Executive Summary -
Highlights of Cyber Threat Intelligence Digest
Vulnerabilities
CVE-2026-71173 Allows Path Traversal Affecting Dell Cloud Disaster Recovery - CVE-2026-71173 is a path traversal flaw in Dell Cloud Disaster Recovery, where the application fails to properly validate and sanitise user-supplied file paths before using them to access files on the system. This allows an attacker to supply crafted path input that traverses outside the intended restricted directory and reaches files and locations they were not meant to access. It affects Dell Cloud Disaster Recovery 20.2 and prior versions.
Organisations are advised to update to Dell Cloud Disaster Recovery 20.3.
Google Patches Actively Exploited Type Confusion Vulnerability CVE-2026-85046 in Chrome V8 - On 4 September 2026, Google released security updates addressing 12 vulnerabilities in Chrome, including CVE-2026-85046, a high-severity type confusion flaw in the V8 JavaScript and WebAssembly engine that was already being exploited in the wild. The flaw carries a CVSS score of 8.8 and allows a remote attacker to execute arbitrary code inside the sandbox through a crafted HTML page, affecting versions prior to 152.0.7977.82. It was reported by security researcher Salvatore Gulizia on 4 August 2026 and marks the sixth actively exploited Chrome zero-day addressed this year.
Google acknowledged that an exploit exists in the wild but withheld details of the attacks and attribution to allow users time to patch. On 4 September 2026, CISA added the flaw to its Known Exploited Vulnerabilities catalogue, requiring federal agencies to patch by 18 September 2026.
Users are advised to update Chrome to 152.0.7977.82/.83 on Windows and macOS, and to 152.0.7977.82 on Linux.
CVE-2026-80256 Allows Path Traversal Affecting wcurl - On 2 September 2026, the curl project published an advisory for CVE-2026-80256, a medium-severity path traversal vulnerability affecting wcurl on Windows. Successful exploitation allows an attacker to create an attacker-controlled file outside the directory the user chose, because per cent-encoded backslashes are decoded, causing the output file to be saved in a different folder from the one wcurl was invoked from. The issue is limited to Windows and depends on the user's filesystem permissions and the target file not already existing. It was reported on 25 August 2026, and there is no indication of exploitation in the wild at the time of writing.
To prevent exploitation, organisations are advised to upgrade to wcurl 2026.08.30 (as shipped in curl 8.22.0), apply the patch to their local wcurl version, or explicitly set an output filename or disable per cent-decoding as a workaround.
Potential Threats
Threat Actors Use Evilginx2-Based BigBear 2.0 PhaaS Framework to Hijack Microsoft 365 Sessions Across 461 Organisations - On 7 September 2026, CloudSEK published a report on BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation first identified in June 2026 that targets hundreds of organisations across more than 40 countries and remains active. Threat actors, led by an operator using the alias "General Boss", run a rebranded Evilginx2 adversary-in-the-middle framework leased to at least five affiliates, proxying victims to the legitimate Microsoft login portal while capturing every credential and session cookie in transit; the operation has exfiltrated 5,137 records, including 474 fully MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies.
Once a victim authenticates, the framework intercepts the Microsoft-issued session cookie and replays it to gain persistent access to mailboxes, Teams, and SharePoint without re-authentication. Custom JavaScript injections disable FIDO2/WebAuthn to force victims onto weaker MFA, block Microsoft anti-phishing telemetry, and auto-enable "Keep Me Signed In", while geo-matched residential proxies defeat geo-anomaly detection and researcher analysis.
Toy Ghouls Deploys Custom Backdoors Using HiveMQ and Element for C2 - On 4 September 2026, Kaspersky GERT published an analysis of the Toy Ghouls group (also tracked as Bearlyfy, Laboo.boo, and Feral Wolf) that deployed two custom Windows backdoors against Russian organisations, following its first observation of the malware in early July 2026. The financially motivated group has targeted Russian organisations since 2025, previously relying on public GitHub tools and leaked Babuk and LockBit ransomware builders before developing its own GenieLocker ransomware and, now, these backdoors.
The two versions, internally named mqtt-bird-agent and matrix-bird-agent, route command traffic through legitimate services: one connects to the public HiveMQ MQTT broker and executes commands via hidden PowerShell, while the other communicates through an attacker-controlled Element (Matrix) server and waits for messages prefixed with "cmd:" from an account named panel-bot. Delivered to already-compromised systems via Windows Remote Management using Evil-WinRM and WinRM-fs, the backdoors register under service names that impersonate Windows components (cplsupport and wtas) and gather host reconnaissance, such as public IP, hostname, and disk usage. Sensitive configuration fields are encrypted with ChaCha20-Poly1305 using a key derived from the Windows MachineGuid, with the Element version storing them in the registry after deleting the original file.
Threat Actor Uses Compromised Mailbox to Deliver Suspected LLM-Generated Lure - On 3 September 2026, Invictus Incident Response published an analysis of a business email compromise (BEC) phishing campaign in which a threat actor sent a lure from a compromised but legitimate grocery retailer mailbox, thereby inheriting the sender reputation trusted by email gateways. The email, assessed as highly likely AI-generated, carried the subject "Urgent Review Required - Purchase Order and Invoice Discrepancies" and linked to a two-stage chain: a fake "RFP Access Portal" hosted on AWS S3 that forwarded victims to purchasesord[.]com, a Cloudflare-fronted domain first seen on 25 August 2026, ending in a fake Google sign-in page that exfiltrated credentials via socket.io. Pivoting surfaced related domains such as accessdocuments[.]us, assessed as likely malicious with low confidence of attribution.
BEC campaigns of this kind pose a financial fraud risk by harvesting valid credentials and session tokens to hijack accounts and manipulate payment processes. Compromised mailboxes and abused cloud services such as AWS S3 and Cloudflare deliver lures with inherited trust and host credential-harvesting infrastructure that evades reputation-based filtering. Organisations are advised to enforce phishing-resistant MFA using passkeys or FIDO2 keys, restrict third-party OAuth access to Workspace data, and verify payment changes out of band rather than via email.
General News
Dropbox Discloses Data Breach Through Lenovo Email Verification Flaw - On 2 September 2026, Dropbox began warning users that an unauthorised party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. Dropbox uses Lenovo Identity Provider Services in its authentication infrastructure, and the flaw allowed an attacker to register a Lenovo ID with a victim's email address and log in to the Dropbox account tied to it without the account password, because Dropbox trusted Lenovo's assertion of email control without confirming it via the existing Dropbox login. The access took place between 4 and 21 August 2026, affecting approximately 5,000 accounts, with the attacker viewing and downloading content from some of them.
Account-takeover incidents of this kind pose a risk of data theft and downstream fraud, as attackers gain full access to stored files without requiring the victim's credentials. Legacy or overly trusting identity federation integrations, such as the Lenovo ID link abused here, can bypass primary authentication entirely. Dropbox has expired all sessions authenticated through Lenovo IDs and now requires users to enter their Dropbox password when authenticating via a Lenovo ID; affected users are advised to change their passwords and enable two-factor authentication.
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities - On 5 September 2026, the Arctic Wolf Adversary Research Team reported active exploitation of two recently disclosed PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain, in attacks targeting the education sector across the United States and Europe. The campaign has affected vulnerable PaperCut servers at organisations ranging from K-12 schools to major universities, with threat actors using the chain to run commands, conduct reconnaissance, and create privileged accounts such as "Administrator17".
Observed post-exploitation activity includes discovery commands such as whoami and tasklist, and the delivery of credential-harvesting tools, including lsa_collect.exe and save_hives.exe, via certutil.exe from 45.142.193[.]132, retrieval of Meterpreter Java payloads from 194.180.48[.]134, and use of findstr to search PaperCut config files for terms such as "password", "secret", and "ldap". One tool was observed reconstructing the system BootKey to access the SAM database, raising the risk that stolen credentials open a pathway into other critical systems. Organisations are advised to restrict PaperCut servers from internet exposure and monitor for command interpreters and discovery commands spawned with pc-app.exe as the parent process.
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two are being exploited - On 8 September 2026, Microsoft released its September Patch Tuesday update addressing a record 973 vulnerabilities, the first time the monthly total has surpassed 900. CISA confirmed that two of them, CVE-2026-81963 and CVE-2026-85880, are being actively exploited, affecting a Windows update installation component and a Windows messaging system, respectively, and has given federal agencies until 22 September to patch.
Microsoft has urged customers to apply the updates as a priority, with particular concern around CVE-2026-81963, which researchers warn can serve as the first step in a ransomware chain by allowing an attacker who controls the update stack to escalate privileges and resist remediation; over 22,000 corporate Exchange servers also remain unpatched against weaponised exploit code.
Threat Actor Weekly Graph
Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.
Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.
Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.
Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

| ● Limited Severity | ● Basic Severity | ● Moderate Severity | ● High Severity |
| Threat Actor | Severity Increase | Opportunity | Intent | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Sandworm Team | ● High | → | ● High | ● 79 | → | ● 99 | ● 25 | → | ● 25 |
| APT37 | ● High | → | ● High | ● 80 | → | ● 99 | ● 25 | → | ● 25 |
| BlueDelta | ● High | → | ● High | ● 82 | → | ● 99 | ● 30 | → | ● 30 |
| CL0P Ransomware Group (FANCYCAT) | ● High | → | ● High |
● 84 | → | ● 99 | ● 49 | → | ● 49 |
| RedGolf | ● High | → | ● High | ● 79 | → | ● 89 | ● 25 | → | ● 25 |
Global Trends Powered by Recorded Future
Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.
The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.
▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.
| Attackers | Methods | Vulnerabilities | Targets | |||||
|---|---|---|---|---|---|---|---|---|
| Dark Storm Team | ▲ | DDoS | ▲ | CVE-2026-87491 | ▲ | Liquid Global | ▲ | |
| Morocco | ▲ | Play Ransomware | ▲ | CVE-2026-85880 | ▲ | Quoine Pte Ltd | ▲ | |
| ShinyHunters | ▲ | Safepay Ransomware | ▲ | CVE-2026-81963 | ▲ | Boston Scientific | ▲ | |
| Chinese Hackers | ▲ | Stealware | ▲ | CVE-2026-75650 | ▲ | Баланс продавца (New) | ▲ | |
| Malone Lam | ▲ | Trial_recovery | ▲ | CVE-2026-86218 | ▲ | Mathspace | ▲ | |
Prominent Information Security Events
Threat Actors Use Evilginx2-Based BigBear 2.0 PhaaS Framework to Hijack Microsoft 365 Sessions Across 461 Organisations
Source: Insikt Group | Validated Intelligence Event
IOC: Domain - haliotisbar[.]com
IOC: IP - 107.191.46.14
On 7 September 2026, CloudSEK published a report on BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation first identified in June 2026, which remains active and targets hundreds of organisations across more than 40 countries. Microsoft 365 is one of the world's most widely used enterprise platforms, giving the operators access to a vast pool of potential victims. Run by an actor using the alias "General Boss", it is a rebranded Evilginx2 adversary-in-the-middle framework leased to at least five affiliates, each of which receives stolen credentials in real time via Telegram bots. Victims are sent phishing links that proxy their traffic to the legitimate Microsoft login portal, so the page they see is real while every credential and session cookie passes through the attacker's reverse proxy; the "offy" phishlet targets the OAuth 2.0 flow, making it effective against any organisation using Azure AD / Entra ID. To date, the operation has exfiltrated 5,137 records, including 474 fully MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, with India, France, and Saudi Arabia among the most targeted.
Once a victim authenticates, the framework intercepts the Microsoft-issued session cookie before it reaches the browser and replays it to gain persistent access to mailboxes, Teams, and SharePoint without re-authentication, while captured refresh tokens extend that access well beyond the initial expiry. Custom JavaScript injections disable FIDO2/WebAuthn to force victims onto weaker MFA, block Microsoft anti-phishing telemetry, and auto-enable "Keep Me Signed In". Geo-matched residential proxies across 69 countries defeat geo-anomaly detection and conditional access, while ipapi.is integration blocks data centre and VPN addresses to frustrate researchers' analysis.
Toy Ghouls Deploys Custom Backdoors Using HiveMQ and Element for C2
Source: Insikt Group | Validated Intelligence Event
IOC: Domain - meet[.]element[.]tw
IOC: Hash - 7916c33688385525078bee504c90f359
On 4 September 2026, Kaspersky GERT published an analysis of two custom Windows backdoors deployed by the financially motivated Toy Ghouls group (also tracked as Bearlyfy, Laboo.boo, and Feral Wolf) against Russian organisations, having first observed the malware in early July 2026. The group has targeted Russian organisations since 2025, previously relying on public GitHub tools and leaked Babuk and LockBit ransomware builders before developing its own GenieLocker ransomware and, now, these bespoke backdoors, a shift toward privately developed tooling. Kaspersky did not identify the affected organisations, state how many systems were compromised, or disclose how the attackers first gained access. The two versions, internally named mqtt-bird-agent and matrix-bird-agent, were delivered to already-compromised systems via Windows Remote Management using Evil-WinRM and WinRM-fs, and each can run interactively or install itself as a Windows service under names impersonating legitimate components, "Problem Reports Control Panel" (cplsupport) and "Windows Telemetry Aggregator Service" (wtas).
Both backdoors route command traffic through legitimate communication services rather than dedicated infrastructure, letting malicious activity blend with normal business traffic. The HiveMQ version connects to the public broker at broker.hivemq.com to report status, collect commands, and return results, executing instructions through hidden PowerShell; the Element version communicates through an attacker-controlled Matrix server, awaiting messages prefixed with "cmd:" from an account named panel-bot. On first run, each contacts ip-api.com to obtain the host's public IP and country, and gathers reconnaissance, including hostname, processor load, and disk usage. Sensitive configuration fields are encrypted with ChaCha20-Poly1305 using a key derived from the Windows MachineGuid, and the Element version deletes the original configuration file and stores the encrypted settings in the registry. Neither HiveMQ nor Element was breached; the operators abused HiveMQ's public broker and ran their own Element server.
Remediation Actions
Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:
-
CVE-2026-71173 (Path traversal flaw in Dell Cloud Disaster Recovery) - This vulnerability can be remediated by updating to the most recent patch Version CDR 20.3
- CVE-2026-85046 (High-severity type confusion flaw in the V8 JavaScript and WebAssembly engine) - This vulnerability is being actively exploited in the wild, and organisations should update to a patched version as a priority to 152.0.7977.82/.83 on Windows and macOS and to 152.0.7977.82 on Linux.
-
CVE-2026-80256 (Path traversal vulnerability affecting wcurl) - This vulnerability, when successfully exploited, allows an attacker to create an attacker-controlled file outside the directory the user chose, causing the output file to be saved in a different folder from the one wcurl was invoked from. Organisations are advised to update to wcurl 2026.08.30 to remediate this issue.
If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.