Monthly Threat Digest : August 2026

Monthly Threat Digest
Download Now
Monthly Threat Digest — August 2026 | HiveForce Labs

Summary

August reshaped the cybersecurity landscape with active exploitation of 5 zero-days. A rising cyber-espionage threat gained attention: Cl0p-linked operators hit internet-facing PTC Windchill and FlexPLM servers, chaining a pre-auth FlexPLM WSDL disclosure with a Windchill login servlet flaw (CVE-2026-12569) for unauthenticated RCE, then dropping hex-named JSP web shells and staging engineering data for extortion.

The same hunger for quiet access drove the espionage side, only the payoff was intelligence. Mirage Kitten, an Iranian group also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore, fielded three undocumented families: the NightLedger backdoor plus WebSocket tunnelers BridgeHead and ArcBridge, aimed at the Middle East, Africa, and South Asia.

Rails patched CVE-2026-66066, dubbed KindaRails2Shell, a critical Active Storage flaw that leaves unsafe libvips loaders on by default, so apps are vulnerable simply because nobody chose otherwise. Head Mare weaponised trust instead, chaining two flaws in unpatched TrueConf servers for SYSTEM-level code execution, planting a web shell, swapping the TrueConf Client installer for a trojanized build carrying PhantomCore, then adding PhantomGraph, which hides its C2 traffic inside Microsoft OneDrive. With these increasing risks, strengthening defensive measures is more critical than ever in today’s digital landscape.

Insights for the month highlight India, Spain, Germany, Brazil, and Russia as the top-targeted countries, and the Government, Education, Healthcare, Finance, and Manufacturing sectors as the top-targeted industries.


Celebrity Vulnerabilities

CVE IDCelebrity VulnerabilityAffected ProductAssociated ActorCWE IDPatch Link
CVE-2026-66066KindaRails2ShellRuby on Rails Active Storage, all versions before 7.2.3.2; 8.0 and later before 8.0.5.1; 8.1 and later before 8.1.3.1-CWE-1188link
CVE-2026-64638XSS2ShellWordPress Core 4.7.0 through 7.0.2, all branches; before 7.0.3-CWE-79link
CVE-2024-6387regreSSHionOpenSSH serverAPT36CWE-362, CWE-364link, link

Full CPE, associated-attack, and TTP detail for each celebrity vulnerability above is documented in the source digest and mirrors the individual advisories already published for regreSSHion (APT36 / PATCHCORD / SHEETCORD / HACKERAI C2 Agent), KindaRails2Shell, and XSS2Shell.


Vulnerabilities Summary

CVE IDNameAffected Product
CVE-2026-18577N-able N-central Authentication Bypass Using an Alternate Path or ChannelN-able N-central (Before 2026.3.1.7)
CVE-2026-18556N-able N-central Authentication Bypass Using an Alternate Path or ChannelN-able N-central (Before 2026.2)
CVE-2026-66066KindaRails2Shell (Ruby on Rails Active Storage Arbitrary File Read)Ruby on Rails Active Storage
CVE-2026-63077JetBrains TeamCity Deserialization of Untrusted DataJetBrains TeamCity On-Premises
CVE-2026-64638XSS2Shell (WordPress Core Pre-Auth Reflected Cross-Site Scripting)WordPress Core
CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-FreeWindows Server, Windows 10-11 26H1
CVE-2026-62832Windows User Profile Service Elevation of PrivilegeWindows Server, Windows 10-11 26H1
CVE-2026-72971Windows Container Isolation FS Filter Driver (unionfs.sys) TamperingWindows 11 26H1
CVE-2025-49113RoundCube Webmail Deserialization of Untrusted DataRoundcube Webmail
CVE-2024-51324Baidu Antivirus Improper Privilege Management Arbitrary Process TerminationBdApiUtil driver of Baidu Antivirus
CVE-2024-55591Fortinet FortiOS and FortiProxy Authentication BypassFortiOS, FortiProxy
CVE-2025-24472Fortinet FortiOS and FortiProxy Authentication BypassFortiOS, FortiProxy
CVE-2024-6387regreSSHion (OpenSSH Unauthenticated Remote Code Execution)OpenSSH server
CVE-2026-12569PTC Windchill and FlexPLM Improper Input ValidationPTC Windchill PDMLink and FlexPLM
CVE-2026-65400Apple macOS Improper AuthenticationApple macOS Sonoma, Sequoia, Tahoe
CVE-2026-64849MLflow Server-Side Request ForgeryMLflow
CVE-2024-1709ConnectWise ScreenConnect Authentication BypassConnectWise ScreenConnect
CVE-2023-48788Fortinet FortiClient EMS SQL InjectionFortinet FortiClient EMS
CVE-2025-10035FortiClient EMSFortra GoAnywhere MFT Deserialization of Untrusted DataFortiClient EMSFortra GoAnywhere MFT
CVE-2026-1731SQL Injection BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command InjectionBeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-59310Broadcom VMware vCenter Path TraversalVMware vCenter, Cloud Foundation, vSphere Foundation, Telco Cloud Platform/Infrastructure
CVE-2026-59309Broadcom VMware vCenter Authentication BypassVMware vCenter, Cloud Foundation, vSphere Foundation, Telco Cloud Platform/Infrastructure
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access ControlOracle HTTP Server, Oracle WebLogic Server Proxy Plug-in
CVE-2026-60004Gitea Code InjectionGitea
CVE-2026-75604Vercel Next.js Windows-Hosted Remote Code ExecutionVercel Next.js
CVE-2026-36425OPSWAT AppRemover Arbitrary Process TerminationOPSWAT AppRemover
CVE-2026-82078PaperCut NG and PaperCut MF Unsafe Dynamic Class LoadingPaperCut NG and PaperCut MF
CVE-2026-81578PaperCut NG and PaperCut MF Authentication BypassPaperCut NG and PaperCut MF

Attacks Summary

Attack NameTypeImpact
NightLedgerBackdoorRemote access, Data exfiltration
BridgeHeadTunneling toolNetwork pivoting, Traffic relay, Perimeter bypass
ArcBridgeTunneling toolNetwork pivoting, Traffic relay, Perimeter bypass
ChainDropWormCredential theft, supply chain compromise
FDMTPBackdoorSystem Compromise
XCSSETModular malwareInformation theft, Defenses disabled
PhantomCoreBackdoorSystem Compromise
PhantomGraphBackdoorSystem Compromise
TroyBackdoorSystem Compromise
FudModuleRootkitSystem Compromise
RelayShellWebshellSystem Compromise
MISTPENDownloaderLoads additional payload
ForestTigerBackdoorSystem Compromise
DeadLockRansomwareData stolen, Backups disabled, Operations halted
GunraRansomwareData encryption, extortion
PATCHCORDBackdoorSystem Compromise
SHEETCORDBackdoorSystem Compromise
HACKERAI C2 AgentFrameworkSystem Compromise, persistence
CoolClientBackdoorSystem Compromise
PlugXRATKeylogging, screen capture, system compromise
Monero MinerCryptominerData Theft
AntinoBackdoorRemote access, Persistent foothold, Credential theft
ClientKingBackdoorRemote access, Persistent foothold, Credential theft
XG-WebFrameworkData exfiltration, Command execution
SilentDataCollectorStealerSteal Data
NetworkShareScannerWormSystem disruption
SilentEncryptorRansomwareEncrypt Data, Data theft
MedusaRansomwareEncryption, data theft/extortion
Babuk-derived ESXi ransomwareRansomwareData encryption, Service disruption, Log destruction
GrandoreiroBanking TrojanBanking fraud, System profiling, Payload delivery
C2LooperBackdoorFoothold, recon, payload delivery
SynkLoaderLoaderData theft
QUICAgentBackdoorRemote exec, espionage
WeedHackMaaSremote-access
GoCaracalRATData theft, keylogging, RDP, SOCKS5
BandookRATFile theft, credential theft, keylogging
Delphi loaderLoaderPayload delivery
SparkRATRATSystem Compromise

Adversaries Summary

Actor NameMotiveOriginAttack/MalwareProduct
Mirage KittenInformation theft and espionageIranNightLedger, BridgeHead, ArcBridgeWindows
Head MareInformation Theft, Espionage, Financial Gain-PhantomCore, PhantomGraphTrueConf Server, TrueConf Client
Payroll PiratesFinancial Gains--Microsoft 365, Outlook, Graph API, Entra ID
LazarusInformation theft and espionage, Sabotage and destruction, Financial crimeNorth KoreaTroy, FudModule, RelayShell, MISTPEN, ForestTigerMicrosoft Windows, Roundcube Webmail
APT36Information theft and espionagePakistanPATCHCORD, SHEETCORD, HACKERAI C2 AgentOpenSSH server
HoneyMyteInformation theft and espionageChinaCoolClient, PlugXMicrosoft Windows
JewelbugEspionage and Financial GainsChinaAntino, ClientKing, XG-WebWindows, Linux, Chrome, Firefox, x86-64 servers, ARM64, routers
Storm-1175Espionage and Financial Gains-Medusa ransomwareWindows and Linux
Dark CaracalEspionage and Information TheftLebanonGoCaracal, Bandook, Delphi loaderWindows

Targeted Products, Countries & Industries

Targeted products spanned RMM/IT management platforms (N-able N-central), web framework components (Ruby on Rails Active Storage), CI/CD build servers (JetBrains TeamCity), CMS platforms (WordPress Core), operating systems (Windows Server 2012–2025, Windows 10-11 26H1, Apple macOS Sonoma/Sequoia/Tahoe), webmail (Roundcube), endpoint security drivers (BdApiUtil/Baidu Antivirus, OPSWAT AppRemover), network security appliances (FortiOS/FortiProxy), managed file transfer (Fortra GoAnywhere MFT), remote access daemons (OpenSSH server), PLM enterprise applications (PTC Windchill PDMLink and FlexPLM), MLOps platforms (MLflow), remote support software (ConnectWise ScreenConnect, BeyondTrust Remote Support/PRA), virtualization management (VMware vCenter/Cloud Foundation/vSphere Foundation/Telco Cloud), web server middleware (Oracle HTTP Server/WebLogic Proxy Plug-in), Git hosting (Gitea), web application frameworks (Vercel Next.js), and print management servers (PaperCut NG/MF).

Targeted countries were led by India, Spain, Germany, Brazil, and Russia, with a broad tail of activity recorded across the Czech Republic, United States, France, Italy, Singapore, Poland, Switzerland, Colombia, Romania, Croatia, Sri Lanka, Denmark, Turkey, Bangladesh, Portugal, Indonesia, Argentina, Uruguay, and dozens of additional countries worldwide. Targeted industries were led by Government, Education, Healthcare, Finance, and Manufacturing, designating a cyber battleground spanning public-sector, academic, clinical, financial, and industrial environments, with Agriculture recording the least targeted activity.


Top 25 MITRE ATT&CK TTPs

#TTP
1T1059 Command and Scripting Interpreter
2T1071 Application Layer Protocol
3T1036 Masquerading
4T1027 Obfuscated Files or Information
5T1071.001 Web Protocols
6T1190 Exploit Public-Facing Application
7T1082 System Information Discovery
8T1204 User Execution
9T1566 Phishing
10T1036.005 Match Legitimate Name or Location
11T1070 Indicator Removal
12T1057 Process Discovery
13T1083 File and Directory Discovery
14T1041 Exfiltration Over C2 Channel
15T1105 Ingress Tool Transfer
16T1140 Deobfuscate/Decode Files or Information
17T1204.002 Malicious File
18T1574 Hijack Execution Flow
19T1005 Data from Local System
20T1102 Web Service
21T1583 Acquire Infrastructure
22T1059.003 Windows Command Shell
23T1033 System Owner/User Discovery
24T1562.001 Disable or Modify Tools
25T1588 Obtain Capabilities

Top Indicators of Compromise (IOCs)

Attack NameTypeValue
ChainDropSHA25654dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668, fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb, 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
FDMTPSHA256795594ad5e6f2868cc4d8ed12dabf4f3999a1477c6b250527c5ede9a98528fb9
PhantomCoreMD5c5a460e4e68a088f6e51b2c6474642ec, 129462164a7d52e9ea8560b60f0412c5, ec0bf4a2186a88874e9f26f07cfeb532, b348642146ea34771e5785c5857950f5
PhantomGraphSHA256b9e4052b310f9451eca9784a4a33bf5282d1bd07e3359eba9648be625e2e40dd
PlugXSHA256489f43be558b2679284ceabed7adc4f3dd1fd2b459b97b7d59375cb8383cd19a
MoneroSHA2560e4541c3153ec5ed01497f19cf4f63d0d9529976ce67da55a0f1a561ff4fb7e6535bfc7b607c838182752fd6e6732794
AntinoSHA25664b9f35206cb8ad0b79a07dad35acf024d2d429855352674f3fecc0798b96cfd, 1f8a2658aeabcfecee2fe37978ccbcddfee8045e23ed5f069b4c1743acad4ccd
MedusaEmailkey[.]medusa[.]serviceteam[@]protonmail[.]com, medusa[.]support[@]onionmail[.]org, mds[.]svt[.]breach[@]protonmail[.]com, mds[.]svt[.]mir2[@]protonmail[.]com, MedusaSupport[@]cock[.]li
MedusaSHA2560cefeb6210b7103fd32b996beff518c9b6e1691a97bb1cda7f5fb57905c4be96, 9632d7e4a87ec12fdd05ed3532f7564526016b78972b2cd49a610354d672523c

Complete indicator sets for NightLedger, BridgeHead, ArcBridge, XCSSET, and every other tracked family — including full domain lists and additional hashes — are catalogued in the source digest appendix and on the Uni5Xposure platform.


Top 5 Takeaways

01

In August 2026, 5 zero-day vulnerabilities surfaced across products from Fortinet, Windows, Apple, Fortra, and PaperCut.

02

Newly identified malware active in August included a broad mix of Backdoors, Ransomware, and RATs. Key discoveries were NightLedger, FDMTP, PhantomCore, PhantomGraph, Troy, ForestTiger, PATCHCORD, SHEETCORD, CoolClient, Antino, ClientKing, C2Looper, and QUICAgent, each representing distinct capabilities ranging from stealthy persistence to large-scale compromise.

03

Cyberattacks concentrated heavily on India, Spain, Germany, Brazil, and Russia, which absorbed most hostile activity. Espionage operations and financially motivated intrusions drove the surge, underscoring that no region remained insulated as adversaries expanded their operations worldwide.

04

Government, Education, Healthcare, Finance, and Manufacturing sectors absorbed the bulk of targeted activity, with ransomware operations, data theft, and espionage campaigns driving operational disruption.

05

Activity during the period was dominated by Lazarus, APT36, and Storm-1175, all well-resourced groups known for sustained, high-impact operations. Their campaigns shaped a threat landscape defined by disciplined tradecraft, rapid exploitation cycles, and a clear focus on high-value targets across public and private sectors.


Recommendations

Security Teams: This digest can be used as a guide to help security teams prioritize the 28 significant vulnerabilities and block the indicators related to the 10 active threat actors, 38 active malware, and 255 potential MITRE TTPs.

Uni5 Users: This is an actionable threat digest for HivePro Uni5 customers, who can get comprehensive insights into their threat exposure and take action easily through the HivePro Uni5 dashboard by running a scan to discover the assets impacted by the 28 significant vulnerabilities, and testing the efficacy of their security controls by simulating the attacks related to active threat actors, active malware, and potential MITRE TTPs in Breach and Attack Simulation (BAS).

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.