Monthly Threat Digest JULY 2026

Monthly Threat Digest
Download Now
Monthly Threat Digest — July 2026 | HiveForce Labs

Summary

July's digest was dominated by thirteen actively exploited zero-days. TA488 hit the US and Europe via a Microsoft Exchange flaw (CVE-2026-42897) deploying OWAReaper, while UNK_MassTraction exploited Roundcube's CVE-2025-49113 against university research departments. Arista patched CVE-2026-16812 in VeloCloud Orchestrator, attackers chained SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) for root-level access, and Cavern Manticore ran stealthy espionage against Israel.


Insights

  • Cisco's own firewall manager had a skeleton key baked in: CVE-2026-20316 turns built-in credentials into an actively exploited zero-day.
  • Just opening the email is the exploit: TA488's CVE-2026-42897 turns a glance at Outlook Web Access into the disk-free OWAReaper backdoor.
  • Coinbase Cartel: 100 victims, zero encryption, all extortion.

Celebrity Vulnerabilities

Five vulnerabilities earned "celebrity" status in July: Bad Epoll, RoguePlanet, CitrixBleed 2, and wp2shell.

CVE-2026-46242 Bad Epoll: Linux kernel use-after-free (CWE-416), fixed in 6.18.33/7.0.10/7.1. CVE-2026-63030 & CVE-2026-60137 wp2shell: WordPress Core interpretation-conflict chained with SQL injection, an unauthenticated takeover of its ~500 million sites. Also branded: CVE-2026-50656 RoguePlanet (Defender privilege escalation, in Qilin's arsenal) and CVE-2025-5777 CitrixBleed 2 (NetScaler OOB read, used by INC ransomware).


Vulnerabilities Exploited

35 vulnerabilities were actively exploited in July, each a Zero-Day or Celebrity Vulnerability in the CISA KEV catalog.

CVE IDNameAffected ProductAssociated Actors
CVE-2025-29635D-Link DIR-823X Command InjectionD-Link DIR-823X 240126/240802RustDuck
CVE-2017-17215Huawei HG532 RCEHuawei HG532RustDuck
CVE-2018-8007Apache CouchDB Privilege EscalationApache CouchDB ≤1.7.1RustDuck
CVE-2024-1781Totolink Command InjectionTOTOLINK X6000R AX3000RustDuck
CVE-2026-45659SharePoint Deserialization of Untrusted DataSharePoint Server (multiple editions)
CVE-2025-3248Langflow Missing AuthenticationLangflow before 1.3.0JADEPUFFER
CVE-2021-29441Nacos AuthFilter Auth Bypass by SpoofingAlibaba Nacos before 1.4.1JADEPUFFER
CVE-2026-46242Bad Epoll (Linux Kernel Use After Free)Linux Kernel
CVE-2026-48282Adobe ColdFusion Path TraversalAdobe ColdFusion 2025.9/2023.20 & earlier
CVE-2024-42009Roundcube Webmail XSSRoundcube WebmailUNK_MassTraction toolset
CVE-2025-49113Roundcube Deserialization of Untrusted DataRoundcube Webmail (before 1.5.10/1.6.11)UNK_MassTraction toolset
CVE-2020-22653Ruckus Unauthorized Image Signature InjectionRuckus Wireless DevicesUAT-7810 toolset
CVE-2020-22658Ruckus Unauthorized Image BootRuckus Wireless DevicesUAT-7810 toolset
CVE-2023-25717Ruckus Wireless Products CSRF/RCERuckus Wireless AdminUAT-7810 toolset
CVE-2023-3519NetScaler ADC/Gateway Code InjectionCitrix NetScaler ADC/GatewayINC Ransomware
CVE-2026-56291Balbooa Forms Unrestricted File UploadBalbooa Forms (com_baforms) ≤2.4.0
CVE-2026-56164SharePoint Missing AuthenticationSharePoint Server (multiple editions)
CVE-2026-56155AD FS Insufficient Access-Control GranularityAD FS (Windows 10; Server 2012–2025)
CVE-2026-50661Windows BitLocker Security Feature BypassWindows 10–11 26H1; Server 2016–2025
CVE-2026-15409SonicWall SMA1000 SSRFSonicWall SMA1000 (6210, 7210, 8200v)
CVE-2026-15410SonicWall SMA1000 Code Injectionsame as above
CVE-2023-48788FortiClient EMS SQL InjectionFortinet FortiClientEMS 7.0–7.2INC Ransomware
CVE-2024-57727SimpleHelp Path TraversalSimpleHelp v5.5.7 and beforeINC Ransomware
CVE-2025-5777CitrixBleed 2 (NetScaler Gateway OOB Read)NetScaler ADC and GatewayINC Ransomware
CVE-2026-63030wp2shell (WordPress Interpretation Conflict)WordPress Core (before 6.9.5/7.0.2)
CVE-2026-60137wp2shell (WordPress SQL Injection)same as above
CVE-2026-6875ServiceNow AI Platform RCEServiceNow AI Platform
CVE-2026-16232Check Point SmartConsole Improper AuthenticationCheck Point Security/Multi-Domain Mgmt Server
CVE-2026-0257PAN-OS Authentication BypassPalo Alto Networks PAN-OS / Prisma AccessQilin Ransomware
CVE-2026-16812Arista VeloCloud Orchestrator Command InjectionArista VCO On-Prem
CVE-2026-12569PTC Windchill/FlexPLM Improper Input ValidationPTC Windchill/FlexPLM
CVE-2026-16723Alibaba FastJson RCEAlibaba FastJson 1.x (1.2.68–1.2.83)
CVE-2026-42897Exchange Server XSSMicrosoft Exchange ServerTA488, OWAReaper
CVE-2026-20316Cisco Secure FMC Hard-coded PasswordCisco Secure FMC

Spotlight: CVE-2026-42897 (Exchange, CWE-79) let TA488 deploy OWAReaper from a single opened email — patch here. CVE-2025-49113 (Roundcube, CWE-502) gave UNK_MassTraction code execution against university research departments.


Attacks Executed

33 attacks spanned botnets, ransomware, backdoors, stealers, and RATs.

Attack NameTypeCVEsImpacted ProductDelivery Method
RustDuckBotnetCVE-2025-29635, CVE-2017-17215, CVE-2018-8007, CVE-2024-1781Huawei HG532, D-Link DIR-823X, Totolink X6000R, Apache CouchDB, and other IoT/web devicesWeak Telnet/SSH credentials; known vulnerabilities
Veil#DropFrameworkWindowsPhishing
PureLog StealerInfostealerWindowsPhishing
OusabanBanking TrojanWindowsPhishing
JADEPUFFERRansomwareCVE-2025-3248, CVE-2021-29441Langflow, Alibaba Nacos, MySQL, MinIOExploiting Vulnerability
VShellBackdoorCVE-2024-42009, CVE-2025-49113Roundcube WebmailExploit + Phishing
IceCubeStealersame as VShellRoundcube WebmailExploit + Phishing
SquareShellWebshellsame as VShellRoundcube WebmailExploit + Phishing
SNOWLIGHTLoadersame as VShellRoundcube WebmailExploit + Phishing
SHORTLEASHBackdoorCVE-2020-22653, CVE-2020-22658, CVE-2023-25717Ruckus wireless routersExploit + Phishing
LONGLEASHBackdoorsame as SHORTLEASHRuckus wireless routersExploit + Phishing
DOGLEASHBackdoorsame as SHORTLEASHRuckus wireless routersExploit + Phishing
LEASHTESTLinux binarysame as SHORTLEASHRuckus wireless routersExploit + Phishing
JARLEASHBackdoorsame as SHORTLEASHRuckus wireless routersExploit + Phishing
AsyncRATRATSocial Engineering
CavernModular FrameworkWindowsSupply Chain Compromise
GigaWiperBackdoorMicrosoft Windows
CrashStealerInfostealermacOS
LabubaRATRATMicrosoft Windows
TELEPUZModular malwareChromium-based browsers, Mozilla FirefoxClickFix
INC RansomwareRansomwareCVE-2023-3519, CVE-2023-48788, CVE-2024-57727, CVE-2025-5777Citrix NetScaler ADC/Gateway, Fortinet FortiClientEMS, SimpleHelpExploiting Vulnerabilities
SpiralsRansomwareWindowsASP.NET web shell on internet-facing IIS
HOLLOWGRAPHBackdoorWindowsMicrosoft 365 mailbox calendar
HelloInjectorLoaderViPNet Update SystemDLL Sideloading
HelloProxyLoadersame as aboveIn-memory injection (via HelloInjector)
HelloExecutorBackdoorsame as aboveIn-memory execution (via HelloProxy)
HelloCleanerWipersame as abovesame as HelloExecutor
HelloBackdoorBackdoorsame as abovesame as HelloExecutor
SmartLoaderLoaderWindowsSocial Engineering
StealCInformation StealerWindowsSocial Engineering
Qilin RansomwareRansomwareCVE-2026-0257Palo Alto Networks PAN-OS / Prisma AccessSocial Engineering
OWAReaperBackdoorCVE-2026-42897Microsoft Exchange ServerExploiting Vulnerability
TenguBotnetLinux, AndroidTelnet credential brute force
OWAReaper

TA488's backdoor via CVE-2026-42897, running inside the OWA reading pane to harvest and persist stolen credentials in browser localStorage.

Also tracked (table above): RustDuck, Veil#Drop, PureLog Stealer, Ousaban, JADEPUFFER, the Roundcube and Ruckus toolsets, AsyncRAT, Cavern, GigaWiper, CrashStealer, LabubaRAT, TELEPUZ, Spirals, HOLLOWGRAPH, the HelloNet chain, SmartLoader, StealC, Tengu, Qilin Ransomware, and INC Ransomware.


Adversaries in Action

ActorOriginNotable Activity
UNK_MassTractionChina-alignedEspionage cluster targeting universities via Roundcube flaws CVE-2024-42009/CVE-2025-49113 to deploy VShell, IceCube, SquareShell, SNOWLIGHT
UAT-7810China-alignedExploits Ruckus flaws CVE-2020-22653, CVE-2020-22658, CVE-2023-25717 to deploy SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST, JARLEASH
Cavern Manticore (Cav3rn)Iran (MOIS)Stealthy espionage against Israel's government, defense, and IT-services sectors via the Cavern .NET C2 framework
APT41 (Winnti, Brass Typhoon, TA415)ChinaFinancial crime, information theft, and espionage; disciplined tradecraft
Coinbase Cartel (shinysp1d3r)Financially motivated100 victims via data theft and extortion, no encryption
TA488 (Void Blizzard, Laundry Bear)RussiaBooby-trapped emails exploiting CVE-2026-42897 to deploy OWAReaper against Exchange Server

Per-actor MITRE ATT&CK mappings are available via Uni5Xposure.


Targeted Products

Exploited products spanned mail/collaboration servers, IAM, operating systems, network devices, applications/databases, and security appliances — full detail is in the table above.


Targeted Countries

United States, Canada, Spain, Malta, and Bulgaria were most targeted, followed by United Kingdom, Slovakia, Czech Republic, and Taiwan; Guadeloupe, Panama, Guam, and Qatar were least targeted, across 193 countries worldwide. Full breakdown: Uni5Xposure.


Top MITRE ATT&CK TTPs

223 distinct TTPs were tracked in July; the 6 most prevalent are below.

TTPTacticTechnique
T1059ExecutionCommand and Scripting Interpreter
T1190Initial AccessExploit Public-Facing Application
T1071Command and ControlApplication Layer Protocol
T1588Resource DevelopmentObtain Capabilities
T1041ExfiltrationExfiltration Over C2 Channel
T1566Initial AccessPhishing

The complete ATT&CK matrix is available to Uni5 customers via Uni5Xposure.


Top Indicators of Compromise (IOCs)

Curated highlights; full IOC sets are on Uni5Xposure.

Attack NameTypeValue
RustDuckSHA256a5d1b65b1055677156cd87b357ef488704115a2cbf52044dbb041072efed2f9d
OWAReaperSHA2566897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4
OWAReaperDomainasecdns[.]com
AsyncRATSHA256601d9deea6467a57e42c355d481331cd78d6487bd160a081332420c69f214455
INC RansomwareSHA25631800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502

Recommendations

Security Teams

Prioritize the 35 vulnerabilities; block indicators tied to the 6 actors and 33 malware covered here.

Uni5 Users

Uni5 customers can act on this digest directly via the dashboard.

01

Run a Scan

Discover assets impacted by this month's 35 vulnerabilities.

02

Test Security Controls

Simulate tracked actors, malware, and TTPs in BAS.


Appendix

KEV: CISA's catalog of publicly exploited flaws. Celebrity Vulnerabilities: high-impact flaws with catchy names. Glossary: CVE – Common Vulnerabilities and Exposures; CPE – Common Platform Enumeration; CWE – Common Weakness Enumeration.


What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.