
Episode notes
Last Week in Tech for Monday 28 September 2026, covering the week from 21 September.
F5 BIG-IP APM zero-day (22 Sep). CVE-2026-94127, heap overflow enabling unauthenticated RCE. F5 scores it CVSS v3.1 9.8 and CVSS v4.0 9.3. Exploitable only where APM acts as an OAuth authorisation server with an access policy and OAuth profile on the same virtual server. Added to CISA KEV the same day, federal deadline 25 Sep. Hotfixes for 17.1.x, 17.5.x and 21.1.0, plus an iRule workaround via F5 Support. Shadowserver sees 14,700+ IPs with a BIG-IP APM fingerprint; patch status unknown.
Check Point firewalls and management (22 Sep). CVE-2026-85102, pre-auth RCE in Security Gateway and Spark VPN certificate handling, patched 9 Sep, with exploitation attempts against Spark customers since 12 Sep. CVE-2026-93616, pre-auth path traversal in Security Management, a zero-day with targeted attacks seen on 23 July and a fix released 22 Sep; LivePatch does not fix it. Both rated critical by Check Point. Also in the same KEV batch: Arista VeloCloud Orchestrator CVE-2026-93952, actively exploited, rated critical; fixed in 5.2.3.16 and 6.4.2.8.
Bitget hack (24 Sep). First put at US$351.6M, revised by CEO Gracy Chen on 25 Sep to about US$387.5M after uncounted transfers from the same incident were traced. Attackers compromised a wallet backend, spoofed transaction data and triggered Bitget's own authorisation process; private keys were not taken. Hot and warm wallets hit; cold wallets secure. Losses covered by Bitget's User Protection Fund; some funds frozen; 5% recovery bounty offered. Bitget says the flaw is fixed and is reopening withdrawals in phases from 28 Sep. Bitget suspects North Korea — its own assessment, not confirmed by law enforcement.
AI agents run a carding campaign (single-source). Gambit Security describes an ongoing campaign dating to July in which one operator used three open-source agent tools. Between 10 and 15 Sep alone it counted 105 attacks and at least 27 unnamed companies compromised; 600,000+ card records were taken from two victims, skimmers confirmed on 19 named victims, and 100+ further infected sites linked. Mean cost about US$25 per completed scan; campaign estimated at US$12,000–18,000.
Akamai–Anthropic deal (24 Sep). US$11.6bn over seven years for CPU workloads on Akamai Cloud, expandable by up to US$9bn. Anthropic receives a warrant for up to about 5% of Akamai. Akamai expects about US$5.5bn in related capex, partly to pre-buy memory.
ShinyHunters' FBI claim. The FBI confirmed only that it is aware of a claimed compromise of FBIJobs.gov and is investigating. The PeopleSoft zero-day, data volume and systems named are unverified claims; no new CVE. PeopleSoft users should confirm the June fix for CVE-2026-35273 is applied.
Coming up: Wednesday, the OpenAI agent inside a Services Australia portal. Friday, one stolen app key and hundreds of online stores.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: F5 advisory K000162605; CISA KEV; BleepingComputer; The Register; Rapid7; Check Point; Arista SA-0183; SecurityWeek; CoinDesk; CNBC; Gambit Security; Akamai newsroom; TechCrunch; Cybersecurity Dive.
