Weekly Threat Digest: 21 to 27 September 2026
HiveForce Labs tracked two attacks, nine actively exploited vulnerabilities and one adversary this week, led by Check Point zero-days CVE-2026-93616 and CVE-2026-85102, F5 BIG-IP APM CVE-2026-94127, PAYLOAD and DragonForce ransomware, and the Meowciety403 extortion group.
Summary
HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, two major attacks were detected, nine vulnerabilities were actively exploited, and one threat actor group was closely monitored, signaling a concerning escalation in malicious activity worldwide.
Among the most significant developments, Check Point is warning that attackers are actively exploiting two critical, no-login-required flaws. One of them, CVE-2026-93616, is a zero-day in the Check Point Management web service that gives attackers code execution on the server that controls firewall policy, administration, and logging. F5 disclosed CVE-2026-94127, a critical unauthenticated remote code execution flaw in the OAuth component of BIG-IP Access Policy Manager (APM), and confirmed it is being actively exploited in the wild.
Meowciety403, also tracked as Nekoneko200, is an emerging, financially motivated extortion group that has been active since August 2026. It operates as a data broker rather than as a confirmed encryption-based ransomware operation. Together, these developments underscore a growing trend of hybrid cyber operations that combine technical exploitation with social engineering, reinforcing the need for timely patching, continuous monitoring, and layered security defenses.
Insights
F5 confirms active exploitation of BIG-IP APM flaw CVE-2026-94127.
A Middle Eastern manufacturer was hit by PAYLOAD's encryption-free attack.
996 Zyxel switches were hacked across 48 countries; patch CVE-2026-7273 now.
CVE-2026-85102 and CVE-2026-93616: Check Point warns of active attacks on two critical pre-auth flaws.
CVE-2026-93952: a zero-day enables unauthenticated privileged takeover of on-premises Arista VCO.
DragonForce hides backdoor traffic inside Microsoft Teams relays.
Threat distribution
Vulnerability volume
Most targeted countries
Activity was also recorded across Spain, Brazil, Vietnam, Canada, South Africa, China, Switzerland, Colombia, Venezuela, Egypt, Mexico, France, Austria, Argentina, South Korea, Greece, Sri Lanka, India, Taiwan, Turkey, Bahrain, the United Kingdom, Israel, the United States, Italy, Japan and many additional countries worldwide.
Attack Details
PAYLOAD Ransomware
PAYLOAD is a ransomware that, instead of deploying an encryptor on Windows systems, turns Active Directory Group Policy into a weapon. The attackers got in through a FortiGate SSL VPN using stolen credentials, gained domain admin-level control, and linked a malicious GPO named "PAYLOAD" at the domain root.
- Type
- Ransomware
- Delivery
- Malicious GPO
- Impact
- Wallpaper hijack, Admin lockout, Data exfiltration
- Platform
- Microsoft Active Directory (Group Policy), Fortinet FortiGate SSL VPN, VMware ESXi
- Targeted CVE
- -
DragonForce Ransomware
DragonForce, now operating as a ransomware cartel, has deployed Backdoor.Turn, a Go-based backdoor that hides command-and-control inside legitimate Microsoft Teams TURN-relay traffic. It pairs this with multi-driver BYOVD exploitation to terminate security tools at kernel level. Its 32-bit Windows locker then encrypts local files and reachable SMB shares using ChaCha8 and RSA-4096.
- Type
- Ransomware
- Delivery
- DLL sideloading, BYOVD
- Impact
- Data encryption, extortion
- Platform
- Microsoft Windows
- Targeted CVE
CVE-2023-52271,CVE-2025-61155,CVE-2025-1055
Patch details for the vulnerable drivers abused by DragonForce: CVE-2023-52271 Topaz Antifraud (wsftprm.sys) is fixed in versions above 2.0.0.0; CVE-2025-1055 K7 Security Anti-Malware (K7RKScan.sys) is fixed in version 23.0.0.10 or later.
Vulnerability Details
All nine vulnerabilities below were reported as zero-days. None carries an associated threat actor in this digest; DragonForce ransomware is associated with three of them.
CVE-2026-7273
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- Zyxel GS1900-8 (before 2.90(AAHH.2)C0), GS1900-8HP (before 2.90(AAHI.2)C0), GS1900-10HP (before 2.90(AAZI.2)C0), GS1900-16 (before 2.90(AAHJ.2)C0), GS1900-24 (before 2.90(AAHL.2)C0), GS1900-24E (before 2.90(AAHK.2)C0), GS1900-24EP (before 2.90(ABTO.2)C0), GS1900-24HPv2 (before 2.90(ABTP.2)C0), GS1900-48 (before 2.90(AAHN.2)C0), GS1900-48HPv2 (before 2.90(ABTQ.2)C0)
- Affected CPE
cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*- CWE ID
CWE-121- Associated TTPs
- T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
- Associated attacks
- -
- Patch details
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
CVE-2026-93616
Check Point Multiple Products Path Traversal Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- Check Point Security Management, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, SmartEvent (R82.20; R82.10 with Jumbo Hotfix Take 44 or lower; R82 with Take 126 or lower; R81.20 with Take 166 or lower; R81.10 with Take 190 or lower, EoS; R80, R80.10, R80.20, R80.30, R80.40, R81, all EoS)
- Affected CPE
cpe:2.3:a:checkpoint:security_management:*:*:*:*:*:*:*:*- CWE ID
CWE-22- Associated TTPs
- T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
- Associated attacks
- -
- Patch details
https://support.checkpoint.com/results/sk/sk1000171/
CVE-2026-85102
Check Point Multiple Products Improper Certificate Validation Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- Check Point Security Gateway, Spark Firewall Centrally Managed, Spark Firewall Locally Managed (R81, EoS; R81.10, EoS; R81.10.x; R81.20; R82; R82.00.x; R82.10)
- Affected CPE
cpe:2.3:a:checkpoint:security_gateway:*:*:*:*:*:*:*:*- Associated TTPs
- T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
- Associated attacks
- -
- Patch details
https://support.checkpoint.com/results/sk/sk1000117
CVE-2026-94127
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- F5 BIG-IP APM (17.1.0 - 17.1.3, 17.5.0 - 17.5.1, 21.1.0)
- Affected CPE
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- CWE ID
CWE-122- Associated TTPs
- T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
- Associated attacks
- -
- Patch details
https://my.f5.com/manage/s/article/K000162605
CVE-2026-93952
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- Arista VeloCloud Orchestrator (VCO) On-Prem (5.2.x before 5.2.3.16, 6.1.x through 6.1.3.7, 6.4.x before 6.4.2.8, 7.0.x through 7.0.0.2)
- Affected CPE
cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*- CWE ID
CWE-20- Associated TTPs
- T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
- Associated attacks
- -
- Patch details
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
CVE-2026-87902
WordPress Unauthenticated Path Traversal Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- WordPress Core (4.7.0 – 7.1.1)
- Affected CPE
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*- CWE ID
CWE-98- Associated TTPs
- T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
- Associated attacks
- -
- Patch details
https://wordpress.org/download/releases/
CVE-2023-52271
Topaz Antifraud Improper Access Control Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- Topaz Antifraud (wsftprm.sys driver)
- Affected CPE
cpe:2.3:a:topazevolution:antifraud:*:*:*:*:*:*:*:*- Associated TTPs
- T1068: Exploitation for Privilege Escalation
- Associated attacks
- DragonForce Ransomware
- Patch details
- Update to the latest version above 2.0.0.0.
CVE-2025-61155
Hotta Studio GameDriverX64 Improper Access Control Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- Tower of Fantasy (Gamedriverx64.sys driver)
- Affected CPE
cpe:2.3:a:hotta_studio:gamedriverx64.sys:*:*:*:*:*:*:*:*- CWE ID
CWE-400- Associated TTPs
- T1068: Exploitation for Privilege Escalation
- Associated attacks
- DragonForce Ransomware
CVE-2025-1055
K7 Computing K7 Security Anti-Malware Missing Authorization Vulnerability
- Celebrity vuln.
- Zero-day
- Affected product
- K7 Security (K7RKScan.sys driver)
- CWE ID
CWE-862- Associated TTPs
- T1068: Exploitation for Privilege Escalation
- Associated attacks
- DragonForce Ransomware
- Patch details
- K7 Security Anti-Malware (K7RKScan.sys) - fixed in version 23.0.0.10 or later.
Actor Details
Meowciety403 (aka Nekoneko200)
Meowciety403, also tracked as Nekoneko200, is an emerging, financially motivated extortion group active since August 2026. It operates as a data broker rather than as a confirmed encryption-based ransomware operation.
- Motive
- Financial gains, information theft
- Targeted industries
- Financial services, financial brokerage and foreign exchange, information technology, IT consulting, technology
- Targeted regions
- United Arab Emirates, Singapore, Germany
- TTPs
TA0001Initial Access,TA0002Execution,TA0003Persistence,TA0005Defense Evasion,TA0008Lateral Movement,TA0040Impact,T1078Valid Accounts,T1059Command and Scripting Interpreter,T1547Boot or Logon AutoStart Execution,T1562Impair Defenses,T1021Remote Services,T1021.001Remote Desktop Protocol,T1080Taint Shared Content,T1657Financial Theft
Recommendations
- 01Security teamsUse this digest to prioritize the nine exploited vulnerabilities and block the indicators related to the threat actor Meowciety403, the malware PAYLOAD, and DragonForce.
- 02Uni5 users: run a scanRun a scan to discover the assets impacted by the nine exploited vulnerabilities from the HivePro Uni5 dashboard.
- 03Uni5 users: simulate attacksTest the efficacy of security controls by simulating the attacks related to the threat actor Meowciety403 and the malware PAYLOAD and DragonForce in Breach and Attack Simulation (BAS).
Indicators of Compromise (IoCs)
| Attack | Type | Value |
|---|---|---|
| PAYLOAD Ransomware | SHA256 | 1CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F |
| PAYLOAD Ransomware | MD5 | E0FD8FF6D39E4C11BDAF860C35FD8DC0 0108656A3E1ADE6CA4F21B084F5E1208 BEA5E267F24D7DA59F6821BFFDBFF293 |
| PAYLOAD Ransomware | TOR address | payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion payload6eualw6kni6v2lqn7ovjcl76ojx25z5unsyvqo3lbqy3bo5qd[.]onion payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd[.]onion |
| DragonForce Ransomware | SHA256 | e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 a4eb9be98d00c961ad8c3329ee80690c1eec98d4c8fa8dd91c371d9ecc451581 |
| DragonForce Ransomware | SHA1 | 55acb53f348c9f6b89343dc8d96522aa75e4cfdb |
| DragonForce Ransomware | MD5 | bd47ae24b03e5ba0f1ab2e95e7acb989 |
| DragonForce Ransomware | File path | C:\Users\Public\log.log |
| DragonForce Ransomware | TOR address | 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd[.]onion z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid[.]onion |
| DragonForce Ransomware | TOX ID | 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20 |
A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.
Top MITRE ATT&CK TTPs
Threat Advisories
- September 2026 Linux Patch Roundup
- Zyxel GS1900 Switches Under Active Attack
- Paws on the Payroll: The Rise of Meowciety403
- Check Point Rushes Fixes as Two Critical Flaws Come Under Active Attack
- CVE-2026-94127: Critical F5 BIG-IP APM Flaw Under Active Exploitation
- Critical Zero-Day in Arista VeloCloud Orchestrator Under Active Attack
- PAYLOAD Ransomware Emerges as a Fast-Growing Extortion Threat
- Race Against the Patch: Critical WordPress RCE Exploited Within Hours
- DragonForce Evolves: Teams-Relayed C2 and BYOVD Kernel Evasion
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
