Weekly Threat Digest: 31 August – 6 September 2026

Weekly Threat Digest
Download Now
Weekly Threat Digest: 31 August to 6 September 2026

HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, three major attacks were detected, eight vulnerabilities were actively exploited, and one threat actor group was closely monitored, signaling a concerning escalation in malicious activity worldwide.

On the vulnerability front, SonicWall confirmed active exploitation of two zero-days in its Secure Mobile Access (SMA) 1000 series. CVE-2026-83548, a maximum-severity flaw in the Work Place interface, lets unauthenticated attackers reach sensitive internal functions through server-side request forgery, while CVE-2026-83549 lets an already-logged-in administrator run arbitrary commands via the Appliance Management Console. SonicWall caught both internally and has already shipped hotfixes. Google, meanwhile, patched a high-severity type confusion bug in Chrome’s V8 engine, CVE-2026-85046, that was also being exploited in the wild — a compiler bug affecting Maglev and TurboFan that gave attackers arbitrary read/write access to the JavaScript heap through nothing more than a crafted webpage.

On the threat-actor side, the Iran-linked group Mirage Kitten (aka Nimbus Manticore) is running a recruitment-themed campaign against aviation, aerospace, and FinTech professionals across the Middle East and Africa, posing as recruiters on LinkedIn and job boards to hand out trojanized coding-challenge files that quietly install two new cross-platform RATs, NodeRabbit and PollCat, capable of remote access, credential theft, and data exfiltration. Separately, a ClickFix-style campaign dubbed TerminalFix tricks victims with a fake Cloudflare CAPTCHA into pasting a PowerShell command that ultimately sideloads malware, sets up persistence, maps out the Active Directory environment, and opens a hidden proxy tunnel for the attacker. Together, these incidents point to a clear pattern: attackers are blending technical exploits with social engineering, making timely patching, vigilant monitoring, and layered defenses more essential than ever.

High-Level Statistics

3 Attacks Executed · 8 Vulnerabilities Exploited · 1 Adversary in Action


Insights

#1
Two PaperCut zero-days chain into an auth bypass and then into RCE, and since the first two emergency patches were bypassable, only Release 3 holds. Patch every server, and treat any exposed one as already breached.
#2
A form field becomes a foothold: Elementor Pro’s CVE-2026-32475 lets attackers upload a PHP file through a contact form and run it as code, with 10M+ WordPress sites in the blast radius.
#3
Iran-linked Mirage Kitten baits aviation and FinTech pros with fake LinkedIn recruiters; the “coding challenge” is really cross-platform Node.js RATs hiding C2 behind Azure and Cloudflare.
#4
Another V8 zero-day in the wild: Chrome’s CVE-2026-85046 type confusion bug is under active attack; patch to 152.0.7977.82 now, not later.
#5
Two SonicWall SMA 1000 zero-days chained: one unauthenticated SSRF opens the door, one command injection walks right through to full device takeover.
#6
The CAPTCHA is the con: TerminalFix tricks victims into pasting a PowerShell command that daisy-chains DLL sideloading, PNG-hidden payloads, and AD recon into a Python reverse-tunnel backdoor.

Top MITRE ATT&CK TTPs

Top TTPs (unordered)
T1059: Command and Scripting Interpreter
T1190: Exploit Public-Facing Application
T1588: Obtain Capabilities
T1588.006: Vulnerabilities
T1082: System Information Discovery
T1036: Masquerading
T1505: Server Software Component
T1027: Obfuscated Files or Information
T1547: Boot or Logon Autostart Execution
T1189: Drive-by Compromise
T1543: Create or Modify System Process
T1204: User Execution
T1105: Ingress Tool Transfer
T1068: Exploitation for Privilege Escalation
T1572: Protocol Tunneling
T1070: Indicator Removal
T1546: Event Triggered Execution
T1566: Phishing
T1564: Hide Artifacts
T1102: Web Service

Attacks Executed

NameTypeOverviewDelivery MethodAssociated Actor
NodeRabbitRATA cross-platform Node.js RAT and Mirage Kitten’s first Node.js implant, running on Windows, Linux, and macOS. Launched by a trojanized npm package, it persists by masquerading as legitimate updaters and encrypts C2 traffic with AES-256-GCM. Across three variants it supports up to 23 commands.Trojanized coding-challenge archivesMirage Kitten
PollCatRATA cross-platform RAT written in obfuscated JavaScript, delivered via an OTP-gated React coding challenge. It runs independently of the lure, registers with its C2, and profiles the host against 24 security-vendor directories. It declares 22 commands and persists via scheduled tasks, cron, or LaunchAgents.Trojanized React coding challengeMirage Kitten
Retrograde/MiniFastBackdoorA native Windows DLL backdoor previously attributed to Mirage Kitten, used here as PollCat’s attribution comparator. It shares an identical C2 handshake, host registration, polling logic, and beacon timing, but implements functional UAC elevation and scheduled-task persistence.—Mirage Kitten

Vulnerabilities Exploited

CVE IDNameAffected ProductZero-DayPatch Link
CVE-2026-72529TrueConf Server Missing Authentication for Critical Function VulnerabilityTrueConf server 5.3.X–5.3.9, 5.4.X–5.4.9, 5.5.X–5.5.5 and earlierYestrueconf.com update
CVE-2026-72530TrueConf Server Code Injection VulnerabilityTrueConf server 5.3.X–5.3.9, 5.4.X–5.4.9, 5.5.X–5.5.5 and earlierYestrueconf.com update
CVE-2026-82078PaperCut NG/MF Unsafe Dynamic Class Loading VulnerabilityAll versions of PaperCut NG and PaperCut MFYespapercut.com bulletin
CVE-2026-81578PaperCut NG/MF Authentication Bypass VulnerabilityAll versions of PaperCut NG and PaperCut MFYespapercut.com bulletin
CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicWall SMA 1000 (6210, 7210, 8200v) 12.4.3-03453 and 12.5.0-02835 and olderYespsirt.global.sonicwall.com
CVE-2026-83549SonicWall SMA1000 Appliances OS Command Injection VulnerabilitySonicWall SMA 1000 (6210, 7210, 8200v) 12.4.3-03453 and 12.5.0-02835 and olderYespsirt.global.sonicwall.com
CVE-2026-32475WordPress Elementor Pro Unauthenticated Arbitrary File Upload VulnerabilityWordPress Elementor Pro (before 4.2.2)Yeswordpress.org/plugins/elementor
CVE-2026-85046Google Chrome V8 Type Confusion VulnerabilityGoogle Chrome (before 152.0.7977.82 Linux; before 152.0.7977.82/.83 Windows, macOS)Yeschromereleases.googleblog.com

Adversaries in Action

NameOriginMotiveTarget IndustriesTarget Regions
Mirage Kitten (aka UNC1549, TA455, Smoke Sandstorm, Bohrium, DEV-0056, Yellow Dev 13, Subtle Snail, Nimbus Manticore, Screening Serpens, GalaxyGato)IranInformation theft and espionageAerospace, Aviation, FinTechMiddle East and Africa

Recommendations

01
Prioritize the Eight Exploited Vulnerabilities

This digest can be used to drive security teams to prioritize the eight exploited vulnerabilities and block indicators related to the threat actor Mirage Kitten and malware NodeRabbit, PollCat, and Retrograde/MiniFast.

02
Uni5 Users: Run a Scan

HivePro Uni5 customers can get comprehensive insight into their threat exposure and action it over the Uni5 dashboard by running a scan to discover assets impacted by the eight exploited vulnerabilities.

03
Uni5 Users: Simulate the Attacks

Test the efficacy of security controls by simulating the attacks related to the threat actor Mirage Kitten and malware Retrograde/MiniFast in Breach and Attack Simulation (BAS).


Threat Advisories Referenced This Week


Appendix: Indicators of Compromise (IOCs)

AttackTypeValue
NodeRabbitDomainsnaturalapplication[.]azurewebsites[.]net, retaildemo[.]azurewebsites[.]net, tubitak[.]azurewebsites[.]net, rgbteller[.]azurewebsites[.]net, wslwebui[.]azurewebsites[.]net, plugplay[.]azurewebsites[.]net, crossdwm[.]azurewebsites[.]net, wdisystem[.]azurewebsites[.]net, wslmenus[.]azurewebsites[.]net, dnshnsdev[.]azurewebsites[.]net, hpjumpsrv[.]azurewebsites[.]net, storview[.]azurewebsites[.]net, healthcomfsdpower[.]com, visitfinancedentists[.]com, msmanagementgrp[.]com, msmanagementgrpmedia[.]com
PollCatURL / Domainshxxps[:]//lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate; domains: lifespotify[.]com, gamebarapp[.]azurewebsites[.]net, gamebarappinformation[.]azurewebsites[.]net, sahi-finance[.]com; filenames: RankChallenge-react-6uJSX3-main.zip, requireObject.js
Retrograde/MiniFastMD5 / SHA256810F8E3B88EB05F710C09552941D6F56 / 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864

A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.