalike journalism sites is still the quiet path past the email gateway. Patch Chrome and that September Windows ALPC fix, and treat activist-themed PDF and link bait like untrusted binaries. DepthFirst published a use-after-free in the Linux A.F. underscore UNIX socket garbage collector, C.V.E. twenty twenty-six dash eighty thousand five hundred twenty-one, that escapes a container and reaches host root. Upstream fixed it August sixth. Ubuntu still lists twenty-six point oh four, twenty-four point oh four, and twenty-two point oh four L.T.S., including cloud kernels for A.W.S., Azure, and G.C.P., as vulnerable with work in progress. DepthFirst released exploit code aimed at Ubuntu twenty-six point oh four. A.F. underscore UNIX and SCM_RIGHTS are allowed in default Docker and Kubernetes seccomp profiles, so the path bypasses namespaces, cgroups, and seccomp from inside the guest. No confirmed wild use yet, but a public PoC against unpatched L.T.S. is enough. Move untrusted workloads to microVMs like Firecracker or Kata if you cannot wait on Canonical, and do not treat a shared-kernel container as a security boundary just because the brochure said so. Microsoft and partners seized about fifty EvilTokens sites and disabled more than one hundred fifty support domains for a phishing-as-a-service kit that abused OAuth device code flow and used A.I. at every step. Storm-two nine nine two sold the platform on Telegram. Victims pasted a code into the real microsoft.com slash devicelogin page, handed over tokens without giving a password, and stayed owned even after a reset if sessions were not revoked. Microsoft ties it to more than twelve thousand compromised inboxes across over ten thousand organizations. The product sold mailbox-reading chatbots, B.E.C. drafting, org-role mapping, and wire-transfer hunting for about five hundred dollars a month on top of kit fees. Two men were arrested in London. Device code phishing plus an A.I. analyst that writes the invoice fraud for you is the new commodity stack. Disable device code flow where you do not need it, revoke refresh tokens on suspicious sign-ins, and assume the next kit is already cloning the playbook. An F5 APM OAuth zero-day already in KEV with a Friday deadline, cPanel CalDAV turning one hosting login into root, a Chinese Chrome-Windows chain dropping CLEANGULP, a public Ubuntu container-escape exploit while L.T.S. waits, and EvilTokens' A.I. phishing shop taken offline. Edge identity, shared hosting panels, browser zero-days, container kernels, and device-code OAuth all earned a louder alarm overnight. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show