Volexity reported that the China-aligned group UTA0565 exploited a three-vulnerability zero-day chain affecting Chrome and Microsoft before the defects were disclosed or patched, during September 3–4. The chain included CVE-2026-85046 and CVE-2026-87491, remote-code-execution defects in Chromium-based browser JavaScript engines, and CVE-2026-85880, a Windows Advanced Local Procedure Call privilege-escalation zero-day.
Why it matters
Volexity said UTA0565 used multiple fake websites, phishing emails targeting Asian government entities, and spoofed domains impersonating the Center for American Progress and China Digital Times. The reported chain crosses browser and operating-system boundaries, making the distinction between those layers central to its practitioner relevance.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Identity · The Hacker News
What happened
Attackers are exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM) that can allow unauthenticated code execution on a BIG-IP system, according to F5. The vulnerability affects only systems where APM operates as an OAuth authorization server issuing access tokens to applications.
Why it matters
The reported condition narrows relevance to a specific authorization role rather than all BIG-IP deployments.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Identity · Helpnetsecurity
What happened
Check Point released emergency fixes for critical Management Server vulnerability CVE-2026-93616, which had been exploited as early as July 23, 2026. Check Point confirmed that CVE-2026-85102, a pre-authentication remote-code-execution vulnerability in Check Point Quantum Security Gateway, was probed a few days after patches were released on September 9, 2026.
Why it matters
The two reported cases distinguish exploitation of a management component from post-patch probing of a gateway defect.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.