31th August – Threat Intelligence Report - Check Point Research
This weekly threat intelligence report covers multiple active breaches, AI-related threats, and critical vulnerability disclosures. PaperCut, ServiceNow, Vercel Next.js, and Ubiquiti all released patches for critical vulnerabilities, several rated CVSS 10.0, with PaperCut vulnerabilities actively exploited in the wild. Notable breaches include Manchester Airports Group (8.7 million records exposed), ATF (Qilin ransomware), Boston Scientific (operational disruption), and McKesson (ShinyHunters exfiltrated 1TB via Okta vishing). Threat actor activity includes expanded toolsets from Iran-linked Nimbus Manticore and China-linked QTFY infrastructure disruption by U.S. authorities.
- cveCVE-2026-18885Code injection vulnerability rated CVSS 10.0 allowing unauthenticated attackers to execute code.
- cveCVE-2026-18886Access control vulnerability rated CVSS 10.0 allowing unauthenticated attackers to escalate privileges.
- cveCVE-2026-74820SQL injection vulnerability rated CVSS 10.0 allowing unauthenticated attackers to access and modify instance data.
- cveCVE-2026-75604Windows-specific path traversal flaw that can result in unauthenticated remote code execution under affected configurations.
- cveCVE-2026-81578Authentication bypass vulnerability rated CVSS 8.8 that can be chained with CVE-2026-82078 for unauthenticated remote code execution.
- cveCVE-2026-82078Unsafe class loading vulnerability rated CVSS 9.4 that enables unauthenticated remote code execution when chained with CVE-2026-81578.
Detection / Hunteropenrouter
What Happened
Several organizations including airports, a U.S. federal agency, and healthcare companies were hit by cyberattacks this week, exposing millions of customer records and disrupting operations. A hacking group called ShinyHunters used phone-based deception (pretending to be legitimate callers) to break into a healthcare company's cloud accounts and steal data on 284 million patients. On the vulnerability side, multiple software vendors issued urgent fixes for serious security holes. PaperCut, ServiceNow, Next.js, and Ubiquiti all had critical flaws patched, some allowing attackers to take over systems without needing a password. Organizations using any of these products should apply the available patches immediately. Separately, researchers highlighted new risks in AI tools where hidden malicious instructions can bypass safety controls, and U.S. authorities disrupted Chinese infrastructure used to target government agencies.
Key Takeaways
- PaperCut released emergency fixes for two actively exploited vulnerabilities (CVE-2026-81578, CVE-2026-82078) that can be chained for unauthenticated remote code execution on PaperCut NG and MF servers.
- ServiceNow patched three CVSS 10.0 vulnerabilities in its AI Platform allowing unauthenticated code injection, privilege escalation, and SQL injection.
- Vercel fixed two critical Next.js vulnerabilities including a Windows-specific path traversal (CVE-2026-75604) and an AVIF image-processing flaw with a public proof-of-concept available.
- ShinyHunters claimed responsibility for a McKesson breach using vishing to compromise Okta accounts and exfiltrate approximately 1TB of data containing 284 million patient-related records.
- Iran-linked Nimbus Manticore expanded its toolset with an SSH tunneling utility and a C++ backdoor resembling TWOSTROKE for persistent access against Middle East and European organizations.
Affected Systems
- PaperCut NG and MF servers
- Ubiquiti UniFi Protect, Network, Access, Talk, UniFi OS, and other Ubiquiti products
- Next.js versions prior to 15.5.24 and 16.3.3 on Windows
- ServiceNow AI Platform instances
- Amazon Kiro versions prior to 0.8.140
- Okta identity management platform
- Salesforce and Snowflake cloud platforms
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-81578 | PaperCut NG and MF | High | Authentication bypass vulnerability rated CVSS 8.8 that can be chained with CVE-2026-82078 for unauthenticated remote code execution. |
| CVE-2026-82078 | PaperCut NG and MF | Critical | Unsafe class loading vulnerability rated CVSS 9.4 that enables unauthenticated remote code execution when chained with CVE-2026-81578. |
| CVE-2026-75604 | Next.js (Vercel) | Critical | Windows-specific path traversal flaw that can result in unauthenticated remote code execution under affected configurations. |
| CVE-2026-18885 | ServiceNow AI Platform | Critical | Code injection vulnerability rated CVSS 10.0 allowing unauthenticated attackers to execute code. |
| CVE-2026-18886 | ServiceNow AI Platform | Critical | Access control vulnerability rated CVSS 10.0 allowing unauthenticated attackers to escalate privileges. |
| CVE-2026-74820 | ServiceNow AI Platform | Critical | SQL injection vulnerability rated CVSS 10.0 allowing unauthenticated attackers to access and modify instance data. |
Attack Chain
- Initial Access: ShinyHunters used vishing (voice phishing) to compromise Okta accounts at McKesson, gaining access to Salesforce and Snowflake platforms.
- Exfiltration: Approximately 1TB of data containing 284 million patient-related records was exfiltrated from McKesson's third-party applications.
- Initial Access: Qilin ransomware group compromised a standalone ATF computer containing investigation target information.
- Impact: ATF system was disconnected; Qilin listed the agency on its leak site claiming responsibility.
- Initial Access: Chinese threat actor exploited known ownCloud and WordPress vulnerabilities to compromise Philippine nuclear research and marine engineering organizations.
- Exfiltration: Attackers obtained reactor-related records, employee information, and credentials from compromised Philippine organizations.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules, queries, or signatures are provided in this article. The article is a summary-style threat intelligence bulletin covering multiple incidents and vulnerabilities.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | The article does not describe specific endpoint behaviors, file artifacts, or process execution patterns that EDR could detect. The breaches described involve cloud platform compromise (Okta, Salesforce, Snowflake) and network appliance exploitation, which are outside typical EDR telemetry scope. |
| Network Visibility | Medium | The article mentions SSH tunneling by Nimbus Manticore and exploitation of public-facing applications (PaperCut, ownCloud, WordPress, ServiceNow). Network monitoring for anomalous SSH sessions and exploitation attempts against these services could provide detection value. |
| Detection Difficulty | Hard | The article describes diverse attack vectors across cloud platforms, network appliances, and on-premises applications. No specific IOCs, hashes, or behavioral indicators are provided. Detection would require environment-specific baselining and correlation across multiple log sources. |
Required Log Sources
- Okta authentication logs
- Salesforce audit logs
- Snowflake access logs
- PaperCut NG/MF application logs
- ServiceNow platform logs
- Web application firewall logs
- SSH session logs
- Network flow data
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for anomalous authentication patterns in Okta logs, such as successful logins from unusual geographic locations or IP addresses followed by access to Salesforce or Snowflake, which may indicate vishing-driven credential compromise similar to the McKesson breach. | Okta System Log events, Salesforce login history, Snowflake query history | Initial Access / Credential Access | Medium — legitimate users traveling or using VPNs may trigger geographic anomaly alerts. |
| Consider hunting for exploitation attempts against PaperCut NG and MF servers, particularly requests targeting authentication bypass and class loading endpoints associated with CVE-2026-81578 and CVE-2026-82078. | PaperCut application logs, reverse proxy logs, WAF logs | Initial Access | Low — exploitation attempts against these specific endpoints are unlikely to occur in normal usage. |
| Consider hunting for unauthorized SSH tunneling activity from systems in the Middle East or Europe, particularly persistent outbound SSH connections to unfamiliar destinations, which may indicate Nimbus Manticore activity. | Network flow logs, SSH authentication logs, endpoint network connection logs | Command and Control | Medium — legitimate administrative SSH tunneling is common in enterprise environments. |
| Consider hunting for exploitation of known ownCloud and WordPress vulnerabilities targeting sensitive government or research organizations, particularly requests attempting to access credential stores or sensitive document repositories. | Web server access logs, WAF logs, CMS application logs | Initial Access / Exfiltration | Low to Medium — vulnerability scanners may trigger some alerts. |
| Consider hunting for anomalous data access patterns in ServiceNow instances, particularly unauthenticated requests targeting code injection, SQL injection, or privilege escalation endpoints associated with CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. | ServiceNow platform logs, web application firewall logs, reverse proxy access logs | Initial Access / Privilege Escalation | Low — unauthenticated access to these endpoints is abnormal. |
Control Gaps
- Cloud platform authentication monitoring (Okta, Salesforce, Snowflake) may not be correlated with on-premises SIEM pipelines, delaying detection of vishing-driven account compromise.
- Network appliance and IoT device exploitation (Ubiquiti, internet-connected devices targeted by QScan) may fall outside standard EDR and network monitoring coverage.
- AI assistant platforms with browsing and code execution capabilities lack established detection controls for cryptographic context injection attacks.
- Voice phishing (vishing) attacks bypass email-based security controls and may not be covered by existing security awareness training focused on email phishing.
Key Behavioral Indicators
- Successful Okta authentication events immediately followed by bulk data access in Salesforce or Snowflake from the same session
- Unauthenticated HTTP requests targeting PaperCut class loading or authentication endpoints
- Persistent outbound SSH connections from endpoints in Middle Eastern or European organizations to previously unseen destinations
- HTTP requests exploiting known ownCloud or WordPress CVEs targeting government or research sector organizations
- Unauthenticated requests to ServiceNow AI Platform endpoints associated with code injection or SQL injection
False Positive Assessment
Low — the vulnerabilities described have specific exploitation patterns and the breaches involve confirmed incidents. However, the article does not provide specific IOCs for detection, so environment-specific tuning would be required for any detection logic developed from these findings.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider prioritizing patching of PaperCut NG and MF servers for CVE-2026-81578 and CVE-2026-82078, as these are actively exploited in the wild.
- If your organization uses ServiceNow AI Platform, consider applying patches for CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 immediately, as all are rated CVSS 10.0 and allow unauthenticated exploitation.
- If your organization runs Next.js on Windows, consider upgrading to version 15.5.24 or 16.3.3 to address CVE-2026-75604 and the AVIF image-processing vulnerability, noting that a public proof-of-concept exists for the AVIF issue.
- If your organization uses Ubiquiti products, consider reviewing and applying the 21 patched vulnerabilities across UniFi product lines, several of which received CVSS 10.0 scores.
- If your organization uses Amazon Kiro, consider verifying that version 0.8.140 or later is installed to address the prompt injection vulnerability.
Infrastructure Hardening
- Consider implementing network-level access restrictions for PaperCut, ServiceNow, and other public-facing application management interfaces to limit exposure to unauthenticated exploitation.
- Evaluate whether Ubiquiti device management interfaces should be segmented from general network access, particularly for devices receiving CVSS 10.0 vulnerability fixes.
- Consider implementing conditional access policies for Okta accounts that require additional verification for access to Salesforce, Snowflake, or other high-value SaaS applications.
- If applicable, consider deploying WAF rules to detect and block exploitation attempts targeting the specific PaperCut, ServiceNow, and Next.js vulnerability endpoints described.
User Protection
- Consider reviewing and strengthening vishing protections, including caller verification procedures for employees with access to cloud platform administration tools.
- If your organization uses AI assistants with browsing and code execution capabilities, consider evaluating whether cryptographic context injection poses a risk to sensitive conversation data.
- Consider implementing MFA enforcement for all Okta accounts, particularly those with access to Salesforce, Snowflake, or other data-rich SaaS platforms.
Security Awareness
- Consider incorporating vishing awareness training into existing security awareness programs, emphasizing that attackers may impersonate IT staff to obtain Okta or SaaS credentials via phone.
- If applicable, consider educating users about the AnonyMousKIT phishing-as-a-service operation targeting iPhone owners via email, SMS, WhatsApp, and AI-generated voice calls to steal Apple IDs and 2FA codes.
- Consider reminding users not to open unfamiliar project files in AI development environments like Amazon Kiro, as crafted workspace files could exploit prompt injection vulnerabilities.