HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, three major attacks were detected, eight vulnerabilities were actively exploited, and one threat actor group was closely monitored, signaling a concerning escalation in malicious activity worldwide.
On the vulnerability front, SonicWall confirmed active exploitation of two zero-days in its Secure Mobile Access (SMA) 1000 series. CVE-2026-83548, a maximum-severity flaw in the Work Place interface, lets unauthenticated attackers reach sensitive internal functions through server-side request forgery, while CVE-2026-83549 lets an already-logged-in administrator run arbitrary commands via the Appliance Management Console. SonicWall caught both internally and has already shipped hotfixes. Google, meanwhile, patched a high-severity type confusion bug in Chrome’s V8 engine, CVE-2026-85046, that was also being exploited in the wild — a compiler bug affecting Maglev and TurboFan that gave attackers arbitrary read/write access to the JavaScript heap through nothing more than a crafted webpage.
On the threat-actor side, the Iran-linked group Mirage Kitten (aka Nimbus Manticore) is running a recruitment-themed campaign against aviation, aerospace, and FinTech professionals across the Middle East and Africa, posing as recruiters on LinkedIn and job boards to hand out trojanized coding-challenge files that quietly install two new cross-platform RATs, NodeRabbit and PollCat, capable of remote access, credential theft, and data exfiltration. Separately, a ClickFix-style campaign dubbed TerminalFix tricks victims with a fake Cloudflare CAPTCHA into pasting a PowerShell command that ultimately sideloads malware, sets up persistence, maps out the Active Directory environment, and opens a hidden proxy tunnel for the attacker. Together, these incidents point to a clear pattern: attackers are blending technical exploits with social engineering, making timely patching, vigilant monitoring, and layered defenses more essential than ever.
High-Level Statistics
3 Attacks Executed · 8 Vulnerabilities Exploited · 1 Adversary in Action
Insights
CVE-2026-32475 lets attackers upload a PHP file through a contact form and run it as code, with 10M+ WordPress sites in the blast radius.CVE-2026-85046 type confusion bug is under active attack; patch to 152.0.7977.82 now, not later.Top MITRE ATT&CK TTPs
Attacks Executed
| Name | Type | Overview | Delivery Method | Associated Actor |
|---|---|---|---|---|
| NodeRabbit | RAT | A cross-platform Node.js RAT and Mirage Kitten’s first Node.js implant, running on Windows, Linux, and macOS. Launched by a trojanized npm package, it persists by masquerading as legitimate updaters and encrypts C2 traffic with AES-256-GCM. Across three variants it supports up to 23 commands. | Trojanized coding-challenge archives | Mirage Kitten |
| PollCat | RAT | A cross-platform RAT written in obfuscated JavaScript, delivered via an OTP-gated React coding challenge. It runs independently of the lure, registers with its C2, and profiles the host against 24 security-vendor directories. It declares 22 commands and persists via scheduled tasks, cron, or LaunchAgents. | Trojanized React coding challenge | Mirage Kitten |
| Retrograde/MiniFast | Backdoor | A native Windows DLL backdoor previously attributed to Mirage Kitten, used here as PollCat’s attribution comparator. It shares an identical C2 handshake, host registration, polling logic, and beacon timing, but implements functional UAC elevation and scheduled-task persistence. | — | Mirage Kitten |
Vulnerabilities Exploited
| CVE ID | Name | Affected Product | Zero-Day | Patch Link |
|---|---|---|---|---|
CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | TrueConf server 5.3.X–5.3.9, 5.4.X–5.4.9, 5.5.X–5.5.5 and earlier | Yes | trueconf.com update |
CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | TrueConf server 5.3.X–5.3.9, 5.4.X–5.4.9, 5.5.X–5.5.5 and earlier | Yes | trueconf.com update |
CVE-2026-82078 | PaperCut NG/MF Unsafe Dynamic Class Loading Vulnerability | All versions of PaperCut NG and PaperCut MF | Yes | papercut.com bulletin |
CVE-2026-81578 | PaperCut NG/MF Authentication Bypass Vulnerability | All versions of PaperCut NG and PaperCut MF | Yes | papercut.com bulletin |
CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | SonicWall SMA 1000 (6210, 7210, 8200v) 12.4.3-03453 and 12.5.0-02835 and older | Yes | psirt.global.sonicwall.com |
CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | SonicWall SMA 1000 (6210, 7210, 8200v) 12.4.3-03453 and 12.5.0-02835 and older | Yes | psirt.global.sonicwall.com |
CVE-2026-32475 | WordPress Elementor Pro Unauthenticated Arbitrary File Upload Vulnerability | WordPress Elementor Pro (before 4.2.2) | Yes | wordpress.org/plugins/elementor |
CVE-2026-85046 | Google Chrome V8 Type Confusion Vulnerability | Google Chrome (before 152.0.7977.82 Linux; before 152.0.7977.82/.83 Windows, macOS) | Yes | chromereleases.googleblog.com |
Adversaries in Action
| Name | Origin | Motive | Target Industries | Target Regions |
|---|---|---|---|---|
| Mirage Kitten (aka UNC1549, TA455, Smoke Sandstorm, Bohrium, DEV-0056, Yellow Dev 13, Subtle Snail, Nimbus Manticore, Screening Serpens, GalaxyGato) | Iran | Information theft and espionage | Aerospace, Aviation, FinTech | Middle East and Africa |
Recommendations
This digest can be used to drive security teams to prioritize the eight exploited vulnerabilities and block indicators related to the threat actor Mirage Kitten and malware NodeRabbit, PollCat, and Retrograde/MiniFast.
HivePro Uni5 customers can get comprehensive insight into their threat exposure and action it over the Uni5 dashboard by running a scan to discover assets impacted by the eight exploited vulnerabilities.
Test the efficacy of security controls by simulating the attacks related to the threat actor Mirage Kitten and malware Retrograde/MiniFast in Breach and Attack Simulation (BAS).
Threat Advisories Referenced This Week
- Head Mare Chains TrueConf Server Flaws to Drop PhantomCore and PhantomGraph
- PaperCut NG/MF Zero-Day Under Active Exploitation Across All Versions
- Two SMA 1000 Zero-Days Open SonicWall Appliances to RCE
- Mirage Kitten Turns Job Interviews into a Gateway for Corporate Espionage
- One Empty File to Full Takeover: Elementor Pro Under Active Attack
- CVE-2026-85046: Chrome V8 Type Confusion Zero-Day Exploited in the Wild
Appendix: Indicators of Compromise (IOCs)
| Attack | Type | Value |
|---|---|---|
| NodeRabbit | Domains | naturalapplication[.]azurewebsites[.]net, retaildemo[.]azurewebsites[.]net, tubitak[.]azurewebsites[.]net, rgbteller[.]azurewebsites[.]net, wslwebui[.]azurewebsites[.]net, plugplay[.]azurewebsites[.]net, crossdwm[.]azurewebsites[.]net, wdisystem[.]azurewebsites[.]net, wslmenus[.]azurewebsites[.]net, dnshnsdev[.]azurewebsites[.]net, hpjumpsrv[.]azurewebsites[.]net, storview[.]azurewebsites[.]net, healthcomfsdpower[.]com, visitfinancedentists[.]com, msmanagementgrp[.]com, msmanagementgrpmedia[.]com |
| PollCat | URL / Domains | hxxps[:]//lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate; domains: lifespotify[.]com, gamebarapp[.]azurewebsites[.]net, gamebarappinformation[.]azurewebsites[.]net, sahi-finance[.]com; filenames: RankChallenge-react-6uJSX3-main.zip, requireObject.js |
| Retrograde/MiniFast | MD5 / SHA256 | 810F8E3B88EB05F710C09552941D6F56 / 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 |
A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
