
July's digest was dominated by thirteen actively exploited zero-days. TA488 hit the US and Europe via a Microsoft Exchange flaw (CVE-2026-42897) deploying OWAReaper, while UNK_MassTraction exploited Roundcube's CVE-2025-49113 against university research departments. Arista patched CVE-2026-16812 in VeloCloud Orchestrator, attackers chained SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) for root-level access, and Cavern Manticore ran stealthy espionage against Israel.
Monthly Highlights
CVE-2026-20316 turns built-in credentials into an actively exploited zero-day.CVE-2026-42897 turns a glance at Outlook Web Access into the disk-free OWAReaper backdoor.Zero-Day Spotlight
Five vulnerabilities earned "celebrity" status in July: Bad Epoll, RoguePlanet, CitrixBleed 2, and wp2shell.
CVE-2026-46242 Bad Epoll: Linux kernel use-after-free (CWE-416), fixed in 6.18.33/7.0.10/7.1. CVE-2026-63030 & CVE-2026-60137 wp2shell: WordPress Core interpretation-conflict chained with SQL injection, an unauthenticated takeover of its ~500 million sites. Also branded: CVE-2026-50656 RoguePlanet (Defender privilege escalation, in Qilin's arsenal) and CVE-2025-5777 CitrixBleed 2 (NetScaler OOB read, used by INC ransomware).
Exploitation
35 vulnerabilities were actively exploited in July, each a Zero-Day or Celebrity Vulnerability in the CISA KEV catalog.
| CVE ID | Name | Affected Product | Associated Actors |
|---|---|---|---|
CVE-2025-29635 | D-Link DIR-823X Command Injection | D-Link DIR-823X 240126/240802 | RustDuck |
CVE-2017-17215 | Huawei HG532 RCE | Huawei HG532 | RustDuck |
CVE-2018-8007 | Apache CouchDB Privilege Escalation | Apache CouchDB ≤1.7.1 | RustDuck |
CVE-2024-1781 | Totolink Command Injection | TOTOLINK X6000R AX3000 | RustDuck |
CVE-2026-45659 | SharePoint Deserialization of Untrusted Data | SharePoint Server (multiple editions) | — |
CVE-2025-3248 | Langflow Missing Authentication | Langflow before 1.3.0 | JADEPUFFER |
CVE-2021-29441 | Nacos AuthFilter Auth Bypass by Spoofing | Alibaba Nacos before 1.4.1 | JADEPUFFER |
CVE-2026-46242 | Bad Epoll (Linux Kernel Use After Free) | Linux Kernel | — |
CVE-2026-48282 | Adobe ColdFusion Path Traversal | Adobe ColdFusion 2025.9/2023.20 & earlier | — |
CVE-2024-42009 | Roundcube Webmail XSS | Roundcube Webmail | UNK_MassTraction toolset |
CVE-2025-49113 | Roundcube Deserialization of Untrusted Data | Roundcube Webmail (before 1.5.10/1.6.11) | UNK_MassTraction toolset |
CVE-2020-22653 | Ruckus Unauthorized Image Signature Injection | Ruckus Wireless Devices | UAT-7810 toolset |
CVE-2020-22658 | Ruckus Unauthorized Image Boot | Ruckus Wireless Devices | UAT-7810 toolset |
CVE-2023-25717 | Ruckus Wireless Products CSRF/RCE | Ruckus Wireless Admin | UAT-7810 toolset |
CVE-2023-3519 | NetScaler ADC/Gateway Code Injection | Citrix NetScaler ADC/Gateway | INC Ransomware |
CVE-2026-56291 | Balbooa Forms Unrestricted File Upload | Balbooa Forms (com_baforms) ≤2.4.0 | — |
CVE-2026-56164 | SharePoint Missing Authentication | SharePoint Server (multiple editions) | — |
CVE-2026-56155 | AD FS Insufficient Access-Control Granularity | AD FS (Windows 10; Server 2012–2025) | — |
CVE-2026-50661 | Windows BitLocker Security Feature Bypass | Windows 10–11 26H1; Server 2016–2025 | — |
CVE-2026-15409 | SonicWall SMA1000 SSRF | SonicWall SMA1000 (6210, 7210, 8200v) | — |
CVE-2026-15410 | SonicWall SMA1000 Code Injection | same as above | — |
CVE-2023-48788 | FortiClient EMS SQL Injection | Fortinet FortiClientEMS 7.0–7.2 | INC Ransomware |
CVE-2024-57727 | SimpleHelp Path Traversal | SimpleHelp v5.5.7 and before | INC Ransomware |
CVE-2025-5777 | CitrixBleed 2 (NetScaler Gateway OOB Read) | NetScaler ADC and Gateway | INC Ransomware |
CVE-2026-63030 | wp2shell (WordPress Interpretation Conflict) | WordPress Core (before 6.9.5/7.0.2) | — |
CVE-2026-60137 | wp2shell (WordPress SQL Injection) | same as above | — |
CVE-2026-6875 | ServiceNow AI Platform RCE | ServiceNow AI Platform | — |
CVE-2026-16232 | Check Point SmartConsole Improper Authentication | Check Point Security/Multi-Domain Mgmt Server | — |
CVE-2026-0257 | PAN-OS Authentication Bypass | Palo Alto Networks PAN-OS / Prisma Access | Qilin Ransomware |
CVE-2026-16812 | Arista VeloCloud Orchestrator Command Injection | Arista VCO On-Prem | — |
CVE-2026-12569 | PTC Windchill/FlexPLM Improper Input Validation | PTC Windchill/FlexPLM | — |
CVE-2026-16723 | Alibaba FastJson RCE | Alibaba FastJson 1.x (1.2.68–1.2.83) | — |
CVE-2026-42897 | Exchange Server XSS | Microsoft Exchange Server | TA488, OWAReaper |
CVE-2026-20316 | Cisco Secure FMC Hard-coded Password | Cisco Secure FMC | — |
Spotlight: CVE-2026-42897 (Exchange, CWE-79) let TA488 deploy OWAReaper from a single opened email — patch here. CVE-2025-49113 (Roundcube, CWE-502) gave UNK_MassTraction code execution against university research departments.
Malware & Campaigns
33 attacks spanned botnets, ransomware, backdoors, stealers, and RATs.
| Attack Name | Type | CVEs | Impacted Product | Delivery Method |
|---|---|---|---|---|
| RustDuck | Botnet | CVE-2025-29635, CVE-2017-17215, CVE-2018-8007, CVE-2024-1781 | Huawei HG532, D-Link DIR-823X, Totolink X6000R, Apache CouchDB, and other IoT/web devices | Weak Telnet/SSH credentials; known vulnerabilities |
| Veil#Drop | Framework | — | Windows | Phishing |
| PureLog Stealer | Infostealer | — | Windows | Phishing |
| Ousaban | Banking Trojan | — | Windows | Phishing |
| JADEPUFFER | Ransomware | CVE-2025-3248, CVE-2021-29441 | Langflow, Alibaba Nacos, MySQL, MinIO | Exploiting Vulnerability |
| VShell | Backdoor | CVE-2024-42009, CVE-2025-49113 | Roundcube Webmail | Exploit + Phishing |
| IceCube | Stealer | same as VShell | Roundcube Webmail | Exploit + Phishing |
| SquareShell | Webshell | same as VShell | Roundcube Webmail | Exploit + Phishing |
| SNOWLIGHT | Loader | same as VShell | Roundcube Webmail | Exploit + Phishing |
| SHORTLEASH | Backdoor | CVE-2020-22653, CVE-2020-22658, CVE-2023-25717 | Ruckus wireless routers | Exploit + Phishing |
| LONGLEASH | Backdoor | same as SHORTLEASH | Ruckus wireless routers | Exploit + Phishing |
| DOGLEASH | Backdoor | same as SHORTLEASH | Ruckus wireless routers | Exploit + Phishing |
| LEASHTEST | Linux binary | same as SHORTLEASH | Ruckus wireless routers | Exploit + Phishing |
| JARLEASH | Backdoor | same as SHORTLEASH | Ruckus wireless routers | Exploit + Phishing |
| AsyncRAT | RAT | — | — | Social Engineering |
| Cavern | Modular Framework | — | Windows | Supply Chain Compromise |
| GigaWiper | Backdoor | — | Microsoft Windows | — |
| CrashStealer | Infostealer | — | macOS | — |
| LabubaRAT | RAT | — | Microsoft Windows | — |
| TELEPUZ | Modular malware | — | Chromium-based browsers, Mozilla Firefox | ClickFix |
| INC Ransomware | Ransomware | CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, CVE-2025-5777 | Citrix NetScaler ADC/Gateway, Fortinet FortiClientEMS, SimpleHelp | Exploiting Vulnerabilities |
| Spirals | Ransomware | — | Windows | ASP.NET web shell on internet-facing IIS |
| HOLLOWGRAPH | Backdoor | — | Windows | Microsoft 365 mailbox calendar |
| HelloInjector | Loader | — | ViPNet Update System | DLL Sideloading |
| HelloProxy | Loader | — | same as above | In-memory injection (via HelloInjector) |
| HelloExecutor | Backdoor | — | same as above | In-memory execution (via HelloProxy) |
| HelloCleaner | Wiper | — | same as above | same as HelloExecutor |
| HelloBackdoor | Backdoor | — | same as above | same as HelloExecutor |
| SmartLoader | Loader | — | Windows | Social Engineering |
| StealC | Information Stealer | — | Windows | Social Engineering |
| Qilin Ransomware | Ransomware | CVE-2026-0257 | Palo Alto Networks PAN-OS / Prisma Access | Social Engineering |
| OWAReaper | Backdoor | CVE-2026-42897 | Microsoft Exchange Server | Exploiting Vulnerability |
| Tengu | Botnet | — | Linux, Android | Telnet credential brute force |
TA488's backdoor via CVE-2026-42897, running inside the OWA reading pane to harvest and persist stolen credentials in browser localStorage.
Also tracked (table above): RustDuck, Veil#Drop, PureLog Stealer, Ousaban, JADEPUFFER, the Roundcube and Ruckus toolsets, AsyncRAT, Cavern, GigaWiper, CrashStealer, LabubaRAT, TELEPUZ, Spirals, HOLLOWGRAPH, the HelloNet chain, SmartLoader, StealC, Tengu, Qilin Ransomware, and INC Ransomware.
Threat Actors
| Actor | Origin | Notable Activity |
|---|---|---|
| UNK_MassTraction | China-aligned | Espionage cluster targeting universities via Roundcube flaws CVE-2024-42009/CVE-2025-49113 to deploy VShell, IceCube, SquareShell, SNOWLIGHT |
| UAT-7810 | China-aligned | Exploits Ruckus flaws CVE-2020-22653, CVE-2020-22658, CVE-2023-25717 to deploy SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST, JARLEASH |
| Cavern Manticore (Cav3rn) | Iran (MOIS) | Stealthy espionage against Israel's government, defense, and IT-services sectors via the Cavern .NET C2 framework |
| APT41 (Winnti, Brass Typhoon, TA415) | China | Financial crime, information theft, and espionage; disciplined tradecraft |
| Coinbase Cartel (shinysp1d3r) | Financially motivated | 100 victims via data theft and extortion, no encryption |
| TA488 (Void Blizzard, Laundry Bear) | Russia | Booby-trapped emails exploiting CVE-2026-42897 to deploy OWAReaper against Exchange Server |
Per-actor MITRE ATT&CK mappings are available via Uni5Xposure.
Exposure
Exploited products spanned mail/collaboration servers, IAM, operating systems, network devices, applications/databases, and security appliances — full detail is in the table above.
Geography
United States, Canada, Spain, Malta, and Bulgaria were most targeted, followed by United Kingdom, Slovakia, Czech Republic, and Taiwan; Guadeloupe, Panama, Guam, and Qatar were least targeted, across 193 countries worldwide. Full breakdown: Uni5Xposure.
Adversary Tradecraft
223 distinct TTPs were tracked in July; the 6 most prevalent are below.
| TTP | Tactic | Technique |
|---|---|---|
T1059 | Execution | Command and Scripting Interpreter |
T1190 | Initial Access | Exploit Public-Facing Application |
T1071 | Command and Control | Application Layer Protocol |
T1588 | Resource Development | Obtain Capabilities |
T1041 | Exfiltration | Exfiltration Over C2 Channel |
T1566 | Initial Access | Phishing |
The complete ATT&CK matrix is available to Uni5 customers via Uni5Xposure.
Indicators
Curated highlights; full IOC sets are on Uni5Xposure.
| Attack Name | Type | Value |
|---|---|---|
| RustDuck | SHA256 | a5d1b65b1055677156cd87b357ef488704115a2cbf52044dbb041072efed2f9d |
| OWAReaper | SHA256 | 6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4 |
| OWAReaper | Domain | asecdns[.]com |
| AsyncRAT | SHA256 | 601d9deea6467a57e42c355d481331cd78d6487bd160a081332420c69f214455 |
| INC Ransomware | SHA256 | 31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502 |
Guidance
Prioritize the 35 vulnerabilities; block indicators tied to the 6 actors and 33 malware covered here.
Uni5 customers can act on this digest directly via the dashboard.
01Run a Scan
Discover assets impacted by this month's 35 vulnerabilities.
02Test Security Controls
Simulate tracked actors, malware, and TTPs in BAS.
Definitions & Glossary
KEV: CISA's catalog of publicly exploited flaws. Celebrity Vulnerabilities: high-impact flaws with catchy names. Glossary: CVE – Common Vulnerabilities and Exposures; CPE – Common Platform Enumeration; CWE – Common Weakness Enumeration.
Next Steps
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.