Daily Security Intel

Archives
Log in
Subscribe
September 15, 2026

[SecurityIntel] 15 Sep | Red Heron Exploits Gitea RCE Internationally

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, September 15, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Red Heron Exploits Gitea RCE Internationally

CRITICAL

5

C2 IPs

80

OTX IOCs

35

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the exploitation of a Gitea remote code execution vulnerability by threat actor Red Heron, alongside active exploitation of JFrog Artifactory flaws to deploy backdoors. Additionally, hardware-level vulnerabilities like DDRop threaten confidential computing environments on Intel and AMD processors, while social engineering attacks successfully tricked Revolut into releasing sensitive customer data via fraudulent emergency requests.

■ CRITICAL STORIES

CRITICAL#1

Red Heron Exploits Gitea RCE to Compromise 13 Organizations

A suspected Chinese threat actor is actively scanning and exploiting a recently disclosed Gitea RCE vulnerability to rapidly compromise internet-facing instances across multiple countries.

HIGH#2

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Researchers have demonstrated a hardware-level attack that bypasses memory protections in confidential computing environments by silently dropping memory writes, allowing processors to read stale encrypted data.

HIGH#3

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Attackers are actively exploiting three vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges to administrator, and deploy persistent backdoors.

INFO#4

Revolut handed customer data to fraudsters using government email account

Fraudsters successfully used social engineering and compromised or spoofed legitimate government email accounts to submit fake emergency data requests, tricking Revolut into disclosing sensitive customer IDs and financial data.

■ CVEs IDENTIFIED

[CVE-TBD]

Gitea — Remote Code Execution (RCE) exploited by Red Heron

Critical

[CVE-TBD]

JFrog Artifactory — Authentication bypass and privilege escalation leading to backdoor deployment

Critical

[CVE-TBD]

Tencent Chinese-language input method editor — One-click remote code execution

Critical

[CVE-TBD]

Intel TDX & AMD SEV-SNP — DDRop hardware memory protection bypass

High

■ THREAT ACTORS

Red Heron

APT (Suspected Chinese)

Exploiting Gitea RCE to compromise 13 organizations globally

Black Axe

Cybercrime Group

Members extradited from South Africa for lucrative romance scams

Hacking Cat

Hacktivist (Pro-Ukraine)

Deploying new malware and destructive attacks against Russian targets

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Red Heron exploiting Gitea RCE; attackers exploiting JFrog Artifactory flaws.
T1133
External Remote Services | Attackers targeting exposed Vite development servers to steal cloud secrets.
T1566
Phishing | Fake government websites in Central Asia collecting contact details; romance scams by Black Axe.
T1114
Email Collection | Telegram Desktop flaw exfiltrating messages from HTML exports.
T1539
Steal Web Session Cookie | Twitch browser extension exfiltrating OAuth session tokens.
T1204.002
User Execution: Malicious File | ClickFix attacks delivered via hijacked HBO Max Reddit account.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Gitea — RCE actively exploited by Red Heron — [THN]

[P1 PATCH NOW]≤24h

JFrog Artifactory — Three flaws exploited for admin privilege escalation and backdoors — [SW]

[P1 PATCH NOW]≤24h

Tencent Chinese-language input method editor — One-click remote code execution — [SW]

[P2 PATCH NOW]≤72h

Microsoft Remote Desktop Services (RDS) — Out-of-band emergency update to fix RDS failures — [BC]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch the Gitea RCE vulnerability [CVE-TBD] immediately to prevent exploitation by the Red Heron threat actor.
2[P1] Apply security patches for the three JFrog Artifactory vulnerabilities [CVE-TBD] to prevent authentication bypass and backdoor deployment.
3[P1] Apply Microsoft's out-of-band emergency updates for Remote Desktop Services (RDS) and Hyper-V to resolve critical operational failures.
4[P2] Update Tencent Chinese-language input method editor on Windows systems to mitigate the critical one-click remote code execution vulnerability [CVE-TBD].
5[P2] Audit and restrict internet exposure of Vite development servers to prevent unauthorized access and theft of AWS and Azure cloud secrets.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 14 Sep | Tencent Sogou Flaw Exploited to Deploy GrayRabbit
Powered by Buttondown, the easiest way to start and grow your newsletter.