Cyber Threat Intelligence Digest: Week 35

2nd September 2026 - Threat Reports
Share
  • Vulnerabilities
  • Potential Threats
  • General News
  • Threat Actor Weekly Graph
  • Global Trends Powered by Recorded Future
  • Prominent Information Security Events
  • Remediation Actions

Executive Summary -
Highlights of Cyber Threat Intelligence Digest

Vulnerabilities

CVE-2026-81166 Allows Access Bypass Affecting Digital Signage Framework - CVE-2026-81166 is a flaw in the Digital Signage Framework module for Drupal, where a route used by signage devices to refresh dynamic blocks fails to verify whether the requester is a signage device or whether the requested block is intended for display delivery. This allows an anonymous visitor to read the rendered content of blocks they were not meant to see. It affects Digital Signage Framework 2.6.0 and prior versions.

Organisations are advised to update to Digital Signage Framework 2.6.1.

Threat Actors Exploit Langflow Vulnerability CVE-2026-0768 - On 29 August 2026, unidentified threat actors began exploiting CVE-2026-0768 in Langflow (versions up to 1.4.2) to conduct reconnaissance and harvest credentials. The flaw is a critical-severity code injection vulnerability caused by improper validation of a user-supplied string in the validate endpoint, enabling threat actors to execute arbitrary code with root privileges.

Telemetry recorded more than 50 exploitation detections, including malicious requests querying environment variables for Langflow superuser values, OpenAI API keys, and AWS access and secret keys. Threat actors also read /root/.cache/langflow/secret_key and checked SSH access and .bash_history size. Source traffic primarily originated from Russia and targeted UK-based systems at the time of writing.

JFrog Authentication Bypass CVE-2026-82329 Exploited in the Wild to Generate Administrator Tokens - On 28 August 2026, JFrog patched an actively exploited authentication bypass vulnerability tracked as CVE-2026-82329, affecting JFrog Artifactory. Successful exploitation allows unauthenticated threat actors with network access to obtain administrative privileges and generate administrator tokens. The threat actor behind the exploitation remains unknown at the time of writing.

To prevent exploitation, organisations are advised to update JFrog Artifactory to the fixed versions listed in JFrog's official advisory.

Potential Threats

Fake Indeed Interview Application Delivers Android Spyware to Job Seekers - On 26 August 2026, researchers identified a fraudulent Indeed job campaign delivering Android spyware to job seekers, with reports from victims in the United Kingdom. Threat actors advertise fake job openings on Indeed and direct victims to sideload malicious Android applications, named MyInterview or Indeed Interview, under the guise of completing an interview, verifying identity, or accessing a recruitment portal; genuine Indeed interviews take place entirely in-browser and never require a separate APK, VPN setup, or invitation code.

Once installed, the applications act as trojan droppers that impersonate Indeed's login page, establish a VPN connection, and install a spyware payload. The malware requests Android Accessibility permission to take control of the device and block removal via Settings, alongside permissions covering clipboard access, package enumeration, screen-capture detection, and VPN service binding.

Silver Fox Campaign Distributes ValleyRAT Through Trojanized Wallpaper Adware - On 31 August 2026, researchers published an analysis of a suspected Silver Fox campaign distributing ValleyRAT through a trojanized version of QN Wallpaper, a Chinese desktop wallpaper-management adware application. ValleyRAT and associated malware linked to the campaign have been detected over 100,000 times during 2026.

The infection begins with a malicious installer disguised as QN Wallpaper, which performs a decoy action (installing DingTalk or Chrome, or opening a Tencent Meeting download page) while deploying a modified QN Wallpaper application, disabling Windows Defender via the DisableAntiSpyware registry value, and adding autorun persistence. The legitimate, signed QnWallpaper.exe sideloads a malicious libcef.dll, which decrypts and loads an AES-encrypted ValleyRAT payload, establishes Startup-folder persistence via a file-extension association, and attempts privilege escalation through the runas utility. ValleyRAT itself supports keylogging, clipboard theft, screenshot capture, system reconnaissance, remote shutdown/reboot, and download and execution of further payloads via process hollowing.

Magecart E-skimmer Attacker Domain Infects E-commerce Websites - In August 2026, analysts identified nineteen e-commerce websites infected with Magecart e-skimmers attributed to the AcceptCar threat group, which is using the attacker domain paleanchor[.]com to conduct the campaign. The infected websites have received over 586,000 customer visits across their aggregate infection windows, and all purchase attempts made during this period have likely resulted in data theft, increasing downstream fraud risk for affected customers. Fifteen infections linked to paleanchor[.]com remain active as of 1 September 2026.

Magecart e-skimmer infections steal customer financial data during checkout transactions, posing financial fraud risks to card issuers whose customers transact with compromised websites. Attacker domains such as this are used by Magecart operators to deliver malicious payloads to compromised e-commerce sites and/or exfiltrate stolen card data.

General News

Papercut releases emergency patch for exploited flaws - On 28 August 2026, PaperCut released a second emergency patch for two actively exploited vulnerabilities in its PaperCut NG and MF print management software, after researchers found multiple ways to bypass the initial fix. The flaws affect PaperCut NG/MF versions 24, 25 and 26 on Windows, Linux and macOS, and can be chained to bypass authentication and achieve remote code execution.

Huntress has observed exploitation in several customer environments; PaperCut is urging all customers to apply Release 2, even if the first patch is already installed, and to restrict web interface access to trusted IP addresses pending patching.

Microsoft Defender flags legitimate Google search links as malicious -  On 2 September 2026, Microsoft confirmed an ongoing issue in which Defender for Office 365 Safe Links is mistakenly classifying legitimate Google search URLs as malicious. Affected users are shown "Opening this website might not be safe" warnings when attempting to open blocked links, and pasting the URL directly into a browser does not bypass the block.

The root cause is an inaccurate security classification within Safe Links, which rewrites inbound links and performs time-of-click verification across email, Teams and Office 365 apps for tenants with a Defender for Office 365 licence. As a side effect, administrators may see related detection alerts appearing in the Defender portal and in Microsoft Sentinel that do not reflect genuine malicious activity. Microsoft has not disclosed the scope of affected regions or tenants and has classified the incident as an advisory, indicating limited impact, while it works on a fix to the misclassification.

SonicWall warns of activiely exploited SMA100 zero-day flaws - On 2 September 2026, SonicWall warned customers that threat actors are actively chaining two new zero-day vulnerabilities in the SMA1000 secure remote access appliance to achieve remote code execution. The flaws affect the SMA1000 6210, 7210 and 8200v models, but do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series.

SonicWall has urged customers to upgrade to the hotfix release as a matter of priority, and where indicators of compromise are found, to re-image affected appliances, reset all user and administrator passwords, and reset TOTP tokens.

Threat Actor Weekly Graph

Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.

Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.

Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.

Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

 

● Limited Severity ● Basic Severity ● Moderate Severity ● High Severity
Threat Actor Severity Increase Opportunity Intent
Sandworm Team ● High → ● High ● 79 → ● 99 ● 25 → ● 25
RedGolf ● High → ● High ● 79 → ● 99 ● 25 → ● 25
APT37 ● High → ● High ● 81 → ● 99 ● 25 → ● 25
BlueDelta ● High → ● High
● 82 → ● 99 ● 30 → ● 30
CL0P ● High → ● High ● 84 → ● 99 ● 49 → ● 49

Global Trends Powered by Recorded Future

Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.

The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.

▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.

Attackers Methods Vulnerabilities Targets
FulCrumSec ▲ DDoS ▲ CVE-2026-0768 ▲ NovoCure ▲
KryBit ▲ Rhysida ▲ CVE-2026-83549 ▲ Berlin ▲
ShinyHunters ▲ Brain Cipher ▲ CVE-2021-31866 ▲ Huobi ▲
Iran ▲

Anubis Ransomware

▲ CVE-2026-81578 ▲ Manchester Airport ▲
RipperSec ▲ DarkVNC ▲ CVE-2026-83548 ▲ Pocket Bitcoin ▲  

 

Prominent Information Security Events

Fake Indeed Interview Application Delivers Android Spyware to Job Seekers

Source: Insikt Group | Validated Intelligence Event

IOC: Domain - startcareer[.]org

IOC: Domain - c375d8a2af5e53fc8e2ca948a5300d567581eebaf311aae5a2e3986b46765dc5

On 26 August 2026, researchers reported a fraudulent Indeed job campaign delivering Android spyware to job seekers, with reports from victims in the United Kingdom and Brazil, alongside discussions on Reddit describing similar compromises. Indeed is one of the world's largest employment websites, giving the threat actors behind the campaign access to a large pool of potential victims in a competitive job market. Threat actors advertise fake job openings on the platform and, after an applicant's interview is confirmed, direct them to sideload a malicious Android application named MyInterview or Indeed Interview, using lures such as completing an interview, updating the Indeed app, verifying identity, or accessing a recruitment portal or salary agreement. In one reported workflow, a supposed recruitment firm instructed the victim to install the app, connect to a VPN, create an account, enter an invitation code, and keep the app open while awaiting confirmation. Genuine Indeed interviews take place entirely within a browser and never require a separate APK, VPN setup, or invitation code; the company's official app, Indeed Job Search, is distributed solely through Google Play.

Once installed, the malicious applications impersonate Indeed's login page and establish a VPN connection after the victim enters an email address, a step with no legitimate purpose in an interview tool and one that could allow the threat actors to route traffic through their own infrastructure or conceal further malicious activity. Static analysis identified the apps as trojan droppers, capable of installing additional untrusted applications rather than acting as the final payload themselves; at the time of writing, the dropped payload was spyware. The malware requests Android Accessibility permission, which grants it visibility over screen content and the ability to act on the victim's behalf, and uses this to take control of the device and block removal: when a victim selects "Uninstall" in Android Settings, the malware forces the screen back to prevent the process completing. One victim reported apps closing by themselves after installation, with the offending package listed (though disabled) under Android's downloaded Accessibility services.

SilverFox Campaign Distributes ValleyRAT Through Trojanized Wallpaper Adware

Source: Insikt Group | Validated Intelligence Event

IOC: IP: 103.45.66.18

IOC: Hash: ecb49d10339b90d079e06e50470ae1c42764158ed1489c9cec31102a852cd6d1

On 31 August 2026, researchers published an analysis of a suspected Silver Fox campaign distributing the ValleyRAT backdoor through a trojanized version of QN Wallpaper, a Chinese desktop wallpaper-management adware application that legitimately displays adverts and installs bundled partner apps. ValleyRAT and associated malware linked to the campaign have been detected over 100,000 times during 2026, affecting more than 1,500 unique users, primarily in China and India; the attribution to Silver Fox is based on the campaign's geography and its use of ValleyRAT. The infection begins when a victim runs a malicious installer disguised as QN Wallpaper, which performs a decoy action determined by its filename, such as installing DingTalk or Google Chrome, or opening a Tencent Meeting download page, while covertly deploying a modified QN Wallpaper build, disabling Windows Defender via the DisableAntiSpyware registry value, and adding the application to Windows autorun.

The legitimate, signed QnWallpaper.exe carries a dependency on libcef.dll, causing it to automatically sideload a malicious version of that library via DLL sideloading. The malicious libcef.dll establishes persistence by creating a file-extension association and dropping a corresponding file into the Startup directory, checks whether the victim holds Administrator rights and attempts privilege escalation via the runas utility if not, then retrieves and decrypts an AES-encrypted ValleyRAT payload before mapping it into memory and executing it. Once running, ValleyRAT recovers its command-and-control address from an obfuscated configuration string and supports keylogging, clipboard theft and manipulation, screenshot capture, extensive system and security-tool reconnaissance, remote reboot or shutdown, and the download and execution of further payloads via process hollowing in svchost.exe.

Remediation Actions

Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:

  • CVE-2026-81166 (Drupal Digital Signage Framework) - This vulnerability can be remediated by updating to the most recent patch 2.6.1.

  • CVE-2026-0768 (Langflow) - This vulnerability is being actively exploited in the wild to conduct reconnaissance and harvest credentials, and organisations should update to a patched version as a priority.
  • CVE-2026-82329 (JFrog Artifactory) - This vulnerability is being actively exploited in the wild to generate administrator tokens, and can be remediated by updating to the fixed versions listed in JFrog's official advisory.

If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.