Weekly Threat Digest: 14 to 20 SEPTEMBER 2026

Weekly Threat Digest
Download Now
Weekly Threat Digest 14 to 20 September 2026 | Hive Pro Threat Advisory
Weekly Threat Digest/14 to 20 September 2026

Weekly Threat Digest: 14 to 20 September 2026

HiveForce Labs tracked ten attacks, eight actively exploited vulnerabilities and two adversaries this week, led by Cisco ISE and Secure Email Gateway zero-days, GitLab CVE-2026-85706, and Kimsuky's expanded espionage toolkit.

10 attacks executed8 exploited vulnerabilities2 adversariesKimsukyStormous
Published
September 22, 2026
Period
14 to 20 Sep 2026
Report type
Weekly digest
Attacks
10
Vulnerabilities
8
Adversaries
2
Total CVEs
517.5K
Published (week)
4,834
Exploited
8

01 / Overview

Summary

HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, ten major attacks were detected, eight vulnerabilities were actively exploited, and two threat actor groups were closely monitored, signaling a concerning escalation in malicious activity worldwide.

Among the most significant developments, Cisco has confirmed zero-day exploitation of CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass in Identity Services Engine that grants unauthenticated attackers root-level command execution, alongside CVE-2026-76461 (CVSS 9.8), where a single crafted email compromises Secure Email Gateway with root privileges. In parallel, GitLab patched CVE-2026-85706, a maximum-severity path traversal in self-managed CE and EE that enables unauthenticated arbitrary file read, with scanning escalating to theft of configuration and SSH files within days.

Elsewhere, Kimsuky, the North Korean espionage group, expanded its arsenal with AI-generated lures, weaponized QR codes harvesting Microsoft 365 and Okta credentials, and Operation GitPower, which routes payloads and exfiltration through GitHub, Pastebin, Dropbox, and Slack. Separately, Stormous, the Arabic-speaking extortion group active since 2021, announced the termination of its operations and took all leak-site mirrors offline, though a rebrand cannot be ruled out. Together, these incidents reinforce a landscape in which rapidly weaponised edge-facing vulnerabilities and patient, evasion-heavy espionage operations advance side by side, underscoring the need for prompt patching of internet-facing systems and continuous monitoring for post-exploitation activity.

10
Attacks executed
8
Vulnerabilities exploited
2
Adversaries in action

02 / Highlights

Insights

CVE-2026-76460 is a Cisco ISE authentication bypass under active zero-day exploitation, granting unauthenticated attackers root command execution.

JFrog Artifactory flaws were chained to forge persistent admin tokens on internet-facing repositories, peaking at 406,000 attempts in a day, and the minted tokens survive patching.

CVE-2026-85706 is a GitLab path traversal allowing unauthenticated file read on self-managed servers, exploited within a day to steal SSH and configuration secrets.

Kimsuky, the North Korean espionage group, expanded its arsenal with AI-generated lures, weaponized QR codes, and Operation GitPower, routing payloads and stolen data through GitHub, Pastebin, Dropbox, and Slack.

Stormous, the Arabic-speaking extortion group with up to 240 claimed victims, announced its shutdown and took all leak-site mirrors offline, though a rebrand cannot be ruled out.

CVE-2026-76461 lets a single crafted email seize root on Cisco Secure Email Gateway, with no login, password, or user interaction required.

Threat distribution
BackdoorLoaderRATRansomwareCryptominer
Vulnerability volume
517.5K
Total vulnerabilities published
4,834
Published in the week
8
Exploited vulnerabilities

03 / Attacks

Attacks Executed

AppleSeed (KGH_SPY)

AppleSeed is Kimsuky's flagship espionage implant, first seen in 2019 and still active through version 2.1, with the KGH_SPY suite tracked as a closely related modular toolset from the same actor. KGH_SPY is a modular spyware suite giving the operators reconnaissance, keylogging, information-stealing and backdoor functions. The AppleSeed family ships in two forms: a Dropper variant that pulls down further malware and runs C2 commands, and a Spy variant that harvests documents, screenshots, keystrokes and USB drive listings.

Type
Backdoor
Actor
Kimsuky
Delivery
Spear-phishing emails
Impact
Persistent access, remote execution, keystroke logging
Platform
Windows
Targeted CVE
-
HappyDoor

HappyDoor is a backdoor, with the name taken from the "happy" string found in its export DLL name and debug data. It is a DLL that stores its configuration, including C2 addresses and encryption keys, in registry paths designed to look like legitimate software, and it communicates using a custom fixed-length packet structure with several authentication fields.

Type
Backdoor
Actor
Kimsuky
Delivery
Spear-phishing emails
Impact
Persistent access, remote execution, screen capture, file exfiltration
Platform
Windows
Targeted CVE
-
HelloDoor

HelloDoor is a DLL-based backdoor and is Kimsuky's first known malware written in Rust, a language the group rarely uses. Its C2 is hosted on TryCloudflare, a temporary Cloudflare tunneling service that requires no account or setup, which makes the infrastructure behind it hard to trace. On execution it fingerprints the host using the MAC address, computer name and a fixed string, hashes that into a unique ID, and binds to local port 5555 or 5554 depending on whether its token is elevated.

Type
Backdoor
Actor
Kimsuky
Delivery
Spear-phishing emails
Impact
Autorun tampering, host fingerprinting, local port-binding, process termination
Platform
Windows
Targeted CVE
-
httpMalice

httpMalice is a backdoor, surfacing no later than December 2025. It profiles the host with Windows commands run under code page 949, indicating Korean-language (EUC-KR) targets, and its command set covers file transfer, directory archiving and upload, screen capture, in-memory payload loading, hibernation and self-removal.

Type
Backdoor
Actor
Kimsuky
Delivery
Spear-phishing emails
Impact
Persistent backdoor, service creation, remote execution
Platform
Windows
Targeted CVE
-
httpTroy

httpTroy is the final-stage backdoor in a Kimsuky three-part chain. Its role is long-term access and data exfiltration. It marks infected hosts by writing eight random bytes to an Alternate Data Stream, depending on whether it holds an elevated token. It is heavily obfuscated: API calls are hidden behind custom hashing and strings are scrambled with XOR and SIMD operations, with both reconstructed at runtime rather than reused, which frustrates static analysis.

Type
Backdoor
Actor
Kimsuky
Delivery
Spear-phishing
Impact
Remote execution, reverse shell, file transfer, persistent access
Platform
Windows
Targeted CVE
-
MemLoad

MemLoad is a loader; its purpose is twofold: to keep the real backdoor off disk to evade detection and vet the target before committing the payload, using anti-VM checks and basic reconnaissance.

Type
Loader
Actor
Kimsuky
Delivery
Spear-phishing attachment
Impact
Payload delivery, memory injection, scheduled-task persistence, privilege check
Platform
Windows
Targeted CVE
-
HTTPSpy

HttpSpy is a remote access trojan seen in use around April 2026 against South Korean military and enterprise targets. The newer variant abandons the old single-binary design for a three-stage chain with the final RAT decrypted and executed entirely in memory. Its command set covers shell execution, file upload in chunks and download, screen capture, secure file wiping, timestomping, DLL injection into a chosen process, execution in a specified terminal session, TCP connectivity testing, live config updates and full self-uninstall.

Type
RAT
Actor
Kimsuky
Delivery
Spear-phishing attachments
Impact
Remote execution, file exfiltration, file download
Platform
Windows
Targeted CVE
-
AsyncRAT

AsyncRAT is a widely available open-source .NET remote access trojan, not custom Kimsuky tooling; the group adopts it alongside other commodity RATs. In Kimsuky's hands, it appears most prominently in the campaign tracks as Operation GitPower, where encrypted AsyncRAT payloads are staged in Git repositories disguised as image files, with GitHub serving as both the distribution point and the C2 channel so traffic blends into trusted developer infrastructure.

Type
RAT
Actor
Kimsuky
Delivery
Spear-phishing
Impact
Remote control, keystroke logging, screen capture, credential theft
Platform
Windows
Targeted CVE
-
StormousX

StormousX is the ransomware program the Stormous group has marketed under its own brand since 2023 and later offered alongside GhostLocker through the STMX_GhostLocker affiliate service. It is advertised as a file-encrypting payload supporting the group's double-extortion operations, with victims listed across multiple regions.

Type
Ransomware
Actor
Stormous
Delivery
Phishing
Impact
Data theft and public leak
Platform
-
Targeted CVE
-
XMRig

XMRig is an open-source, cross-platform Monero (XMR) cryptocurrency miner that is legitimate software but is one of the most widely abused tools in illicit cryptojacking, as attackers embed it in malware chains to hijack victim CPU resources for mining.

Type
Cryptominer
Actor
-
Delivery
Social engineering
Impact
Resource hijacking, persistent access
Platform
ConnectWise ScreenConnect
Targeted CVE
CVE-2026-84869

04 / Exploited

Vulnerabilities Exploited

CVE-2026-85706
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Affected product
GitLab CE/EE self-managed (18.7 before 19.1.8; 19.2 before 19.2.6; 19.3 before 19.3.2)
CWE ID
CWE-22
Associated TTPs
T1190: Exploit Public-Facing Application, T1005: Data from Local System
Associated attacks
-
Patch link
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
CVE-2026-76461
Cisco Secure Email Gateway SQL Injection Vulnerability
Affected product
Cisco Secure Email Gateway (AsyncOS): 15.5 and earlier (before 15.5.5-014), 16.0 (before 16.0.4-302), 16.5 (before 16.5.0-780)
CWE ID
CWE-89
Associated TTPs
T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Associated attacks
-
Patch link
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
CVE-2026-87886
Acronis Backup Incorrect Default Permissions Vulnerability
Affected product
Acronis Backup plugin for cPanel & WHM (before 1.9.3.1021); Acronis Backup extension for Plesk (before 1.8.11.638)
CWE ID
CWE-276
Associated TTPs
T1068: Exploitation for Privilege Escalation
Associated attacks
-
Patch link
https://security-advisory.acronis.com/updates/UPD-2609-3d72-20a7
https://security-advisory.acronis.com/updates/UPD-2609-efb0-50b2
https://security-advisory.acronis.com/advisories/SEC-10986
CVE-2026-84869
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Affected product
ConnectWise ScreenConnect client version before 26.6.5
CWE ID
CWE-269, CWE-862
Associated TTPs
T1068: Exploitation for Privilege Escalation, T1548: Abuse Elevation Control Mechanism
Associated attacks
XMRig cryptominer
Patch link
https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
CVE-2026-76460
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Affected product
Cisco ISE & ISE-PIC (releases 3.0 through 3.5, before the first fixed release)
CWE ID
CWE-648
Associated TTPs
T1190: Exploit Public-Facing Application, T1068: Exploitation for Privilege Escalation
Associated attacks
-
Patch link
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
CVE-2026-42016
JFrog Artifactory Incorrect Authorization Vulnerability
Affected product
JFrog Artifactory Self-Hosted before 7.133.11
CWE ID
CWE-863
Associated TTPs
T1583: Acquire Infrastructure, T1587: Develop Capabilities, T1528: Steal Application Access Token, T1190: Exploit Public-Facing Application
Associated attacks
-
Patch link
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
CVE-2026-42018
JFrog Artifactory Improper Authentication Vulnerability
Affected product
JFrog Artifactory Self-Hosted before 7.111.20; 7.117.0 to 7.117.27; 7.125.0 to 7.125.19; 7.133.0 to 7.133.28; 7.146.0 to 7.146.8
CWE ID
CWE-287
Associated TTPs
T1190: Exploit Public-Facing Application, T1562: Impair Defenses
Associated attacks
-
Patch link
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
CVE-2026-82329
JFrog Artifactory Improper Authentication Vulnerability
Affected product
JFrog Artifactory Self-Hosted 7.111.4 to 7.111.20; 7.117.0 to 7.117.27; 7.125.0 to 7.125.19; 7.133.0 to 7.133.28; 7.146.0 to 7.146.37; 7.161.0 to 7.161.19
CWE ID
CWE-287
Associated TTPs
T1190: Exploit Public-Facing Application, T1562: Impair Defenses
Associated attacks
-
Patch link
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases

05 / Actors

Adversaries in Action

Kimsuky
Also known as
APT43, Thallium, THALLIUM, Velvet Chollima, Black Banshee, Emerald Sleet, Ruby Sleet, Sparkling Pisces, Springtail, TA427, TA406, Earth Kumiho, PatheticSlug, ARCHIPELAGO, SharpTongue, ITG16, Greendinosa, RGB-D5, Cerium
Origin
North Korea
Motive
Espionage, financial gains
Targeted industries
Government, Public Administration, Defense, Think Tanks, Policy Research Institutes, Academia, Universities, NGOs, Human Rights Organizations, Media, Healthcare, Machinery, Energy, Nuclear Power Operations, Manufacturing, Business Services, Legal Services, Construction, Financial, Insurance, Retail, Cryptocurrency
Targeted regions
South Korea, United States, Japan, Vietnam, Thailand, Brazil, Germany, Russia, Canada, and broader Europe
Targeted CVEs
CVE-2017-11882 CVE-2018-0802 CVE-2019-0708 CVE-2019-1405 CVE-2020-0787 CVE-2024-1709 CVE-2025-48703
Associated attacks
AppleSeed (KGH_SPY), AlphaSeed, HappyDoor, PebbleDash, HelloDoor, httpMalice, httpTroy, MemLoad, HTTPSpy, AsyncRAT, BabyShark, GoldDragon, KLogEXE, Troll Stealer, Gomir, NavRAT, NikiHTTP, NikiTeaR, ComeBacker, DRATzarus, FastFire, FastSpy, FlowerPower, RandomQuery, Yorekey, Grease, TRANSLATEXT, QuasarRAT, Gh0st RAT, KimJongRAT, CSPY Downloader, BITTERSWEET, VENOMBITE, xRAT, MailFetch.py, Reger Dropper, Pidoc Dropper
Affected products
GitHub, Pastebin, Dropbox, Slack, Cloudflare Quick Tunnels, Visual Studio, Microsoft 365, Okta
Key TTPs
T1566 Phishing, T1566.001 Spearphishing Attachment, T1566.002 Spearphishing Link, T1657 Financial Theft, T1041 Exfiltration Over C2 Channel, T1111 MFA Interception, T1056.001 Keylogging, T1102 Web Service, T1071.001 Web Protocols, T1003.001 LSASS Memory, T1059.001 PowerShell, T1105 Ingress Tool Transfer, T1190 Exploit Public-Facing Application, T1203 Exploitation for Client Execution, T1588.007 Artificial Intelligence, T1620 Reflective Code Loading, T1682 Query Public AI Services
Stormous
Motive
Financial gain
Associated ransomware
StormousX
Targeted industries
Technology, Business Services & Consulting, Manufacturing, Retail, Hospitality, Education, Healthcare, Telecommunications, Media, Government, Financial Services, Pharmaceutical, Energy, Transportation, Casino & Gambling, Aerospace and Defense, Food Service, Religion, Agriculture, Real Estate, Aviation, Insurance
Targeted regions
Worldwide, including the United States, United Kingdom, Spain, France, Italy, India, Brazil, China and Japan across more than 50 countries
TTPs
TA0042 Resource Development, TA0001 Initial Access, TA0009 Collection, TA0010 Exfiltration, TA0040 Impact, T1583 Acquire Infrastructure, T1583.001 Domains, T1583.006 Web Services, T1585 Establish Accounts, T1585.001 Social Media Accounts, T1587 Develop Capabilities, T1587.001 Malware, T1078 Valid Accounts, T1566 Phishing, T1005 Data from Local System, T1213 Data from Information Repositories, T1114 Email Collection, T1567 Exfiltration Over Web Service, T1567.002 Exfiltration to Cloud Storage, T1486 Data Encrypted for Impact, T1657 Financial Theft

06 / Actions

Recommendations

  1. 01
    Security Teams
    Use this digest to prioritize the eight exploited vulnerabilities and block the indicators related to the threat actors Kimsuky and Stormous and to the malware AppleSeed (KGH_SPY), HappyDoor, HelloDoor, httpMalice, httpTroy, MemLoad, HTTPSpy, AsyncRAT, StormousX, and XMRig.
  2. 02
    Uni5 Users: Scan for Exposure
    Run a Scan in the HivePro Uni5 dashboard to discover the assets impacted by the eight exploited vulnerabilities.
  3. 03
    Uni5 Users: Validate Controls
    Test the efficacy of security controls by simulating the attacks related to the threat actor Kimsuky and the malware StormousX in Breach and Attack Simulation (BAS).

07 / Mapping

Top MITRE ATT&CK TTPs

T1190
Exploit Public-Facing Application
T1588
Obtain Capabilities
T1588.006
Vulnerabilities
T1078
Valid Accounts
T1059
Command and Scripting Interpreter
T1657
Financial Theft
T1585
Establish Accounts
T1567
Exfiltration Over Web Service
T1583
Acquire Infrastructure
T1566
Phishing
T1005
Data from Local System
T1083
File and Directory Discovery
T1041
Exfiltration Over C2 Channel
T1098
Account Manipulation
T1589
Gather Victim Identity Information
T1053
Scheduled Task/Job
T1087
Account Discovery
T1105
Ingress Tool Transfer
T1068
Exploitation for Privilege Escalation
T1552
Unsecured Credentials

08 / Indicators

Indicators of Compromise (IoCs)

TypeValue
AppleSeed SHA256
0845f218a588f7619169787c4db69ce9de0c84143b100400b6476d7289a1c493
2c796053053a571e9f913fd5bae3bb45e27a9f510eace944af4b331e802a4ba0
8c35eed98b295d2fc13cb7280e17dcbf232f6703ee74052a479196786ea9f333
HappyDoor SHA256
4ac02dc231f2546ce64335729145db672b5ab01d8943df8a550cc77fc436df14
HappyDoor Domains
cms[.]spaceyou[.]o-r[.]kr
erp[.]spaceme[.]p-e[.]kr
HelloDoor SHA256
db284cc9b6536ab6f956a45ce9e5905716c7547f5e8dc572dc07aa125d27819e
62aac86f38f26700cf534c0a316d31882ffb74488bd1d87a3caeef604fc3a124
HelloDoor FileName
[별지 제8호서식] 개인정보(열람 정정삭제 처리정지) 요구서(개인정보 보호법 시행규칙).hwp.jse
httpMalice SHA256
23420100260cc80055fbf02f4464212278c0e71a4387537771f3fb50f2f891e5
httpMalice URL
hxxps[:]//www[.]pyrotech[.]co[.]kr/common/include/tech/default[.]php
hxxp[:]//newjo-imd[.]com/common/include/library/default[.]php
httpMalice MD5
08160acf08fccecde7b34090db18b321
94faed9af49c98a89c8acc55e97276c9
httpTroy MD5
7e0825019d0de0c1c4a1673f94043ddb
httpTroy Domains
file[.]bigcloud[.]n-e[.]kr
load[.]auraria[.]org
MemLoad MD5
58ac2f65e335922be3f60e57099dc8a3
f73ba062116ea9f37d072aa41c7f5108
MemLoad SHA256
2d597c3a726970927b302bf015cec4e37cdc974959cb846dbcb23cdb46386a6c
MemLoad Domains
load[.]ssangyongcne[.]o-r[.]kr
load[.]yju[.]o-r[.]kr
attach[.]docucloud[.]o-r[.]kr
load[.]supershop[.]o-r[.]kr
load[.]erasecloud[.]n-e[.]kr
HTTPSpy URLs
hxxps[:]//bigfile[.]jaycloudlab[.]com/download[.]php?id=745896
hxxps[:]//download[.]birdriver[.]org/download[.]php?id=393156
HTTPSpy MD5
a581fdea0970f8a5b6cfec4853c802d7
AsyncRAT SHA256
601d9deea6467a57e42c355d481331cd78d6487bd160a081332420c69f214455
daac2fe0fe9a71f531d9b35c9ca269c0bdfbd1bbac5e8d73fc91afcff20ef524
7bb7c893fdf7f7ccd998610969d23993c50fc0b693e67930b6f98d8dbd003ee3
StormousX TOR Address
3slz4povugieoi3tw7sblxoowxhbzxeju427cffsst5fo2tizepwatid[.]onion
h3reihqb2y7woqdary2g3bmk3apgtxuyhx4j2ftovbhe3l5svev7bdyd[.]onion
pdcizqzjitsgfcgqeyhuee5u6uki6zy5slzioinlhx6xjnsw25irdgqd[.]onion
6sf5xa7eso3e3vk46i5tpcqhnlayczztj7zjktzaztlotyy75zs6j7qd[.]onion
zib7duoiglvzvnpjs5faly6bio4xhwiby2lupsnxrkjnx46gmwdfyrid[.]onion
ahb6hjhe4nomgfwxequu52hazigh4ty4gdcnrf3r7z5tiyhour5py2id[.]onion
stniiomyjliimcgkvdszvgen3eaaoz55hreqqx6o77yvmpwt7gklffqd[.]onion
5pbckbo5ra36srfwmb2y6mqpqj7akx3e6ewanujszv7nnjndbbgsjsad[.]onion
XMRig Filename
SearchIndex.exe

09 / Advisories

Threat Advisories

  • GitLab Path Traversal (CVE-2026-85706) Exploited to Steal Secrets
  • Root Delivered by Email: Cisco Secure Email Gateway Zero-Day
  • Kimsuky Blends AI-Generated Lures and Quishing into an Expanded Espionage Arsenal
  • Acronis Backup Plugin Flaw Exploited in the Wild
  • Stormous Extortion Group Announces Shutdown After Four Years of Leak-Site Activity
  • CVE-2026-84869: Critical ScreenConnect Client Flaw Under Active Exploitation
  • Cisco ISE Authentication Bypass Zero-Day Under Active Exploitation
  • JFrog Artifactory Flaws Chained for Administrative Takeover

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.