Monthly Threat Digest: Vulnerabilities, Attacks, and Actors — September 2026
September reshaped the cybersecurity landscape, with 20 zero-day vulnerabilities actively exploited, ShinyHunters renewing mass exploitation of Oracle PeopleSoft CVE-2026-35273, the BlueMoon Chrome V8 exploit chain around CVE-2026-87491, and Storm-3069 deploying the NeedyMantis backdoor.
Summary
September reshaped the cybersecurity landscape, with 20 zero-day vulnerabilities actively exploited. One of the most notable threats came from ShinyHunters (UNC6240), which renewed its mass exploitation of a critical Oracle PeopleSoft PeopleTools flaw, CVE-2026-35273. The attackers bypass WAF rules by URL-encoding a single character in the PSEMHUB path, letting them reach systems that were never patched. Once inside, they deploy web shells, the SIDEEYE backdoor, Neo-reGeorg tunnels, and MeshAgent. Victims span higher education, healthcare, government, and other sectors worldwide, and the goal is data theft and extortion. Organizations should patch immediately and should not rely on WAF rules alone.
Additionally, Google patched CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine used by Chrome and other Chromium-based browsers. The fix reached the Chromium source tree weeks before the stable Chrome release, which gave attackers a patch-gap window to weaponize the flaw. The attacks are tied to a shared exploit kit called BlueMoon, which chains this flaw with a second V8 flaw (CVE-2026-85046) and a Windows kernel privilege escalation flaw (CVE-2026-85880) to compromise a computer with a single click. BlueMoon was first seen on August 28, 2026, and was used by multiple China-aligned actors. The attacks have delivered the GRIMWEDGE JScript backdoor, the SUPERSTOMP loader, the ShadowPad backdoor, and Rust-based loaders.
Moreover, NeedyMantis is a modular backdoor used by the China-based actor Storm-3069 to keep long-term access to networks it has already breached. Its targets include telecommunications, education, healthcare, nonprofit, and government organizations. It is delivered through DLL sideloading inside bundles of legitimate software such as Poedit, curl, Vim, and TightVNC. With risks like these growing, strong defensive measures are more important than ever.
Insights
ShinyHunters is running a renewed mass campaign, so attackers are scanning for unpatched PeopleTools systems right now (CVE-2026-35273).
NetScaler handles VPN, remote access, load balancing, and authentication, so CVE-2026-88771 or CVE-2026-88772 hands an attacker the keys to the perimeter.
NeedyMantis is how Storm-3069 signs a long-term lease, so the real risk is how long it stays, not how it got in.
CVE-2026-86950 lives in CoreGraphics, the part of Apple's software that draws images and documents, so almost everything on an iPhone, iPad, or Mac touches it.
PAYLOAD ransomware skipped the encryptor entirely in one intrusion, so a ransomware defense built only to catch encryption would have seen nothing.
CVE-2026-87491 is the seventh Chrome zero-day of 2026 exploited in the wild, so Chrome emergency updates are becoming routine.
StyleSmuggler (CVE-2026-75650) scores a perfect CVSS 10.0, so this is about as bad as a vulnerability gets.
Mirage Kitten is using fake recruiters to deliver NodeRabbit and PollCat, so the job offer in your inbox may be the attack.
Threat distribution
Celebrity Vulnerabilities
CVE-2026-75650 · StyleSmuggler
Adobe Commerce and Magento Open Source Remote Code Execution Vulnerability
- Status
- Zero-day
- Affected product
- Adobe Commerce and Magento Open Source 2.4.4 - 2.4.9 (2026-aug and earlier), Adobe Commerce on Cloud, Adobe Commerce B2B 1.3.3 - 1.5.3
- CWE ID
CWE-1336- Patch link
https://helpx.adobe.com/security/products/magento/apsb26-146.html
CVE-2026-6471 · PostGREShell
PostgreSQL Output Plugin Missing Authorization Vulnerability
- Status
- Zero-day
- Affected product
- PostgreSQL core server before 18.6, 17.11, 16.15, 15.19, and 14.24
- CWE ID
CWE-862- Patch link
https://www.postgresql.org/support/security/CVE-2026-6471/
CVE-2026-69414 · ShieldBreak
Microsoft Defender Elevation of Privilege Vulnerability
- Status
- Zero-day
- Affected product
- Microsoft Malware Protection Engine
- CWE ID
CWE-269, CWE-284- Patch link
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
Vulnerability Details: Vulnerabilities Summary
| CVE ID | Name |
|---|---|
CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function |
CVE-2026-72530 | TrueConf Server Code Injection |
CVE-2026-82078 | PaperCut NG and PaperCut MF Unsafe Dynamic Class Loading |
CVE-2026-81578 | PaperCut NG and PaperCut MF Authentication Bypass |
CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery |
CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection |
CVE-2026-32475 | WordPress Elementor Pro Unauthenticated Arbitrary File Upload |
CVE-2026-85046 | Google Chrome V8 Type Confusion |
CVE-2026-75650 | Adobe Commerce and Magento Open Source Remote Code Execution (StyleSmuggler) |
CVE-2026-6471 | PostgreSQL Output Plugin Missing Authorization (PostGREShell) |
CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow |
CVE-2026-81963 | Microsoft Windows Link Following |
CVE-2026-69414 | Microsoft Defender Elevation of Privilege (ShieldBreak) |
CVE-2026-86218 | N-able N-central Static Code Injection |
CVE-2026-87491 | Google Chromium V8 Out of Bounds Write |
CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal |
CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection |
CVE-2026-87886 | Acronis Backup Incorrect Default Permissions |
CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization |
CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs |
CVE-2026-42016 | JFrog Artifactory Incorrect Authorization |
CVE-2026-42018 | JFrog Artifactory Improper Authentication |
CVE-2026-82329 | JFrog Artifactory Improper Authentication |
CVE-2026-7273 | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow |
CVE-2026-93616 | Check Point Multiple Products Path Traversal |
CVE-2026-85102 | Check Point Multiple Products Improper Certificate Validation |
CVE-2026-94127 | F5 BIG-IP APM Heap-based Buffer Overflow |
CVE-2026-93952 | Arista VeloCloud Orchestrator Improper Input Validation |
CVE-2026-87902 | WordPress Unauthenticated Path Traversal |
CVE-2023-52271 | Topaz Antifraud Improper Access Control |
CVE-2025-61155 | Hotta Studio GameDriverX64 Improper Access Control |
CVE-2025-1055 | K7 Computing K7 Security Anti-Malware Missing Authorization |
CVE-2026-88771 | Citrix NetScaler Improper Input Validation |
CVE-2026-88772 | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer |
CVE-2026-86950 | Apple Multiple Products Out-of-Bounds Write |
CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function |
Attack Details: Attacks Summary
| Attack | Type | CVEs | Delivery method |
|---|---|---|---|
| NodeRabbit | RAT | - | Trojanized coding-challenge archives |
| PollCat | RAT | - | Trojanized React coding challenge |
| Retrograde/MiniFast | Backdoor | - | - |
| COBALTSPIN | Network tunneler | - | - |
| REALBREEZE | Brute-forcing utility | - | Downloaded from GitHub repositories |
| MILDFROST | Backdoor | - | - |
| BOATBEAM | Backdoor | - | - |
| LIGHTPAINT | Backdoor | - | - |
| KICKPLATE | Backdoor | - | - |
| XWORM | RAT | - | Phishing |
| JSCeal | Stealer | - | Malicious Facebook and Google ads |
| PEEP | Toolkit | - | - |
| GRIMWEDGE | Backdoor | CVE-2026-87491 | Phishing |
| SUPERSTOMP | Loader | CVE-2026-87491 | Phishing |
| LONGTALE | Browser extension | CVE-2026-87491 | Phishing |
| ShadowPad | Backdoor | CVE-2026-87491 | Phishing |
| Panzer | Ransomware | - | - |
| AppleSeed (KGH_SPY) | Backdoor | - | Spear-phishing emails |
| HappyDoor | Backdoor | - | Spear-phishing emails |
| HelloDoor | Backdoor | - | Spear-phishing emails |
| httpMalice | Backdoor | - | Spear-phishing emails |
| httpTroy | Backdoor | - | Spear-phishing |
| MemLoad | Loader | - | Spear-phishing attachment |
| HTTPSpy | RAT | - | Spear-phishing attachments |
| AsyncRAT | RAT | - | Spear-phishing |
| StormousX | Ransomware | - | Phishing |
| XMRig | Cryptominer | CVE-2026-84869 | Social engineering |
| PAYLOAD Ransomware | Ransomware | - | Malicious GPO |
| DragonForce Ransomware | Ransomware | CVE-2023-52271, CVE-2025-61155, CVE-2025-1055 | DLL sideloading, BYOVD |
| SIDEEYE | Multi-stage backdoor | CVE-2026-35273 | Trojanized Ple64.exe installer |
| NeedyMantis | Modular backdoor | - | DLL sideloading |
Actor Details: Adversaries Summary
| Actor | Motive | Origin | CVEs | Attacks / malware | Product |
|---|---|---|---|---|---|
| Mirage Kitten | Information theft and espionage | Iran | - | NodeRabbit, PollCat, Retrograde/MiniFast | Windows |
| BREEZE COMET | Financial gain | Brazil | - | COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, LIGHTPAINT, KICKPLATE, XWORM | Windows, Linux, Active Directory, cloud environments, Kubernetes, CI/CD pipelines, Java Virtual Machine (JVM) process space |
| TA412 | Information theft and espionage | China | CVE-2026-87491 | SUPERSTOMP, LONGTALE (aka GemStone) | Google Chrome |
| UTA0560 | Information theft and espionage | China | CVE-2026-87491 | GRIMWEDGE | Google Chrome |
| UNK_LateNight | Information theft and espionage | China | CVE-2026-87491 | ShadowPad | Google Chrome |
| UNK_DoubleCheck | Information theft and espionage | - | CVE-2026-87491 | - | Google Chrome |
| UNK_QuietRacket | Information theft and espionage | China | CVE-2026-87491 | - | Google Chrome |
| Kimsuky | Espionage, financial gains | North Korea | CVE-2017-11882, CVE-2018-0802, CVE-2019-0708, CVE-2019-1405, CVE-2020-0787, CVE-2024-1709, CVE-2025-48703 | AppleSeed (KGH_SPY), AlphaSeed, HappyDoor, PebbleDash, HelloDoor, httpMalice, httpTroy, MemLoad, HTTPSpy, AsyncRAT, BabyShark, GoldDragon, Troll Stealer, QuasarRAT, Gh0st RAT, KimJongRAT and 20 more tracked families | GitHub, Pastebin, Dropbox, Slack, Cloudflare Quick Tunnels, Visual Studio, Microsoft 365, Okta |
| Stormous | Financial gain | - | - | StormousX | - |
| Meowciety403 | Financial gains, information theft | - | - | - | - |
| ShinyHunters | Financial gain | - | CVE-2026-35273 | SIDEEYE | Oracle PeopleSoft |
| Storm-3069 | Information theft, espionage | China | - | NeedyMantis | - |
Targeted Products, Countries and Industries
Targeted products spanned network security appliances (SonicWall SMA 1000, Check Point, F5 BIG-IP APM, Cisco, Citrix NetScaler), Google Chrome, e-commerce and CMS platforms (Adobe Commerce, Magento, WordPress), PostgreSQL, Windows and Apple operating systems, endpoint security drivers (Microsoft Malware Protection Engine, Topaz Antifraud, K7 Security), RMM and remote support tools (N-able N-central, ConnectWise ScreenConnect), DevOps and repository platforms (GitLab, JFrog Artifactory), TrueConf Server, PaperCut, Acronis Backup, Zyxel and Arista infrastructure, and Oracle PeopleSoft PeopleTools 8.61 and 8.62.
Most targeted countries
Activity was also recorded across the United States, Egypt, Singapore, France, Brazil, Thailand, Italy, South Korea, Turkey, Taiwan, Colombia, India, the Philippines, Spain, Portugal, Argentina, Saudi Arabia, China, Greece, Vietnam, Japan, Israel, the United Kingdom, Australia and many additional countries, 195 in total.
Most targeted industries
55 industries were targeted in total, with Agriculture shown as the least targeted.
Top 5 Takeaways
- 01Zero-daysIn September 2026, 20 zero-day vulnerabilities surfaced across products from PaperCut, SonicWall, Google Chrome, Adobe, Microsoft Windows, N-able, Cisco, Check Point, F5, Arista, Citrix, Apple, and Oracle.
- 02New malwareNewly identified malware active in September included a broad mix of backdoors and RATs. Key discoveries were NodeRabbit, PollCat, Retrograde/MiniFast, and SIDEEYE, each representing distinct capabilities ranging from stealthy persistence and credential theft to large-scale compromise.
- 03Top countriesCyberattacks concentrated heavily on Germany, Mexico, the United Arab Emirates, South Africa, and Canada, which absorbed most of the hostile activity. Espionage operations and financially motivated intrusions drove the surge.
- 04Top industriesGovernment, Finance, Education, Technology, and Retail sectors absorbed the bulk of targeted activity, with ransomware operations, data theft, and espionage campaigns driving operational disruption.
- 05Leading actorsActivity during the period was dominated by TA412, UTA0560, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket, ShinyHunters, and Storm-3069, all well-resourced groups known for sustained, high-impact operations.
Recommendations
Security teams: This digest can be used as a guide to help security teams prioritize the 36 significant vulnerabilities and block the indicators related to the 12 active threat actors, 31 active malware, and 209 potential MITRE TTPs.
Uni5 users: This is an actionable threat digest for HivePro Uni5 customers, who can get comprehensive insights into their threat exposure and take action easily through the HivePro Uni5 dashboard by running a scan to discover the assets impacted by the 36 significant vulnerabilities, and testing the efficacy of their security controls by simulating the attacks related to active threat actors, active malware, and potential MITRE TTPs in Breach and Attack Simulation (BAS).
Top Indicators of Compromise (IoCs)
| Attack | Type | Value |
|---|---|---|
| NodeRabbit | Domains | healthcomfsdpower[.]com visitfinancedentists[.]com msmanagementgrp[.]com msmanagementgrpmedia[.]com naturalapplication[.]azurewebsites[.]net retaildemo[.]azurewebsites[.]net tubitak[.]azurewebsites[.]net rgbteller[.]azurewebsites[.]net wslwebui[.]azurewebsites[.]net plugplay[.]azurewebsites[.]net crossdwm[.]azurewebsites[.]net wdisystem[.]azurewebsites[.]net wslmenus[.]azurewebsites[.]net dnshnsdev[.]azurewebsites[.]net hpjumpsrv[.]azurewebsites[.]net storview[.]azurewebsites[.]net kyrasey-f8hfexa5cqamh7fk[.]westeurope-01[.]azurewebsites[.]net greenyjsgfd[.]azurewebsites[.]net helptellerbls[.]azurewebsites[.]net timedrv[.]azurewebsites[.]net userwellgtfs[.]azurewebsites[.]net hecowime-aqdphyd4bbdef6es[.]westeurope-01[.]azurewebsites[.]net |
| NodeRabbit | URL | hxxps[:]//lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate |
| PollCat | Filenames | RankChallenge-react-6uJSX3-main.zip requireObject.js |
| PollCat | Domains | gamebarapp[.]azurewebsites[.]net gamebarappinformation[.]azurewebsites[.]net sahi-finance[.]com lifespotify[.]com |
| Retrograde/MiniFast | MD5 | 810F8E3B88EB05F710C09552941D6F56 |
| Retrograde/MiniFast | SHA256 | 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 |
| GRIMWEDGE | SHA256 | 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc 59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcb |
| GRIMWEDGE | Domain | ocr[.]opusaccel[.]top |
| SUPERSTOMP | SHA256 | e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0 |
| LONGTALE | SHA256 | 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 |
| LONGTALE | URL | hxxps://xyz0102.gitprogram[.]com/a001 |
| LONGTALE | Hostname | extension-management-portal.centerfjdr658.workers[.]dev extension-management-portal.kmjukilo-lkjh.workers[.]dev |
| ShadowPad | Hostname | ms.checrity[.]com |
| ShadowPad | IPv4 | 79[.]133[.]56[.]90 |
| ShadowPad | Domain | checrity[.]com |
| PAYLOAD Ransomware | SHA256 | 1CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F |
| PAYLOAD Ransomware | MD5 | E0FD8FF6D39E4C11BDAF860C35FD8DC0 0108656A3E1ADE6CA4F21B084F5E1208 BEA5E267F24D7DA59F6821BFFDBFF293 |
| PAYLOAD Ransomware | TOR address | payload6eualw6kni6v2lqn7ovjcl76ojx25z5unsyvqo3lbqy3bo5qd[.]onion payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd[.]onion payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion |
| DragonForce Ransomware | SHA256 | e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 a4eb9be98d00c961ad8c3329ee80690c1eec98d4c8fa8dd91c371d9ecc451581 |
| DragonForce Ransomware | SHA1 | 55acb53f348c9f6b89343dc8d96522aa75e4cfdb |
| DragonForce Ransomware | MD5 | bd47ae24b03e5ba0f1ab2e95e7acb989 |
| DragonForce Ransomware | File path | C:\Users\Public\log.log |
| DragonForce Ransomware | TOR address | 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd[.]onion z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid[.]onion |
| DragonForce Ransomware | TOX ID | 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20 |
| SIDEEYE | SHA256 | 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 |
| SIDEEYE | IPv4 | 162[.]219[.]30[.]165 |
| NeedyMantis | SHA256 | e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77 |
A comprehensive list of IOCs for all tracked attacks is available on the Uni5Xposure platform.
Top MITRE ATT&CK TTPs
209 MITRE ATT&CK techniques were observed across the month; the 25 most frequent are listed above.
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
