Cyware Daily Threat Intelligence - September 23, 2026

Phishing emails disguised as payment plans are slashing through enterprise defenses, delivering ISO files that trigger ransomware and threaten public data leaks. Cyware highlights how the Global Group’s new Ransomware-as-a-Service operation leverages double extortion and command-and-control infrastructure, putting operational uptime and sensitive information at risk for large organizations.
A critical authentication-bypass flaw in Arista VeloCloud Orchestrator is letting attackers pivot into edge devices, with a CVSS 10.0 rating and active exploitation already underway. Some organizations remain exposed as fixes are only available for select release trains, leaving others in a holding pattern while attackers probe for vulnerable deployments.
Zero-day exploits are being weaponized in rapid succession as UTA0565, a China-aligned espionage group, targets Asian government organizations. By chaining vulnerabilities in Chrome and Microsoft products, the group is stealing sensitive data and deploying new malware, with researchers tracking overlap across multiple China-linked teams.
Top Malware Reported in the Last 24 Hours
Global Group Ransomware-as-a-Service
Global Group is a rebranded cybercriminal operation offering a Ransomware-as-a-Service platform built on the legacy of Black Lock and Mamona. Global Group uses double extortion to encrypt data and threaten public leaks. Global Group disables security processes and pulls down payloads from command-and-control infrastructure after initial infection. Global Group reaches victims through phishing emails disguised as payment plans, with a PDF “Download” button leading to a malicious URL and an ISO file containing executable files. Global Group targets large enterprises, causing operational downtime and the risk of data exposure if ransom demands are not met. Cofense reported Global Group connecting to a C2 endpoint at hXXps://globalsupportupdate[.]top during attacks.
Rapuncel Infostealer
Rapuncel is an infostealer campaign focused on credential theft and aggressive defense evasion. Rapuncel attempts to neutralize security tools before stealing data. Rapuncel spreads via fake GitHub pages that rank for queries like “LastPass Authenticator download,” directing victims to a malicious installer. Rapuncel gains local SYSTEM rights and installs a kernel driver to disable 145 antivirus and endpoint-security products. Rapuncel steals passwords, cryptowallet data, Discord and Steam tokens, and screenshots across all monitors, exfiltrating data to attacker-controlled servers. LastPass’s Threat Intelligence, Mitigation, and Escalation (TIME) team and Delphos Labs discovered Rapuncel’s campaign.
Akira Ransomware
Akira ransomware operators are exploiting CVE-2024-40766, an improper access control vulnerability in SonicWall VPN and management interfaces. Akira uses this flaw to break into exposed systems and launch ransomware intrusions. Akira targets organizations with unpatched SonicWall devices, emphasizing the risks of patch debt. Akira’s campaign has left approximately 213,900 SonicWall interfaces exposed to the public internet. Akira has repeatedly compromised managed service providers through separate customer environments. SecurityBrief reported the campaign, and a patch is available.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-93952: Arista VeloCloud Orchestrator Authentication Bypass
CVE-2026-93952 is a critical authentication-bypass vulnerability in Arista VeloCloud Orchestrator (VCO) with a CVSS score of 10.0. CVE-2026-93952 allows remote attackers to access privileged internal functionality and pivot into connected edge devices. CVE-2026-93952 is actively exploited in the wild, and CISA has added it to the Known Exploited Vulnerabilities catalog. The Hacker News and Security.nl reported that fixes are available for the 5.2 and 6.4 release trains, but not yet for 6.1 and 7.0, leaving some organizations exposed. CVE-2026-93952 primarily affects VCO deployments using certificate-based authentication, including Certificate Acquire and Certificate Required modes.
CVE-2026-94127: F5 BIG-IP APM Zero-Day
CVE-2026-94127 is a zero-day remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM). CVE-2026-94127 allows unauthenticated attackers to run arbitrary code and potentially take full control of affected systems. CVE-2026-94127 is triggered by specially crafted network traffic and only impacts BIG-IP APM appliances configured with both an access policy and an OAuth profile. CVE-2026-94127 is actively exploited in the wild, according to the Netherlands’ NCSC warning cited by Security.nl. F5 has released security updates and published indicators of compromise to help organizations assess breaches. A fix is available via F5 security updates.
CVE-2026-85102 and CVE-2026-93616: Check Point Security Gateway Flaws
CVE-2026-85102 and CVE-2026-93616 are vulnerabilities in Check Point Security Gateway and Management environments. CVE-2026-85102 stems from improper validation of certificate data during VPN negotiation, while CVE-2026-93616 involves a pre-authentication path traversal enabling arbitrary-path script execution. Attackers began probing CVE-2026-85102 on September 12, 2026, and Check Point reported limited attacks for CVE-2026-93616 on July 23, 2026. Check Point advised reviewing logs for anomalous certificate-based Mobile Access logins tied to CVE-2026-85102. Affected versions include R81, R81.10, R81.20, R82, R82.10, and R82.20, impacting Security Gateway, Spark Firewall, and Security Management deployments. Fixes are available.
Top Threat Actors Reported in Last 24 hours
UTA0565 (China-aligned espionage group)
UTA0565 is a suspected China-aligned espionage group focused on intelligence collection. UTA0565 exploited zero-day vulnerabilities CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 in Chrome and Microsoft products to gain remote code execution and escalate privileges. UTA0565 paired exploits with phishing emails and spoofed domains impersonating organizations such as the Center for American Progress and China Digital Times. UTA0565 targeted Asian government organizations, aiming to steal sensitive data and compromise decision-making systems. UTA0565 delivered a previously undocumented malware family named CLEANGULP to maintain durable access. Researchers, including Proofpoint, observed overlap with APT31, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket.
Red Heron-linked Threat Actor
A Chinese-speaking threat actor linked to Red Heron is suspected to originate from China and is motivated by data theft. The Red Heron-linked group chained exploits across ZyXEL GS1900 Smart Managed Switches (CVE-2026-7273) and WordPress (CVE-2026-63030, CVE-2026-60137), as well as technologies including PAN-OS GlobalProtect, FlowiseAI, Nuclio, Proxmox, and Ubiquity. The Red Heron-linked group used 17 scripts to bypass controls, escalate privileges, and extract registry data, and ran password-spraying attacks to access internal SQL servers. The Red Heron-linked group targeted government and law-enforcement agencies, compromising 996 devices and stealing more than 18,566 records, including accounts, plaintext passwords, and personal data. The campaign included a “red-on-red” compromise of a Russian state organization in occupied Ukraine.
ShinyHunters
ShinyHunters is a cybercrime group suspected to be motivated by personal leverage. ShinyHunters claims to have hacked the FBI by exploiting a zero-day vulnerability in Oracle PeopleSoft on the bureau’s jobs website, briefly defacing the portal with a seizure banner. ShinyHunters states the PeopleSoft flaw enabled remote code execution and lateral movement into FBI-managed infrastructure, including AWS GovCloud-hosted systems. ShinyHunters disrupted or exposed multiple FBI services, including Criminal Justice Information Services, Human Resources, and MedLink. ShinyHunters claims to have stolen 2 TB to 3 TB of data containing PII and PHI, with samples including addresses and birth dates. ShinyHunters is demanding the FBI amend or remove a May 2026 report about them and is threatening to leak data if demands are not met within a week.
Frequently Asked Questions
What is The Global Group? The Global Group, a rebranded cybercriminal operation, is pushing a Ransomware-as-a-Service playbook built on the legacy of Black Lock and Mamona, using double extortion to encrypt data and threaten public leaks. It reaches victims through phishing emails disguised as payment plans, where a PDF “Download” button sends targets to a malicious URL and ultimately an ISO file containing executable files used to install the ransomware.
What is Rapuncel? Rapuncel is an infostealer campaign that pairs credential theft with unusually aggressive defense evasion, aiming to neutralize security tools before it loots data. It spreads via fake GitHub pages designed to rank in search results for queries like “LastPass Authenticator download,” funneling victims to a booby-trapped installer.
What is Akira? Akira ransomware operators are exploiting CVE-2024-40766, a two-year-old SonicWall bug, to break into exposed VPN and management interfaces and kick off ransomware intrusions. The flaw is an improper access control issue, and the campaign underscores how “patch debt” can accumulate when organizations can’t keep up with the volume of fixes.
What is CVE-2026-93952? A critical authentication-bypass flaw in Arista VeloCloud Orchestrator (VCO) (CVE-2026-93952, CVSS 10.0) lets remote attackers access privileged internal functionality and potentially pivot into connected edge devices. The risk is concentrated in VCO installations using certificate-based authentication between VeloCloud Edge and the orchestrator, including Certificate Acquire and Certificate Required modes, meaning not every deployment is exposed.
What is CVE-2026-94127? A zero-day remote code execution bug in F5 BIG-IP Access Policy Manager (APM) (CVE-2026-94127) allows unauthenticated attackers to run arbitrary code and potentially take full control of affected systems. The issue is triggered by specially crafted network traffic, but it only impacts BIG-IP APM appliances configured with both an access policy and an OAuth profile, narrowing exposure to certain setups.
What is CVE-2026-85102? Two Check Point vulnerabilities under active attack — CVE-2026-85102 and CVE-2026-93616 — can let unauthenticated attackers execute code or run scripts on affected Security Gateway and Management environments. In its advisory, Check Point said CVE-2026-85102 stems from improper validation of certificate data during VPN negotiation, while CVE-2026-93616 involves a pre-authentication path traversal that enables arbitrary-path script execution.
What is UTA0565? UTA0565, a China-aligned espionage group, has been caught exploiting a tight window of zero-day bugs in Chrome and Microsoft products before fixes could land. They used CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to gain remote code execution and escalate privileges, pairing the exploits with phishing emails and spoofed domains masquerading as outlets like the Center for American Progress and China Digital Times.
What is Red Heron? A Chinese-speaking threat actor linked to the Red Heron group has been chaining exploits across widely used infrastructure to break into networks and pull data at scale. Since early June 2026, they have targeted ZyXEL GS1900 Smart Managed Switches via CVE-2026-7273 and WordPress via CVE-2026-63030 and CVE-2026-60137, alongside attempts against technologies including PAN-OS GlobalProtect, FlowiseAI, Nuclio, Proxmox, and Ubiquity.
What is ShinyHunters? ShinyHunters, a cybercrime group, claims it hacked the FBI by exploiting a zero-day vulnerability in Oracle PeopleSoft on the bureau’s jobs website, briefly defacing the portal with a seizure banner. They say the PeopleSoft flaw provided remote code execution, after which they moved laterally into FBI-managed infrastructure including AWS GovCloud-hosted systems.