Monthly Threat Digest : SEPTEMBER 2026

Monthly Threat Digest
Download Now
Monthly Threat Digest September 2026 | Hive Pro Threat Advisory
Monthly Threat Digest/September 2026

Monthly Threat Digest: Vulnerabilities, Attacks, and Actors — September 2026

September reshaped the cybersecurity landscape, with 20 zero-day vulnerabilities actively exploited, ShinyHunters renewing mass exploitation of Oracle PeopleSoft CVE-2026-35273, the BlueMoon Chrome V8 exploit chain around CVE-2026-87491, and Storm-3069 deploying the NeedyMantis backdoor.

Monthly digestSeptember 202636 vulnerabilities31 attacks12 adversaries209 MITRE TTPs
Published
October 1, 2026
Report type
Monthly digest
Total CVEs
524.1K
Published (month)
14,719
Exploited
36
Attacks
31
Adversaries
12
MITRE TTPs
209
Industries
55
Countries
195

01 / Overview

Summary

September reshaped the cybersecurity landscape, with 20 zero-day vulnerabilities actively exploited. One of the most notable threats came from ShinyHunters (UNC6240), which renewed its mass exploitation of a critical Oracle PeopleSoft PeopleTools flaw, CVE-2026-35273. The attackers bypass WAF rules by URL-encoding a single character in the PSEMHUB path, letting them reach systems that were never patched. Once inside, they deploy web shells, the SIDEEYE backdoor, Neo-reGeorg tunnels, and MeshAgent. Victims span higher education, healthcare, government, and other sectors worldwide, and the goal is data theft and extortion. Organizations should patch immediately and should not rely on WAF rules alone.

Additionally, Google patched CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine used by Chrome and other Chromium-based browsers. The fix reached the Chromium source tree weeks before the stable Chrome release, which gave attackers a patch-gap window to weaponize the flaw. The attacks are tied to a shared exploit kit called BlueMoon, which chains this flaw with a second V8 flaw (CVE-2026-85046) and a Windows kernel privilege escalation flaw (CVE-2026-85880) to compromise a computer with a single click. BlueMoon was first seen on August 28, 2026, and was used by multiple China-aligned actors. The attacks have delivered the GRIMWEDGE JScript backdoor, the SUPERSTOMP loader, the ShadowPad backdoor, and Rust-based loaders.

Moreover, NeedyMantis is a modular backdoor used by the China-based actor Storm-3069 to keep long-term access to networks it has already breached. Its targets include telecommunications, education, healthcare, nonprofit, and government organizations. It is delivered through DLL sideloading inside bundles of legitimate software such as Poedit, curl, Vim, and TightVNC. With risks like these growing, strong defensive measures are more important than ever.

524.1K
Total vulnerabilities published
14,719
Published in the month
36
Exploited vulnerabilities

02 / Highlights

Insights

ShinyHunters is running a renewed mass campaign, so attackers are scanning for unpatched PeopleTools systems right now (CVE-2026-35273).

NetScaler handles VPN, remote access, load balancing, and authentication, so CVE-2026-88771 or CVE-2026-88772 hands an attacker the keys to the perimeter.

NeedyMantis is how Storm-3069 signs a long-term lease, so the real risk is how long it stays, not how it got in.

CVE-2026-86950 lives in CoreGraphics, the part of Apple's software that draws images and documents, so almost everything on an iPhone, iPad, or Mac touches it.

PAYLOAD ransomware skipped the encryptor entirely in one intrusion, so a ransomware defense built only to catch encryption would have seen nothing.

CVE-2026-87491 is the seventh Chrome zero-day of 2026 exploited in the wild, so Chrome emergency updates are becoming routine.

StyleSmuggler (CVE-2026-75650) scores a perfect CVSS 10.0, so this is about as bad as a vulnerability gets.

Mirage Kitten is using fake recruiters to deliver NodeRabbit and PollCat, so the job offer in your inbox may be the attack.

Threat distribution
Malware AttacksSocial EngineeringDenial-of-Service AttackInjection AttacksPassword Attack

03 / Celebrity

Celebrity Vulnerabilities

CVE-2026-75650 · StyleSmuggler

Adobe Commerce and Magento Open Source Remote Code Execution Vulnerability

Status
Zero-day
Affected product
Adobe Commerce and Magento Open Source 2.4.4 - 2.4.9 (2026-aug and earlier), Adobe Commerce on Cloud, Adobe Commerce B2B 1.3.3 - 1.5.3
CWE ID
CWE-1336
Patch link
https://helpx.adobe.com/security/products/magento/apsb26-146.html
CVE-2026-6471 · PostGREShell

PostgreSQL Output Plugin Missing Authorization Vulnerability

Status
Zero-day
Affected product
PostgreSQL core server before 18.6, 17.11, 16.15, 15.19, and 14.24
CWE ID
CWE-862
Patch link
https://www.postgresql.org/support/security/CVE-2026-6471/
CVE-2026-69414 · ShieldBreak

Microsoft Defender Elevation of Privilege Vulnerability

Status
Zero-day
Affected product
Microsoft Malware Protection Engine
CWE ID
CWE-269, CWE-284
Patch link
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414

04 / Vulnerabilities

Vulnerability Details: Vulnerabilities Summary

CVE IDName
CVE-2026-72529TrueConf Server Missing Authentication for Critical Function
CVE-2026-72530TrueConf Server Code Injection
CVE-2026-82078PaperCut NG and PaperCut MF Unsafe Dynamic Class Loading
CVE-2026-81578PaperCut NG and PaperCut MF Authentication Bypass
CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery
CVE-2026-83549SonicWall SMA1000 Appliances OS Command Injection
CVE-2026-32475WordPress Elementor Pro Unauthenticated Arbitrary File Upload
CVE-2026-85046Google Chrome V8 Type Confusion
CVE-2026-75650Adobe Commerce and Magento Open Source Remote Code Execution (StyleSmuggler)
CVE-2026-6471PostgreSQL Output Plugin Missing Authorization (PostGREShell)
CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow
CVE-2026-81963Microsoft Windows Link Following
CVE-2026-69414Microsoft Defender Elevation of Privilege (ShieldBreak)
CVE-2026-86218N-able N-central Static Code Injection
CVE-2026-87491Google Chromium V8 Out of Bounds Write
CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal
CVE-2026-76461Cisco Secure Email Gateway SQL Injection
CVE-2026-87886Acronis Backup Incorrect Default Permissions
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization
CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs
CVE-2026-42016JFrog Artifactory Incorrect Authorization
CVE-2026-42018JFrog Artifactory Improper Authentication
CVE-2026-82329JFrog Artifactory Improper Authentication
CVE-2026-7273Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
CVE-2026-93616Check Point Multiple Products Path Traversal
CVE-2026-85102Check Point Multiple Products Improper Certificate Validation
CVE-2026-94127F5 BIG-IP APM Heap-based Buffer Overflow
CVE-2026-93952Arista VeloCloud Orchestrator Improper Input Validation
CVE-2026-87902WordPress Unauthenticated Path Traversal
CVE-2023-52271Topaz Antifraud Improper Access Control
CVE-2025-61155Hotta Studio GameDriverX64 Improper Access Control
CVE-2025-1055K7 Computing K7 Security Anti-Malware Missing Authorization
CVE-2026-88771Citrix NetScaler Improper Input Validation
CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2026-86950Apple Multiple Products Out-of-Bounds Write
CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function

05 / Attacks

Attack Details: Attacks Summary

AttackTypeCVEsDelivery method
NodeRabbitRAT-Trojanized coding-challenge archives
PollCatRAT-Trojanized React coding challenge
Retrograde/MiniFastBackdoor--
COBALTSPINNetwork tunneler--
REALBREEZEBrute-forcing utility-Downloaded from GitHub repositories
MILDFROSTBackdoor--
BOATBEAMBackdoor--
LIGHTPAINTBackdoor--
KICKPLATEBackdoor--
XWORMRAT-Phishing
JSCealStealer-Malicious Facebook and Google ads
PEEPToolkit--
GRIMWEDGEBackdoorCVE-2026-87491Phishing
SUPERSTOMPLoaderCVE-2026-87491Phishing
LONGTALEBrowser extensionCVE-2026-87491Phishing
ShadowPadBackdoorCVE-2026-87491Phishing
PanzerRansomware--
AppleSeed (KGH_SPY)Backdoor-Spear-phishing emails
HappyDoorBackdoor-Spear-phishing emails
HelloDoorBackdoor-Spear-phishing emails
httpMaliceBackdoor-Spear-phishing emails
httpTroyBackdoor-Spear-phishing
MemLoadLoader-Spear-phishing attachment
HTTPSpyRAT-Spear-phishing attachments
AsyncRATRAT-Spear-phishing
StormousXRansomware-Phishing
XMRigCryptominerCVE-2026-84869Social engineering
PAYLOAD RansomwareRansomware-Malicious GPO
DragonForce RansomwareRansomwareCVE-2023-52271, CVE-2025-61155, CVE-2025-1055DLL sideloading, BYOVD
SIDEEYEMulti-stage backdoorCVE-2026-35273Trojanized Ple64.exe installer
NeedyMantisModular backdoor-DLL sideloading

06 / Adversaries

Actor Details: Adversaries Summary

ActorMotiveOriginCVEsAttacks / malwareProduct
Mirage KittenInformation theft and espionageIran-NodeRabbit, PollCat, Retrograde/MiniFastWindows
BREEZE COMETFinancial gainBrazil-COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, LIGHTPAINT, KICKPLATE, XWORMWindows, Linux, Active Directory, cloud environments, Kubernetes, CI/CD pipelines, Java Virtual Machine (JVM) process space
TA412Information theft and espionageChinaCVE-2026-87491SUPERSTOMP, LONGTALE (aka GemStone)Google Chrome
UTA0560Information theft and espionageChinaCVE-2026-87491GRIMWEDGEGoogle Chrome
UNK_LateNightInformation theft and espionageChinaCVE-2026-87491ShadowPadGoogle Chrome
UNK_DoubleCheckInformation theft and espionage-CVE-2026-87491-Google Chrome
UNK_QuietRacketInformation theft and espionageChinaCVE-2026-87491-Google Chrome
KimsukyEspionage, financial gainsNorth KoreaCVE-2017-11882, CVE-2018-0802, CVE-2019-0708, CVE-2019-1405, CVE-2020-0787, CVE-2024-1709, CVE-2025-48703AppleSeed (KGH_SPY), AlphaSeed, HappyDoor, PebbleDash, HelloDoor, httpMalice, httpTroy, MemLoad, HTTPSpy, AsyncRAT, BabyShark, GoldDragon, Troll Stealer, QuasarRAT, Gh0st RAT, KimJongRAT and 20 more tracked familiesGitHub, Pastebin, Dropbox, Slack, Cloudflare Quick Tunnels, Visual Studio, Microsoft 365, Okta
StormousFinancial gain--StormousX-
Meowciety403Financial gains, information theft----
ShinyHuntersFinancial gain-CVE-2026-35273SIDEEYEOracle PeopleSoft
Storm-3069Information theft, espionageChina-NeedyMantis-

07 / Targets

Targeted Products, Countries and Industries

Targeted products spanned network security appliances (SonicWall SMA 1000, Check Point, F5 BIG-IP APM, Cisco, Citrix NetScaler), Google Chrome, e-commerce and CMS platforms (Adobe Commerce, Magento, WordPress), PostgreSQL, Windows and Apple operating systems, endpoint security drivers (Microsoft Malware Protection Engine, Topaz Antifraud, K7 Security), RMM and remote support tools (N-able N-central, ConnectWise ScreenConnect), DevOps and repository platforms (GitLab, JFrog Artifactory), TrueConf Server, PaperCut, Acronis Backup, Zyxel and Arista infrastructure, and Oracle PeopleSoft PeopleTools 8.61 and 8.62.

Most targeted countries
GermanyMexicoUnited Arab EmiratesSouth AfricaCanada

Activity was also recorded across the United States, Egypt, Singapore, France, Brazil, Thailand, Italy, South Korea, Turkey, Taiwan, Colombia, India, the Philippines, Spain, Portugal, Argentina, Saudi Arabia, China, Greece, Vietnam, Japan, Israel, the United Kingdom, Australia and many additional countries, 195 in total.

Most targeted industries
GovernmentFinanceEducationTechnologyRetail

55 industries were targeted in total, with Agriculture shown as the least targeted.


08 / Takeaways

Top 5 Takeaways

  1. 01
    Zero-days
    In September 2026, 20 zero-day vulnerabilities surfaced across products from PaperCut, SonicWall, Google Chrome, Adobe, Microsoft Windows, N-able, Cisco, Check Point, F5, Arista, Citrix, Apple, and Oracle.
  2. 02
    New malware
    Newly identified malware active in September included a broad mix of backdoors and RATs. Key discoveries were NodeRabbit, PollCat, Retrograde/MiniFast, and SIDEEYE, each representing distinct capabilities ranging from stealthy persistence and credential theft to large-scale compromise.
  3. 03
    Top countries
    Cyberattacks concentrated heavily on Germany, Mexico, the United Arab Emirates, South Africa, and Canada, which absorbed most of the hostile activity. Espionage operations and financially motivated intrusions drove the surge.
  4. 04
    Top industries
    Government, Finance, Education, Technology, and Retail sectors absorbed the bulk of targeted activity, with ransomware operations, data theft, and espionage campaigns driving operational disruption.
  5. 05
    Leading actors
    Activity during the period was dominated by TA412, UTA0560, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket, ShinyHunters, and Storm-3069, all well-resourced groups known for sustained, high-impact operations.

09 / Response

Recommendations

Security teams: This digest can be used as a guide to help security teams prioritize the 36 significant vulnerabilities and block the indicators related to the 12 active threat actors, 31 active malware, and 209 potential MITRE TTPs.

Uni5 users: This is an actionable threat digest for HivePro Uni5 customers, who can get comprehensive insights into their threat exposure and take action easily through the HivePro Uni5 dashboard by running a scan to discover the assets impacted by the 36 significant vulnerabilities, and testing the efficacy of their security controls by simulating the attacks related to active threat actors, active malware, and potential MITRE TTPs in Breach and Attack Simulation (BAS).


10 / Indicators

Top Indicators of Compromise (IoCs)

AttackTypeValue
NodeRabbitDomains
healthcomfsdpower[.]com
visitfinancedentists[.]com
msmanagementgrp[.]com
msmanagementgrpmedia[.]com
naturalapplication[.]azurewebsites[.]net
retaildemo[.]azurewebsites[.]net
tubitak[.]azurewebsites[.]net
rgbteller[.]azurewebsites[.]net
wslwebui[.]azurewebsites[.]net
plugplay[.]azurewebsites[.]net
crossdwm[.]azurewebsites[.]net
wdisystem[.]azurewebsites[.]net
wslmenus[.]azurewebsites[.]net
dnshnsdev[.]azurewebsites[.]net
hpjumpsrv[.]azurewebsites[.]net
storview[.]azurewebsites[.]net
kyrasey-f8hfexa5cqamh7fk[.]westeurope-01[.]azurewebsites[.]net
greenyjsgfd[.]azurewebsites[.]net
helptellerbls[.]azurewebsites[.]net
timedrv[.]azurewebsites[.]net
userwellgtfs[.]azurewebsites[.]net
hecowime-aqdphyd4bbdef6es[.]westeurope-01[.]azurewebsites[.]net
NodeRabbitURL
hxxps[:]//lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate
PollCatFilenames
RankChallenge-react-6uJSX3-main.zip
requireObject.js
PollCatDomains
gamebarapp[.]azurewebsites[.]net
gamebarappinformation[.]azurewebsites[.]net
sahi-finance[.]com
lifespotify[.]com
Retrograde/MiniFastMD5
810F8E3B88EB05F710C09552941D6F56
Retrograde/MiniFastSHA256
0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864
GRIMWEDGESHA256
69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc
59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcb
GRIMWEDGEDomain
ocr[.]opusaccel[.]top
SUPERSTOMPSHA256
e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0
LONGTALESHA256
5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3
LONGTALEURL
hxxps://xyz0102.gitprogram[.]com/a001
LONGTALEHostname
extension-management-portal.centerfjdr658.workers[.]dev
extension-management-portal.kmjukilo-lkjh.workers[.]dev
ShadowPadHostname
ms.checrity[.]com
ShadowPadIPv4
79[.]133[.]56[.]90
ShadowPadDomain
checrity[.]com
PAYLOAD RansomwareSHA256
1CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F
PAYLOAD RansomwareMD5
E0FD8FF6D39E4C11BDAF860C35FD8DC0
0108656A3E1ADE6CA4F21B084F5E1208
BEA5E267F24D7DA59F6821BFFDBFF293
PAYLOAD RansomwareTOR address
payload6eualw6kni6v2lqn7ovjcl76ojx25z5unsyvqo3lbqy3bo5qd[.]onion
payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd[.]onion
payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion
DragonForce RansomwareSHA256
e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22
a4eb9be98d00c961ad8c3329ee80690c1eec98d4c8fa8dd91c371d9ecc451581
DragonForce RansomwareSHA1
55acb53f348c9f6b89343dc8d96522aa75e4cfdb
DragonForce RansomwareMD5
bd47ae24b03e5ba0f1ab2e95e7acb989
DragonForce RansomwareFile path
C:\Users\Public\log.log
DragonForce RansomwareTOR address
3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd[.]onion
z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid[.]onion
DragonForce RansomwareTOX ID
1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20
SIDEEYESHA256
3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3
SIDEEYEIPv4
162[.]219[.]30[.]165
NeedyMantisSHA256
e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e
9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef
c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77

A comprehensive list of IOCs for all tracked attacks is available on the Uni5Xposure platform.


11 / MITRE ATT&CK

Top MITRE ATT&CK TTPs

T1059
Command and Scripting Interpreter
T1190
Exploit Public-Facing Application
T1588
Obtain Capabilities
T1588.006
Vulnerabilities
T1027
Obfuscated Files or Information
T1005
Data from Local System
T1071
Application Layer Protocol
T1078
Valid Accounts
T1105
Ingress Tool Transfer
T1566
Phishing
T1068
Exploitation for Privilege Escalation
T1071.001
Web Protocols
T1059.003
Windows Command Shell
T1083
File and Directory Discovery
T1036
Masquerading
T1041
Exfiltration Over C2 Channel
T1657
Financial Theft
T1583
Acquire Infrastructure
T1021
Remote Services
T1082
System Information Discovery
T1053
Scheduled Task/Job
T1562
Impair Defenses
T1036.005
Match Legitimate Name or Location
T1204.002
Malicious File
T1070
Indicator Removal

209 MITRE ATT&CK techniques were observed across the month; the 25 most frequent are listed above.

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.