SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, September 15, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Red Heron Exploits Gitea RCE Internationally | CRITICAL |
|
5 C2 IPs | 80 OTX IOCs | 35 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the exploitation of a Gitea remote code execution vulnerability by threat actor Red Heron, alongside active exploitation of JFrog Artifactory flaws to deploy backdoors. Additionally, hardware-level vulnerabilities like DDRop threaten confidential computing environments on Intel and AMD processors, while social engineering attacks successfully tricked Revolut into releasing sensitive customer data via fraudulent emergency requests. |
|
■ CRITICAL STORIES Red Heron Exploits Gitea RCE to Compromise 13 Organizations A suspected Chinese threat actor is actively scanning and exploiting a recently disclosed Gitea RCE vulnerability to rapidly compromise internet-facing instances across multiple countries. |
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing Researchers have demonstrated a hardware-level attack that bypasses memory protections in confidential computing environments by silently dropping memory writes, allowing processors to read stale encrypted data. |
Three JFrog Artifactory Flaws Exploited for Backdoor Deployment Attackers are actively exploiting three vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges to administrator, and deploy persistent backdoors. |
Revolut handed customer data to fraudsters using government email account Fraudsters successfully used social engineering and compromised or spoofed legitimate government email accounts to submit fake emergency data requests, tricking Revolut into disclosing sensitive customer IDs and financial data. |
|
■ CVEs IDENTIFIED [CVE-TBD] Gitea — Remote Code Execution (RCE) exploited by Red Heron |
[CVE-TBD] JFrog Artifactory — Authentication bypass and privilege escalation leading to backdoor deployment |
[CVE-TBD] Tencent Chinese-language input method editor — One-click remote code execution |
[CVE-TBD] Intel TDX & AMD SEV-SNP — DDRop hardware memory protection bypass |
|
■ THREAT ACTORS Red Heron | APT (Suspected Chinese) |
Exploiting Gitea RCE to compromise 13 organizations globally |
Black Axe | Cybercrime Group |
Members extradited from South Africa for lucrative romance scams |
Hacking Cat | Hacktivist (Pro-Ukraine) |
Deploying new malware and destructive attacks against Russian targets |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Red Heron exploiting Gitea RCE; attackers exploiting JFrog Artifactory flaws. |
| T1133 | | External Remote Services | Attackers targeting exposed Vite development servers to steal cloud secrets. |
| T1566 | | Phishing | Fake government websites in Central Asia collecting contact details; romance scams by Black Axe. |
| T1114 | | Email Collection | Telegram Desktop flaw exfiltrating messages from HTML exports. |
| T1539 | | Steal Web Session Cookie | Twitch browser extension exfiltrating OAuth session tokens. |
| T1204.002 | | User Execution: Malicious File | ClickFix attacks delivered via hijacked HBO Max Reddit account. |
|
■ PATCH PRIORITY Gitea — RCE actively exploited by Red Heron — [THN] |
JFrog Artifactory — Three flaws exploited for admin privilege escalation and backdoors — [SW] |
Tencent Chinese-language input method editor — One-click remote code execution — [SW] |
Microsoft Remote Desktop Services (RDS) — Out-of-band emergency update to fix RDS failures — [BC] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch the Gitea RCE vulnerability [CVE-TBD] immediately to prevent exploitation by the Red Heron threat actor. |
| 2 | [P1] Apply security patches for the three JFrog Artifactory vulnerabilities [CVE-TBD] to prevent authentication bypass and backdoor deployment. |
| 3 | [P1] Apply Microsoft's out-of-band emergency updates for Remote Desktop Services (RDS) and Hyper-V to resolve critical operational failures. |
| 4 | [P2] Update Tencent Chinese-language input method editor on Windows systems to mitigate the critical one-click remote code execution vulnerability [CVE-TBD]. |
| 5 | [P2] Audit and restrict internet exposure of Vite development servers to prevent unauthorized access and theft of AWS and Azure cloud secrets. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |