Summary
August reshaped the cybersecurity landscape with active exploitation of 5 zero-days. A rising cyber-espionage threat gained attention: Cl0p-linked operators hit internet-facing PTC Windchill and FlexPLM servers, chaining a pre-auth FlexPLM WSDL disclosure with a Windchill login servlet flaw (CVE-2026-12569) for unauthenticated RCE, then dropping hex-named JSP web shells and staging engineering data for extortion.
The same hunger for quiet access drove the espionage side, only the payoff was intelligence. Mirage Kitten, an Iranian group also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore, fielded three undocumented families: the NightLedger backdoor plus WebSocket tunnelers BridgeHead and ArcBridge, aimed at the Middle East, Africa, and South Asia.
Rails patched CVE-2026-66066, dubbed KindaRails2Shell, a critical Active Storage flaw that leaves unsafe libvips loaders on by default, so apps are vulnerable simply because nobody chose otherwise. Head Mare weaponised trust instead, chaining two flaws in unpatched TrueConf servers for SYSTEM-level code execution, planting a web shell, swapping the TrueConf Client installer for a trojanized build carrying PhantomCore, then adding PhantomGraph, which hides its C2 traffic inside Microsoft OneDrive. With these increasing risks, strengthening defensive measures is more critical than ever in today’s digital landscape.
Insights for the month highlight India, Spain, Germany, Brazil, and Russia as the top-targeted countries, and the Government, Education, Healthcare, Finance, and Manufacturing sectors as the top-targeted industries.
Celebrity Vulnerabilities
| CVE ID | Celebrity Vulnerability | Affected Product | Associated Actor | CWE ID | Patch Link |
|---|---|---|---|---|---|
CVE-2026-66066 | KindaRails2Shell | Ruby on Rails Active Storage, all versions before 7.2.3.2; 8.0 and later before 8.0.5.1; 8.1 and later before 8.1.3.1 | - | CWE-1188 | link |
CVE-2026-64638 | XSS2Shell | WordPress Core 4.7.0 through 7.0.2, all branches; before 7.0.3 | - | CWE-79 | link |
CVE-2024-6387 | regreSSHion | OpenSSH server | APT36 | CWE-362, CWE-364 | link, link |
Full CPE, associated-attack, and TTP detail for each celebrity vulnerability above is documented in the source digest and mirrors the individual advisories already published for regreSSHion (APT36 / PATCHCORD / SHEETCORD / HACKERAI C2 Agent), KindaRails2Shell, and XSS2Shell.
Vulnerabilities Summary
| CVE ID | Name | Affected Product |
|---|---|---|
CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel | N-able N-central (Before 2026.3.1.7) |
CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel | N-able N-central (Before 2026.2) |
CVE-2026-66066 | KindaRails2Shell (Ruby on Rails Active Storage Arbitrary File Read) | Ruby on Rails Active Storage |
CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data | JetBrains TeamCity On-Premises |
CVE-2026-64638 | XSS2Shell (WordPress Core Pre-Auth Reflected Cross-Site Scripting) | WordPress Core |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free | Windows Server, Windows 10-11 26H1 |
CVE-2026-62832 | Windows User Profile Service Elevation of Privilege | Windows Server, Windows 10-11 26H1 |
CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering | Windows 11 26H1 |
CVE-2025-49113 | RoundCube Webmail Deserialization of Untrusted Data | Roundcube Webmail |
CVE-2024-51324 | Baidu Antivirus Improper Privilege Management Arbitrary Process Termination | BdApiUtil driver of Baidu Antivirus |
CVE-2024-55591 | Fortinet FortiOS and FortiProxy Authentication Bypass | FortiOS, FortiProxy |
CVE-2025-24472 | Fortinet FortiOS and FortiProxy Authentication Bypass | FortiOS, FortiProxy |
CVE-2024-6387 | regreSSHion (OpenSSH Unauthenticated Remote Code Execution) | OpenSSH server |
CVE-2026-12569 | PTC Windchill and FlexPLM Improper Input Validation | PTC Windchill PDMLink and FlexPLM |
CVE-2026-65400 | Apple macOS Improper Authentication | Apple macOS Sonoma, Sequoia, Tahoe |
CVE-2026-64849 | MLflow Server-Side Request Forgery | MLflow |
CVE-2024-1709 | ConnectWise ScreenConnect Authentication Bypass | ConnectWise ScreenConnect |
CVE-2023-48788 | Fortinet FortiClient EMS SQL Injection | Fortinet FortiClient EMS |
CVE-2025-10035 | FortiClient EMSFortra GoAnywhere MFT Deserialization of Untrusted Data | FortiClient EMSFortra GoAnywhere MFT |
CVE-2026-1731 | SQL Injection BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) |
CVE-2026-59310 | Broadcom VMware vCenter Path Traversal | VMware vCenter, Cloud Foundation, vSphere Foundation, Telco Cloud Platform/Infrastructure |
CVE-2026-59309 | Broadcom VMware vCenter Authentication Bypass | VMware vCenter, Cloud Foundation, vSphere Foundation, Telco Cloud Platform/Infrastructure |
CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control | Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in |
CVE-2026-60004 | Gitea Code Injection | Gitea |
CVE-2026-75604 | Vercel Next.js Windows-Hosted Remote Code Execution | Vercel Next.js |
CVE-2026-36425 | OPSWAT AppRemover Arbitrary Process Termination | OPSWAT AppRemover |
CVE-2026-82078 | PaperCut NG and PaperCut MF Unsafe Dynamic Class Loading | PaperCut NG and PaperCut MF |
CVE-2026-81578 | PaperCut NG and PaperCut MF Authentication Bypass | PaperCut NG and PaperCut MF |
Attacks Summary
| Attack Name | Type | Impact |
|---|---|---|
| NightLedger | Backdoor | Remote access, Data exfiltration |
| BridgeHead | Tunneling tool | Network pivoting, Traffic relay, Perimeter bypass |
| ArcBridge | Tunneling tool | Network pivoting, Traffic relay, Perimeter bypass |
| ChainDrop | Worm | Credential theft, supply chain compromise |
| FDMTP | Backdoor | System Compromise |
| XCSSET | Modular malware | Information theft, Defenses disabled |
| PhantomCore | Backdoor | System Compromise |
| PhantomGraph | Backdoor | System Compromise |
| Troy | Backdoor | System Compromise |
| FudModule | Rootkit | System Compromise |
| RelayShell | Webshell | System Compromise |
| MISTPEN | Downloader | Loads additional payload |
| ForestTiger | Backdoor | System Compromise |
| DeadLock | Ransomware | Data stolen, Backups disabled, Operations halted |
| Gunra | Ransomware | Data encryption, extortion |
| PATCHCORD | Backdoor | System Compromise |
| SHEETCORD | Backdoor | System Compromise |
| HACKERAI C2 Agent | Framework | System Compromise, persistence |
| CoolClient | Backdoor | System Compromise |
| PlugX | RAT | Keylogging, screen capture, system compromise |
| Monero Miner | Cryptominer | Data Theft |
| Antino | Backdoor | Remote access, Persistent foothold, Credential theft |
| ClientKing | Backdoor | Remote access, Persistent foothold, Credential theft |
| XG-Web | Framework | Data exfiltration, Command execution |
| SilentDataCollector | Stealer | Steal Data |
| NetworkShareScanner | Worm | System disruption |
| SilentEncryptor | Ransomware | Encrypt Data, Data theft |
| Medusa | Ransomware | Encryption, data theft/extortion |
| Babuk-derived ESXi ransomware | Ransomware | Data encryption, Service disruption, Log destruction |
| Grandoreiro | Banking Trojan | Banking fraud, System profiling, Payload delivery |
| C2Looper | Backdoor | Foothold, recon, payload delivery |
| SynkLoader | Loader | Data theft |
| QUICAgent | Backdoor | Remote exec, espionage |
| WeedHack | MaaS | remote-access |
| GoCaracal | RAT | Data theft, keylogging, RDP, SOCKS5 |
| Bandook | RAT | File theft, credential theft, keylogging |
| Delphi loader | Loader | Payload delivery |
| SparkRAT | RAT | System Compromise |
Adversaries Summary
| Actor Name | Motive | Origin | Attack/Malware | Product |
|---|---|---|---|---|
| Mirage Kitten | Information theft and espionage | Iran | NightLedger, BridgeHead, ArcBridge | Windows |
| Head Mare | Information Theft, Espionage, Financial Gain | - | PhantomCore, PhantomGraph | TrueConf Server, TrueConf Client |
| Payroll Pirates | Financial Gains | - | - | Microsoft 365, Outlook, Graph API, Entra ID |
| Lazarus | Information theft and espionage, Sabotage and destruction, Financial crime | North Korea | Troy, FudModule, RelayShell, MISTPEN, ForestTiger | Microsoft Windows, Roundcube Webmail |
| APT36 | Information theft and espionage | Pakistan | PATCHCORD, SHEETCORD, HACKERAI C2 Agent | OpenSSH server |
| HoneyMyte | Information theft and espionage | China | CoolClient, PlugX | Microsoft Windows |
| Jewelbug | Espionage and Financial Gains | China | Antino, ClientKing, XG-Web | Windows, Linux, Chrome, Firefox, x86-64 servers, ARM64, routers |
| Storm-1175 | Espionage and Financial Gains | - | Medusa ransomware | Windows and Linux |
| Dark Caracal | Espionage and Information Theft | Lebanon | GoCaracal, Bandook, Delphi loader | Windows |
Targeted Products, Countries & Industries
Targeted products spanned RMM/IT management platforms (N-able N-central), web framework components (Ruby on Rails Active Storage), CI/CD build servers (JetBrains TeamCity), CMS platforms (WordPress Core), operating systems (Windows Server 2012–2025, Windows 10-11 26H1, Apple macOS Sonoma/Sequoia/Tahoe), webmail (Roundcube), endpoint security drivers (BdApiUtil/Baidu Antivirus, OPSWAT AppRemover), network security appliances (FortiOS/FortiProxy), managed file transfer (Fortra GoAnywhere MFT), remote access daemons (OpenSSH server), PLM enterprise applications (PTC Windchill PDMLink and FlexPLM), MLOps platforms (MLflow), remote support software (ConnectWise ScreenConnect, BeyondTrust Remote Support/PRA), virtualization management (VMware vCenter/Cloud Foundation/vSphere Foundation/Telco Cloud), web server middleware (Oracle HTTP Server/WebLogic Proxy Plug-in), Git hosting (Gitea), web application frameworks (Vercel Next.js), and print management servers (PaperCut NG/MF).
Targeted countries were led by India, Spain, Germany, Brazil, and Russia, with a broad tail of activity recorded across the Czech Republic, United States, France, Italy, Singapore, Poland, Switzerland, Colombia, Romania, Croatia, Sri Lanka, Denmark, Turkey, Bangladesh, Portugal, Indonesia, Argentina, Uruguay, and dozens of additional countries worldwide. Targeted industries were led by Government, Education, Healthcare, Finance, and Manufacturing, designating a cyber battleground spanning public-sector, academic, clinical, financial, and industrial environments, with Agriculture recording the least targeted activity.
Top 25 MITRE ATT&CK TTPs
| # | TTP |
|---|---|
| 1 | T1059 Command and Scripting Interpreter |
| 2 | T1071 Application Layer Protocol |
| 3 | T1036 Masquerading |
| 4 | T1027 Obfuscated Files or Information |
| 5 | T1071.001 Web Protocols |
| 6 | T1190 Exploit Public-Facing Application |
| 7 | T1082 System Information Discovery |
| 8 | T1204 User Execution |
| 9 | T1566 Phishing |
| 10 | T1036.005 Match Legitimate Name or Location |
| 11 | T1070 Indicator Removal |
| 12 | T1057 Process Discovery |
| 13 | T1083 File and Directory Discovery |
| 14 | T1041 Exfiltration Over C2 Channel |
| 15 | T1105 Ingress Tool Transfer |
| 16 | T1140 Deobfuscate/Decode Files or Information |
| 17 | T1204.002 Malicious File |
| 18 | T1574 Hijack Execution Flow |
| 19 | T1005 Data from Local System |
| 20 | T1102 Web Service |
| 21 | T1583 Acquire Infrastructure |
| 22 | T1059.003 Windows Command Shell |
| 23 | T1033 System Owner/User Discovery |
| 24 | T1562.001 Disable or Modify Tools |
| 25 | T1588 Obtain Capabilities |
Top Indicators of Compromise (IOCs)
| Attack Name | Type | Value |
|---|---|---|
| ChainDrop | SHA256 | 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668, fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb, 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc |
| FDMTP | SHA256 | 795594ad5e6f2868cc4d8ed12dabf4f3999a1477c6b250527c5ede9a98528fb9 |
| PhantomCore | MD5 | c5a460e4e68a088f6e51b2c6474642ec, 129462164a7d52e9ea8560b60f0412c5, ec0bf4a2186a88874e9f26f07cfeb532, b348642146ea34771e5785c5857950f5 |
| PhantomGraph | SHA256 | b9e4052b310f9451eca9784a4a33bf5282d1bd07e3359eba9648be625e2e40dd |
| PlugX | SHA256 | 489f43be558b2679284ceabed7adc4f3dd1fd2b459b97b7d59375cb8383cd19a |
| Monero | SHA256 | 0e4541c3153ec5ed01497f19cf4f63d0d9529976ce67da55a0f1a561ff4fb7e6535bfc7b607c838182752fd6e6732794 |
| Antino | SHA256 | 64b9f35206cb8ad0b79a07dad35acf024d2d429855352674f3fecc0798b96cfd, 1f8a2658aeabcfecee2fe37978ccbcddfee8045e23ed5f069b4c1743acad4ccd |
| Medusa | key[.]medusa[.]serviceteam[@]protonmail[.]com, medusa[.]support[@]onionmail[.]org, mds[.]svt[.]breach[@]protonmail[.]com, mds[.]svt[.]mir2[@]protonmail[.]com, MedusaSupport[@]cock[.]li | |
| Medusa | SHA256 | 0cefeb6210b7103fd32b996beff518c9b6e1691a97bb1cda7f5fb57905c4be96, 9632d7e4a87ec12fdd05ed3532f7564526016b78972b2cd49a610354d672523c |
Complete indicator sets for NightLedger, BridgeHead, ArcBridge, XCSSET, and every other tracked family — including full domain lists and additional hashes — are catalogued in the source digest appendix and on the Uni5Xposure platform.
Top 5 Takeaways
In August 2026, 5 zero-day vulnerabilities surfaced across products from Fortinet, Windows, Apple, Fortra, and PaperCut.
Newly identified malware active in August included a broad mix of Backdoors, Ransomware, and RATs. Key discoveries were NightLedger, FDMTP, PhantomCore, PhantomGraph, Troy, ForestTiger, PATCHCORD, SHEETCORD, CoolClient, Antino, ClientKing, C2Looper, and QUICAgent, each representing distinct capabilities ranging from stealthy persistence to large-scale compromise.
Cyberattacks concentrated heavily on India, Spain, Germany, Brazil, and Russia, which absorbed most hostile activity. Espionage operations and financially motivated intrusions drove the surge, underscoring that no region remained insulated as adversaries expanded their operations worldwide.
Government, Education, Healthcare, Finance, and Manufacturing sectors absorbed the bulk of targeted activity, with ransomware operations, data theft, and espionage campaigns driving operational disruption.
Activity during the period was dominated by Lazarus, APT36, and Storm-1175, all well-resourced groups known for sustained, high-impact operations. Their campaigns shaped a threat landscape defined by disciplined tradecraft, rapid exploitation cycles, and a clear focus on high-value targets across public and private sectors.
Recommendations
Security Teams: This digest can be used as a guide to help security teams prioritize the 28 significant vulnerabilities and block the indicators related to the 10 active threat actors, 38 active malware, and 255 potential MITRE TTPs.
Uni5 Users: This is an actionable threat digest for HivePro Uni5 customers, who can get comprehensive insights into their threat exposure and take action easily through the HivePro Uni5 dashboard by running a scan to discover the assets impacted by the 28 significant vulnerabilities, and testing the efficacy of their security controls by simulating the attacks related to active threat actors, active malware, and potential MITRE TTPs in Breach and Attack Simulation (BAS).
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
