Weekly Threat Digest: 07 to 13 SEPTEMBER 2026

Weekly Threat Digest
Download Now
Weekly Threat Digest: 07 to 13 September 2026

HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, 14 major attacks were detected, 7 vulnerabilities were actively exploited, and 6 threat actor groups were closely monitored, signaling a concerning escalation in malicious activity worldwide.

Among the most significant developments, StyleSmuggler (CVE-2026-75650) leads this cycle. A template-engine flaw in Magento Open Source and Adobe Commerce, exploited in the wild since 4 September 2026, lets unauthenticated attackers hide PHP in a failure report and trigger a failed-payment email that executes it, yielding remote code execution.

That same commercial layer is drawing organized extortion elsewhere. Panzer, a new Ransomware-as-a-Service group, went live with its leak site on 5 August 2026 and has already named 20+ victims across 10+ countries, pairing theft with encryption and countdown timers on Tor.

BREEZE COMET, active since September 2023, is a Brazil-based crew that breaches local financial services, fintech, retail, and eCommerce firms to reach internal payment systems and push fraudulent transfers. Together, these incidents underscore a growing trend of hybrid cyber operations that combine technical exploitation with social engineering, reinforcing the need for timely patching, continuous monitoring, and layered security defenses.

Insights

#1
N-able N-central CVE-2026-86218: a static code injection flaw at maximum severity lets an attacker run code on the RMM server without ever logging in.
#2
CVE-2026-6471: a missing-authorization flaw in PostgreSQL logical decoding, latent since 2014, lets a REPLICATION-only role escalate straight to superuser.
#3
JSCeal: the fake TradingView installer that trades away your crypto, using compiled V8 bytecode to intercept traffic to Binance, Bybit, and Ledger.
#4
PEEP: the “Smart Bookmarks” extension that owns your browser, forging Chromium’s own integrity checks to install a full backdoor.
#5
Patch isn’t enough: hunting the Rust implant behind StyleSmuggler (CVE-2026-75650), since patching Magento does not remove an implant already installed.
#6
BREEZE COMET turns internal payment systems into ATMs, reaching Brazil’s National Financial System Network to push fraudulent transfers.

Top MITRE ATT&CK TTPs

Top TTPs (unordered)
T1059: Command and Scripting Interpreter
T1005: Data from Local System
T1078: Valid Accounts
T1190: Exploit Public-Facing Application
T1071: Application Layer Protocol
T1027: Obfuscated Files or Information
T1068: Exploitation for Privilege Escalation
T1053: Scheduled Task/Job
T1071.001: Web Protocols
T1657: Financial Theft
T1036: Masquerading
T1588: Obtain Capabilities
T1113: Screen Capture
T1539: Steal Web Session Cookie
T1056: Input Capture
T1574: Hijack Execution Flow
T1059.001: PowerShell
T1583: Acquire Infrastructure
T1059.007: JavaScript
T1556: Modify Authentication Process

Attacks Executed

NameTypeOverviewAssociated Actor / Source
COBALTSPINNetwork TunnelerRust-based tunneler opening a reverse SOCKS5 proxy over WebSocket to cross segmented financial networks.BREEZE COMET
REALBREEZEBrute-forcerBrute-forces LDAP to harvest credentials for lateral movement into core banking systems.BREEZE COMET
MILDFROSTBackdoorPassive Java JAR backdoor with DNS tunneling as a covert fallback C2 channel.BREEZE COMET
BOATBEAMBackdoorGo-based backdoor that fakes an IIS HTTPS server on port 443 for stealth.BREEZE COMET
LIGHTPAINTBackdoorJava-based backdoor that installs a legitimate SoftEther VPN for covert access.BREEZE COMET
KICKPLATEBackdoor / LoaderNim-based backdoor and loader that impersonates Windows Update Health Tools.BREEZE COMET
XWORMBackdoorPersists via automated startup shortcut modifications; PowerShell disables Defender real-time monitoring.BREEZE COMET
JSCealStealerCompiled-V8-bytecode crypto stealer that installs a local proxy to intercept exchange traffic.Unattributed
PEEPBrowser Extension / RAT“Smart Bookmarks” extension that forges Chromium integrity checks and bridges to the OS via a native-messaging host.Unattributed
GRIMWEDGEBackdoorJScript backdoor delivered post-exploitation via the BlueMoon Chrome exploit chain.TA412
SUPERSTOMPLoaderLoader that installs the LONGTALE credential-stealing Chrome extension.UTA0560
LONGTALE (aka GemStone)Browser Extension / StealerCredential-stealing Chrome extension installed by SUPERSTOMP.TA412
ShadowPadBackdoorModular backdoor delivered via the BlueMoon exploit chain against Chrome.UNK_LateNight
PanzerRansomwareCross-platform RaaS (Windows/Linux/ESXi/FreeBSD) with an 80/20 affiliate split and Tor leak site.Panzer RaaS

Vulnerabilities Exploited

CVE IDNameZero-DayCISA KEV
CVE-2026-75650StyleSmuggler (Adobe Commerce/Magento RCE)YesNo
CVE-2026-6471PostGREShell (PostgreSQL Output Plugin Missing Authorization)NoNo
CVE-2026-85880Microsoft Windows Heap-Based Buffer OverflowYesYes
CVE-2026-81963Microsoft Windows Link FollowingYesYes
CVE-2026-69414ShieldBreak (Microsoft Defender EoP)NoNo
CVE-2026-86218N-able N-central Static Code InjectionYesYes
CVE-2026-87491Google Chromium V8 Out of Bounds WriteYesYes

Adversaries in Action

NameOriginTarget IndustriesTarget Regions
BREEZE COMET (aka UNC5669, PLUMP SPIDER, SHADOW-AETHER-064, CL-CRI-1163)BrazilFinancial Services, Fintech, Banking Software Providers, Payment Processors, Banks, Retail, Point-Of-Sale, Ecommerce, Exchanges, GovernmentBrazil, Argentina, and 85+ other countries across the Americas and Africa
TA412 (aka JungleBamboo, APT31, Violet Typhoon, TIDE CASTLE, Judgment Panda, Zirconium, RedBravo, Bronze Vinewood, Red Keres)ChinaNon-governmental organizations, aerospace and defense-industrial firms, mining and commodity traders, manufacturing, government and financial sectorUnited States
UTA0560ChinaNon-governmental organizations (NGOs)Worldwide
UNK_LateNightChinaAerospaceUS
UNK_DoubleCheck—ManufacturingVietnam
UNK_QuietRacketChinaGovernment, consulting, financial sectorSingapore, Indonesia

Recommendations

01
Prioritize the Seven Exploited Vulnerabilities

This digest can be used to drive security teams to prioritize the seven exploited vulnerabilities and block indicators related to BREEZE COMET, TA412, UTA0560, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, and malware COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, LIGHTPAINT, KICKPLATE, XWORM, JSCeal, PEEP, GRIMWEDGE, SUPERSTOMP, LONGTALE, ShadowPad, and Panzer.

02
Uni5 Users: Run a Scan

HivePro Uni5 customers can get comprehensive insight into their threat exposure by running a scan to discover assets impacted by the seven exploited vulnerabilities.

03
Uni5 Users: Simulate the Attacks

Test the efficacy of security controls by simulating the attacks related to TA412 and malware MILDFROST, KICKPLATE, XWorm, JSCeal, COBALTSPIN, and REALBREEZE in Breach and Attack Simulation (BAS).


Threat Advisories Referenced This Week


Appendix: Indicators of Compromise (IOCs)

AttackTypeValue
COBALTSPINSHA2563b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec
REALBREEZESHA2562214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a
MILDFROSTSHA256c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a
BOATBEAMSHA2566d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb
KICKPLATESHA256f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f
XWORMSHA25651fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6, d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66, 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8
JSCealSHA2561f5acba97db6d514e4b35ba0601c5269697e8ab3bb99d097db25ec7e74464594
GRIMWEDGESHA256 / Domain69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc, 59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcb; domain ocr[.]opusaccel[.]top
SUPERSTOMPSHA256e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0
LONGTALESHA256 / URL5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3; hxxps[:]//xyz0102[.]gitprogram[.]com/a001
ShadowPadHostname / IPv4 / Domainms[.]checrity[.]com; 79[.]133[.]56[.]90; checrity[.]com
PanzerTOR Address / Tox IDpnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd[.]onion; 8C3D96497A9438794F705C055FC2FD3059F6CF11FF51060EE55ED7F0679CFC7218825BD56CB1

A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.