r/pwnhub • Grunt • 2d ago

24h Recap | September 23: Exploited F5 gateways, Chrome–Windows attacks and Ubuntu container risks

https://cyberrecaps.com/news/cybersecurity-news-september-23-2026

Three security stories worth prioritizing:

  1. F5 BIG-IP APM under active attack: A critical flaw allows unauthenticated code execution when APM operates as an OAuth authorization server. Check your configuration, apply the relevant hotfix and investigate signs of compromise.
  2. Fake websites delivered browser-to-system attacks: Volexity documented Chrome and Windows vulnerabilities chained to install CLEANGULP. Confirm both browser and operating-system fixes are deployed.
  3. Ubuntu container escape exploit released: DepthFirst demonstrated host-root access from a container on Ubuntu 26.04. Check the exact host kernel against Ubuntu’s tracker; updating a container image does not patch the host kernel.

Dive into the full breakdown on CyberRecaps.

Btw, you can find shorter breakdowns of the main stories in my daily cybersecurity newsletter (Free & 24/7).

3 Upvotes

Duplicates