Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison

2026-09-25T02:51:37Z•994ea7a4cf74b841e56183132f41d977e403d63c9ec2f0173962904c83a33c4f
CVE-2026-85102CVE-2026-87902CVE-2026-94127AI malwareArista VeloCloud OrchestratorCISA KEVCheck PointEDR evasionF5 BIG-IP APMWordPressactive exploitationcybercrimedevice-code phishinggovernment breachinfostealerphishing-as-a-serviceremote code executionzero-day

What happened

Security Affairs reports active exploitation of multiple critical vulnerabilities, including an F5 BIG-IP APM zero-day enabling unauthenticated remote code execution, Check Point VPN authentication bypass, and other flaws added to CISA’s KEV catalog. Additional coverage describes WordPress unauthenticated file inclusion leading to possible RCE, phishing-as-a-service compromises affecting over 12,000 inboxes, malware using AI models for decision-making, an infostealer disabling security tools, and alleged government-portal and FBI breaches. The most urgent risks are internet-facing F5, Check-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
994ea7a4cf74b841e56183132f41d977e403d63c9ec2f0173962904c83a33c4f
Enrichment time
2026-09-25T02:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.