HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, 14 major attacks were detected, 7 vulnerabilities were actively exploited, and 6 threat actor groups were closely monitored, signaling a concerning escalation in malicious activity worldwide.
Among the most significant developments, StyleSmuggler (CVE-2026-75650) leads this cycle. A template-engine flaw in Magento Open Source and Adobe Commerce, exploited in the wild since 4 September 2026, lets unauthenticated attackers hide PHP in a failure report and trigger a failed-payment email that executes it, yielding remote code execution.
That same commercial layer is drawing organized extortion elsewhere. Panzer, a new Ransomware-as-a-Service group, went live with its leak site on 5 August 2026 and has already named 20+ victims across 10+ countries, pairing theft with encryption and countdown timers on Tor.
BREEZE COMET, active since September 2023, is a Brazil-based crew that breaches local financial services, fintech, retail, and eCommerce firms to reach internal payment systems and push fraudulent transfers. Together, these incidents underscore a growing trend of hybrid cyber operations that combine technical exploitation with social engineering, reinforcing the need for timely patching, continuous monitoring, and layered security defenses.
Insights
CVE-2026-86218: a static code injection flaw at maximum severity lets an attacker run code on the RMM server without ever logging in.CVE-2026-6471: a missing-authorization flaw in PostgreSQL logical decoding, latent since 2014, lets a REPLICATION-only role escalate straight to superuser.CVE-2026-75650), since patching Magento does not remove an implant already installed.Top MITRE ATT&CK TTPs
Attacks Executed
| Name | Type | Overview | Associated Actor / Source |
|---|---|---|---|
| COBALTSPIN | Network Tunneler | Rust-based tunneler opening a reverse SOCKS5 proxy over WebSocket to cross segmented financial networks. | BREEZE COMET |
| REALBREEZE | Brute-forcer | Brute-forces LDAP to harvest credentials for lateral movement into core banking systems. | BREEZE COMET |
| MILDFROST | Backdoor | Passive Java JAR backdoor with DNS tunneling as a covert fallback C2 channel. | BREEZE COMET |
| BOATBEAM | Backdoor | Go-based backdoor that fakes an IIS HTTPS server on port 443 for stealth. | BREEZE COMET |
| LIGHTPAINT | Backdoor | Java-based backdoor that installs a legitimate SoftEther VPN for covert access. | BREEZE COMET |
| KICKPLATE | Backdoor / Loader | Nim-based backdoor and loader that impersonates Windows Update Health Tools. | BREEZE COMET |
| XWORM | Backdoor | Persists via automated startup shortcut modifications; PowerShell disables Defender real-time monitoring. | BREEZE COMET |
| JSCeal | Stealer | Compiled-V8-bytecode crypto stealer that installs a local proxy to intercept exchange traffic. | Unattributed |
| PEEP | Browser Extension / RAT | “Smart Bookmarks” extension that forges Chromium integrity checks and bridges to the OS via a native-messaging host. | Unattributed |
| GRIMWEDGE | Backdoor | JScript backdoor delivered post-exploitation via the BlueMoon Chrome exploit chain. | TA412 |
| SUPERSTOMP | Loader | Loader that installs the LONGTALE credential-stealing Chrome extension. | UTA0560 |
| LONGTALE (aka GemStone) | Browser Extension / Stealer | Credential-stealing Chrome extension installed by SUPERSTOMP. | TA412 |
| ShadowPad | Backdoor | Modular backdoor delivered via the BlueMoon exploit chain against Chrome. | UNK_LateNight |
| Panzer | Ransomware | Cross-platform RaaS (Windows/Linux/ESXi/FreeBSD) with an 80/20 affiliate split and Tor leak site. | Panzer RaaS |
Vulnerabilities Exploited
| CVE ID | Name | Zero-Day | CISA KEV |
|---|---|---|---|
CVE-2026-75650 | StyleSmuggler (Adobe Commerce/Magento RCE) | Yes | No |
CVE-2026-6471 | PostGREShell (PostgreSQL Output Plugin Missing Authorization) | No | No |
CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow | Yes | Yes |
CVE-2026-81963 | Microsoft Windows Link Following | Yes | Yes |
CVE-2026-69414 | ShieldBreak (Microsoft Defender EoP) | No | No |
CVE-2026-86218 | N-able N-central Static Code Injection | Yes | Yes |
CVE-2026-87491 | Google Chromium V8 Out of Bounds Write | Yes | Yes |
Adversaries in Action
| Name | Origin | Target Industries | Target Regions |
|---|---|---|---|
| BREEZE COMET (aka UNC5669, PLUMP SPIDER, SHADOW-AETHER-064, CL-CRI-1163) | Brazil | Financial Services, Fintech, Banking Software Providers, Payment Processors, Banks, Retail, Point-Of-Sale, Ecommerce, Exchanges, Government | Brazil, Argentina, and 85+ other countries across the Americas and Africa |
| TA412 (aka JungleBamboo, APT31, Violet Typhoon, TIDE CASTLE, Judgment Panda, Zirconium, RedBravo, Bronze Vinewood, Red Keres) | China | Non-governmental organizations, aerospace and defense-industrial firms, mining and commodity traders, manufacturing, government and financial sector | United States |
| UTA0560 | China | Non-governmental organizations (NGOs) | Worldwide |
| UNK_LateNight | China | Aerospace | US |
| UNK_DoubleCheck | — | Manufacturing | Vietnam |
| UNK_QuietRacket | China | Government, consulting, financial sector | Singapore, Indonesia |
Recommendations
This digest can be used to drive security teams to prioritize the seven exploited vulnerabilities and block indicators related to BREEZE COMET, TA412, UTA0560, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, and malware COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, LIGHTPAINT, KICKPLATE, XWORM, JSCeal, PEEP, GRIMWEDGE, SUPERSTOMP, LONGTALE, ShadowPad, and Panzer.
HivePro Uni5 customers can get comprehensive insight into their threat exposure by running a scan to discover assets impacted by the seven exploited vulnerabilities.
Test the efficacy of security controls by simulating the attacks related to TA412 and malware MILDFROST, KICKPLATE, XWorm, JSCeal, COBALTSPIN, and REALBREEZE in Breach and Attack Simulation (BAS).
Threat Advisories Referenced This Week
- BREEZE COMET Turns Brazil’s Instant Payment Rails into a Cash-Out Channel
- StyleSmuggler: Adobe Commerce and Magento Zero-Day Exploited
- JSCeal: Crypto Stealer Hidden in V8 Bytecode
- CVE-2026-6471: Twelve-Year-Old PostgreSQL Flaw Grants Full Server Control
- PEEP: The Bookmark Extension That Backdoors Your PC
- Microsoft’s September 2026 Patch Tuesday – Priority Fixes
- N-able N-central Pre-Auth RCE Exploited in the Wild (CVE-2026-86218)
- Patch-Gap Panic: Chrome V8 Zero-Day Fuels the BlueMoon Espionage Wave
- Panzer: New Cross-Platform RaaS Claims Global Victims in Its First Month
Appendix: Indicators of Compromise (IOCs)
| Attack | Type | Value |
|---|---|---|
| COBALTSPIN | SHA256 | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec |
| REALBREEZE | SHA256 | 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a |
| MILDFROST | SHA256 | c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a |
| BOATBEAM | SHA256 | 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb |
| KICKPLATE | SHA256 | f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f |
| XWORM | SHA256 | 51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6, d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66, 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8 |
| JSCeal | SHA256 | 1f5acba97db6d514e4b35ba0601c5269697e8ab3bb99d097db25ec7e74464594 |
| GRIMWEDGE | SHA256 / Domain | 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc, 59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcb; domain ocr[.]opusaccel[.]top |
| SUPERSTOMP | SHA256 | e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0 |
| LONGTALE | SHA256 / URL | 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3; hxxps[:]//xyz0102[.]gitprogram[.]com/a001 |
| ShadowPad | Hostname / IPv4 / Domain | ms[.]checrity[.]com; 79[.]133[.]56[.]90; checrity[.]com |
| Panzer | TOR Address / Tox ID | pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion; 8C3D96497A9438794F705C055FC2FD3059F6CF11FF51060EE55ED7F0679CFC7218825BD56CB1 |
A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
