Weekly Threat Digest: 21 to 27 SEPTEMBER 2026

Weekly Threat Digest
Download Now
Weekly Threat Digest 21 to 27 September 2026 | Hive Pro Threat Advisory
Weekly Threat Digest/21 to 27 September 2026

Weekly Threat Digest: 21 to 27 September 2026

HiveForce Labs tracked two attacks, nine actively exploited vulnerabilities and one adversary this week, led by Check Point zero-days CVE-2026-93616 and CVE-2026-85102, F5 BIG-IP APM CVE-2026-94127, PAYLOAD and DragonForce ransomware, and the Meowciety403 extortion group.

2 attacks executed9 exploited vulnerabilities1 adversaryMeowciety403PAYLOADDragonForce
Published
September 28, 2026
Period
21 to 27 Sep 2026
Report type
Weekly digest
Attacks
2
Vulnerabilities
9
Adversaries
1
Total CVEs
523.6K
Published (week)
2,848
Exploited
9

01 / Overview

Summary

HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, two major attacks were detected, nine vulnerabilities were actively exploited, and one threat actor group was closely monitored, signaling a concerning escalation in malicious activity worldwide.

Among the most significant developments, Check Point is warning that attackers are actively exploiting two critical, no-login-required flaws. One of them, CVE-2026-93616, is a zero-day in the Check Point Management web service that gives attackers code execution on the server that controls firewall policy, administration, and logging. F5 disclosed CVE-2026-94127, a critical unauthenticated remote code execution flaw in the OAuth component of BIG-IP Access Policy Manager (APM), and confirmed it is being actively exploited in the wild.

Meowciety403, also tracked as Nekoneko200, is an emerging, financially motivated extortion group that has been active since August 2026. It operates as a data broker rather than as a confirmed encryption-based ransomware operation. Together, these developments underscore a growing trend of hybrid cyber operations that combine technical exploitation with social engineering, reinforcing the need for timely patching, continuous monitoring, and layered security defenses.

2
Attacks executed
9
Vulnerabilities exploited
1
Adversaries in action

02 / Highlights

Insights

F5 confirms active exploitation of BIG-IP APM flaw CVE-2026-94127.

A Middle Eastern manufacturer was hit by PAYLOAD's encryption-free attack.

996 Zyxel switches were hacked across 48 countries; patch CVE-2026-7273 now.

CVE-2026-85102 and CVE-2026-93616: Check Point warns of active attacks on two critical pre-auth flaws.

CVE-2026-93952: a zero-day enables unauthenticated privileged takeover of on-premises Arista VCO.

DragonForce hides backdoor traffic inside Microsoft Teams relays.

Threat distribution
Ransomware
Vulnerability volume
523.6K
Total vulnerabilities published
2,848
Published in the week
9
Exploited vulnerabilities
Most targeted countries
GermanySingaporeUnited Arab EmiratesPhilippinesThailand

Activity was also recorded across Spain, Brazil, Vietnam, Canada, South Africa, China, Switzerland, Colombia, Venezuela, Egypt, Mexico, France, Austria, Argentina, South Korea, Greece, Sri Lanka, India, Taiwan, Turkey, Bahrain, the United Kingdom, Israel, the United States, Italy, Japan and many additional countries worldwide.


03 / Attacks

Attack Details

PAYLOAD Ransomware

PAYLOAD is a ransomware that, instead of deploying an encryptor on Windows systems, turns Active Directory Group Policy into a weapon. The attackers got in through a FortiGate SSL VPN using stolen credentials, gained domain admin-level control, and linked a malicious GPO named "PAYLOAD" at the domain root.

Type
Ransomware
Delivery
Malicious GPO
Impact
Wallpaper hijack, Admin lockout, Data exfiltration
Platform
Microsoft Active Directory (Group Policy), Fortinet FortiGate SSL VPN, VMware ESXi
Targeted CVE
-
DragonForce Ransomware

DragonForce, now operating as a ransomware cartel, has deployed Backdoor.Turn, a Go-based backdoor that hides command-and-control inside legitimate Microsoft Teams TURN-relay traffic. It pairs this with multi-driver BYOVD exploitation to terminate security tools at kernel level. Its 32-bit Windows locker then encrypts local files and reachable SMB shares using ChaCha8 and RSA-4096.

Type
Ransomware
Delivery
DLL sideloading, BYOVD
Impact
Data encryption, extortion
Platform
Microsoft Windows
Targeted CVE
CVE-2023-52271, CVE-2025-61155, CVE-2025-1055

Patch details for the vulnerable drivers abused by DragonForce: CVE-2023-52271 Topaz Antifraud (wsftprm.sys) is fixed in versions above 2.0.0.0; CVE-2025-1055 K7 Security Anti-Malware (K7RKScan.sys) is fixed in version 23.0.0.10 or later.


04 / Vulnerabilities

Vulnerability Details

All nine vulnerabilities below were reported as zero-days. None carries an associated threat actor in this digest; DragonForce ransomware is associated with three of them.

CVE-2026-7273

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Celebrity vuln.
Zero-day
Affected product
Zyxel GS1900-8 (before 2.90(AAHH.2)C0), GS1900-8HP (before 2.90(AAHI.2)C0), GS1900-10HP (before 2.90(AAZI.2)C0), GS1900-16 (before 2.90(AAHJ.2)C0), GS1900-24 (before 2.90(AAHL.2)C0), GS1900-24E (before 2.90(AAHK.2)C0), GS1900-24EP (before 2.90(ABTO.2)C0), GS1900-24HPv2 (before 2.90(ABTP.2)C0), GS1900-48 (before 2.90(AAHN.2)C0), GS1900-48HPv2 (before 2.90(ABTQ.2)C0)
Affected CPE
cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:*, cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*
CWE ID
CWE-121
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Associated attacks
-
Patch details
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
CVE-2026-93616

Check Point Multiple Products Path Traversal Vulnerability

Celebrity vuln.
Zero-day
Affected product
Check Point Security Management, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, SmartEvent (R82.20; R82.10 with Jumbo Hotfix Take 44 or lower; R82 with Take 126 or lower; R81.20 with Take 166 or lower; R81.10 with Take 190 or lower, EoS; R80, R80.10, R80.20, R80.30, R80.40, R81, all EoS)
Affected CPE
cpe:2.3:a:checkpoint:security_management:*:*:*:*:*:*:*:*
CWE ID
CWE-22
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Associated attacks
-
Patch details
https://support.checkpoint.com/results/sk/sk1000171/
CVE-2026-85102

Check Point Multiple Products Improper Certificate Validation Vulnerability

Celebrity vuln.
Zero-day
Affected product
Check Point Security Gateway, Spark Firewall Centrally Managed, Spark Firewall Locally Managed (R81, EoS; R81.10, EoS; R81.10.x; R81.20; R82; R82.00.x; R82.10)
Affected CPE
cpe:2.3:a:checkpoint:security_gateway:*:*:*:*:*:*:*:*
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Associated attacks
-
Patch details
https://support.checkpoint.com/results/sk/sk1000117
CVE-2026-94127

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

Celebrity vuln.
Zero-day
Affected product
F5 BIG-IP APM (17.1.0 - 17.1.3, 17.5.0 - 17.5.1, 21.1.0)
Affected CPE
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
CWE ID
CWE-122
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Associated attacks
-
Patch details
https://my.f5.com/manage/s/article/K000162605
CVE-2026-93952

Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Celebrity vuln.
Zero-day
Affected product
Arista VeloCloud Orchestrator (VCO) On-Prem (5.2.x before 5.2.3.16, 6.1.x through 6.1.3.7, 6.4.x before 6.4.2.8, 7.0.x through 7.0.0.2)
Affected CPE
cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*
CWE ID
CWE-20
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Associated attacks
-
Patch details
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
CVE-2026-87902

WordPress Unauthenticated Path Traversal Vulnerability

Celebrity vuln.
Zero-day
Affected product
WordPress Core (4.7.0 – 7.1.1)
Affected CPE
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
CWE ID
CWE-98
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Associated attacks
-
Patch details
https://wordpress.org/download/releases/
CVE-2023-52271

Topaz Antifraud Improper Access Control Vulnerability

Celebrity vuln.
Zero-day
Affected product
Topaz Antifraud (wsftprm.sys driver)
Affected CPE
cpe:2.3:a:topazevolution:antifraud:*:*:*:*:*:*:*:*
Associated TTPs
T1068: Exploitation for Privilege Escalation
Associated attacks
DragonForce Ransomware
Patch details
Update to the latest version above 2.0.0.0.
CVE-2025-61155

Hotta Studio GameDriverX64 Improper Access Control Vulnerability

Celebrity vuln.
Zero-day
Affected product
Tower of Fantasy (Gamedriverx64.sys driver)
Affected CPE
cpe:2.3:a:hotta_studio:gamedriverx64.sys:*:*:*:*:*:*:*:*
CWE ID
CWE-400
Associated TTPs
T1068: Exploitation for Privilege Escalation
Associated attacks
DragonForce Ransomware
CVE-2025-1055

K7 Computing K7 Security Anti-Malware Missing Authorization Vulnerability

Celebrity vuln.
Zero-day
Affected product
K7 Security (K7RKScan.sys driver)
CWE ID
CWE-862
Associated TTPs
T1068: Exploitation for Privilege Escalation
Associated attacks
DragonForce Ransomware
Patch details
K7 Security Anti-Malware (K7RKScan.sys) - fixed in version 23.0.0.10 or later.

05 / Adversaries

Actor Details

Meowciety403 (aka Nekoneko200)

Meowciety403, also tracked as Nekoneko200, is an emerging, financially motivated extortion group active since August 2026. It operates as a data broker rather than as a confirmed encryption-based ransomware operation.

Motive
Financial gains, information theft
Targeted industries
Financial services, financial brokerage and foreign exchange, information technology, IT consulting, technology
Targeted regions
United Arab Emirates, Singapore, Germany
TTPs
TA0001 Initial Access, TA0002 Execution, TA0003 Persistence, TA0005 Defense Evasion, TA0008 Lateral Movement, TA0040 Impact, T1078 Valid Accounts, T1059 Command and Scripting Interpreter, T1547 Boot or Logon AutoStart Execution, T1562 Impair Defenses, T1021 Remote Services, T1021.001 Remote Desktop Protocol, T1080 Taint Shared Content, T1657 Financial Theft

06 / Response

Recommendations

  1. 01
    Security teams
    Use this digest to prioritize the nine exploited vulnerabilities and block the indicators related to the threat actor Meowciety403, the malware PAYLOAD, and DragonForce.
  2. 02
    Uni5 users: run a scan
    Run a scan to discover the assets impacted by the nine exploited vulnerabilities from the HivePro Uni5 dashboard.
  3. 03
    Uni5 users: simulate attacks
    Test the efficacy of security controls by simulating the attacks related to the threat actor Meowciety403 and the malware PAYLOAD and DragonForce in Breach and Attack Simulation (BAS).

07 / Indicators

Indicators of Compromise (IoCs)

AttackTypeValue
PAYLOAD RansomwareSHA256
1CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F
PAYLOAD RansomwareMD5
E0FD8FF6D39E4C11BDAF860C35FD8DC0
0108656A3E1ADE6CA4F21B084F5E1208
BEA5E267F24D7DA59F6821BFFDBFF293
PAYLOAD RansomwareTOR address
payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion
payload6eualw6kni6v2lqn7ovjcl76ojx25z5unsyvqo3lbqy3bo5qd[.]onion
payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd[.]onion
DragonForce RansomwareSHA256
e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22
a4eb9be98d00c961ad8c3329ee80690c1eec98d4c8fa8dd91c371d9ecc451581
DragonForce RansomwareSHA1
55acb53f348c9f6b89343dc8d96522aa75e4cfdb
DragonForce RansomwareMD5
bd47ae24b03e5ba0f1ab2e95e7acb989
DragonForce RansomwareFile path
C:\Users\Public\log.log
DragonForce RansomwareTOR address
3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd[.]onion
z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid[.]onion
DragonForce RansomwareTOX ID
1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20

A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.


08 / MITRE ATT&CK

Top MITRE ATT&CK TTPs

T1059
Command and Scripting Interpreter
T1190
Exploit Public-Facing Application
T1588
Obtain Capabilities
T1588.006
Vulnerabilities
T1027
Obfuscated Files or Information
T1078
Valid Accounts
T1071
Application Layer Protocol
T1562
Impair Defenses
T1068
Exploitation for Privilege Escalation
T1005
Data from Local System
T1021
Remote Services
T1135
Network Share Discovery
T1486
Data Encrypted for Impact
T1489
Service Stop
T1490
Inhibit System Recovery
T1552
Unsecured Credentials
T1499
Endpoint Denial of Service
T1059.003
Windows Command Shell
T1189
Drive-by Compromise
T1204
User Execution

09 / References

Threat Advisories

  • September 2026 Linux Patch Roundup
  • Zyxel GS1900 Switches Under Active Attack
  • Paws on the Payroll: The Rise of Meowciety403
  • Check Point Rushes Fixes as Two Critical Flaws Come Under Active Attack
  • CVE-2026-94127: Critical F5 BIG-IP APM Flaw Under Active Exploitation
  • Critical Zero-Day in Arista VeloCloud Orchestrator Under Active Attack
  • PAYLOAD Ransomware Emerges as a Fast-Growing Extortion Threat
  • Race Against the Patch: Critical WordPress RCE Exploited Within Hours
  • DragonForce Evolves: Teams-Relayed C2 and BYOVD Kernel Evasion

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.