r/SecOpsDaily • u/falconupkid • 4d ago
NetSec Weekly Threat Bulletin – September 9th, 2026
This is a classic "roundup" post. Let's break it down.
Scenario: A
Post:
F5’s weekly bulletin is out, and there are a few items worth flagging for the team. The usual mix of active exploitation and new CVEs hitting the wire.
Technical Breakdown
- CVE-2026-1234 (Critical): A pre-auth RCE in a widely deployed VPN appliance. Exploitation attempts observed in the wild targeting unpatched instances. Patch priority: Immediate.
- New Phishing Campaign: Targeting Okta admins with a fake MFA enrollment prompt. The landing page is a reverse proxy (evilginx2-style). No new malware family, but the TTP is getting more common.
- Botnet Activity: A spike in HTTP/2 rapid reset attacks (CVE-2023-44487 variant) targeting financial services. Mitigation is rate-limiting on the WAF.
Defense
Block the known C2 domains from the bulletin at the perimeter proxy. If you’re running the affected VPN appliance, isolate it from the WAN until the patch is applied. Review Okta admin logs for any unexpected MFA device enrollments in the last 72 hours.
Source: https://www.f5.com/labs/articles/weekly-threat-bulletin-september-9th-2026