Daily Security Intel

Archives
Log in
Subscribe
August 27, 2026

[SecurityIntel] 27 Aug | FBI Disrupts Chinese Espionage Proxy Infrastructure

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, August 27, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

FBI Disrupts Chinese Espionage Proxy Infrastructure

CRITICAL

5

C2 IPs

0

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by the FBI's disruption of the Chinese state-sponsored "QTFY" proxy infrastructure (QScan and QTRouter) targeting US critical infrastructure, alongside active exploitation of a Gitea RCE vulnerability (CVE-2026-60004). Additionally, critical remote code execution vulnerabilities are actively targeted in Microsoft SharePoint, the Avada WordPress theme, and unpatched Kaltura mwEmbed video player libraries, while Iranian state-sponsored group Nimbus Manticore expands its backdoor arsenal. Organizations must prioritize patching exposed DevOps, content management, and remote collaboration platforms to mitigate these high-impact vectors.

■ CRITICAL STORIES

CRITICAL#1

Critical Avada WordPress theme flaw enables zero-click RCE

This zero-click vulnerability chain allows unauthenticated threat actors to execute arbitrary PHP code on servers hosting the highly popular Avada WordPress theme, posing an immediate risk of full site takeover.

HIGH#2

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The FBI and DOJ dismantled the QScan and QTRouter platforms, which functioned as a technical "quartermaster" proxy network enabling Chinese cyber espionage actors to scan and exploit IoT devices across federal agencies and critical infrastructure.

CRITICAL#3

CISA Warns of Exploited Gitea Vulnerability

CISA added CVE-2026-60004, a remote code execution vulnerability in the Gitea DevOps platform, to its Known Exploited Vulnerabilities catalog, signaling active wild exploitation that requires immediate patching.

HIGH#4

New GPUThor attack defeats NVIDIA ECC protection for root access

Security researchers disclosed a novel Rowhammer-style attack targeting NVIDIA GPUs that bypasses Error-Correcting Code (ECC) protections to achieve denial-of-service and root-level privilege escalation.

■ CVEs IDENTIFIED

CVE-2026-60004

Gitea DevOps Platform — Remote Code Execution

Critical

[CVE-TBD-Avada]

Avada WordPress Theme — Zero-click Remote Code Execution

Critical

[CVE-TBD-GPUThor]

NVIDIA GPUs — ECC Bypass, Privilege Escalation, and DoS

High

[CVE-TBD-SharePoint1]

Microsoft SharePoint — Remote Code Execution (Chained Vulnerability 1)

Critical

■ THREAT ACTORS

QTFY (QScan / QTRouter)

State-Sponsored (China)

Infrastructure disrupted by FBI; used for scanning and proxying attacks against US federal agencies and critical infrastructure.

Nimbus Manticore

State-Sponsored (Iran / IRGC)

Expanded infrastructure across Europe and Middle East; deployed TWOSTROKE-like backdoor and SSH tunneler.

Unknown Russian Influence Actors

State-Sponsored / Influence Group

Used VPNs and ChatGPT accounts to generate and distribute social media propaganda; accounts banned by OpenAI.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Used to exploit Gitea (CVE-2026-60004), Avada WordPress theme, and Microsoft SharePoint.
T1090
Proxy | Chinese QTFY group used QTRouter and QScan proxy networks to route operational traffic and scan targets.
T1566.002
Phishing: Spearphishing Link | NovaCookies campaigns used fake DocuSign notifications to redirect users to AitM phishing pages.
T1539
Steal Web Session Cookie | NovaCookies AitM proxy captured Microsoft 365 session cookies to bypass MFA.
T1021.004
Remote Services: SSH | Nimbus Manticore deployed an SSH tunneler for secure remote access and persistence.
T1496
Resource Hijacking | Attackers targeted exposed LiteLLM AI gateways to deploy cryptominers.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Gitea — Active in-the-wild exploitation of CVE-2026-60004 RCE — SecurityWeek

[P1 PATCH NOW]≤24h

Microsoft SharePoint — Active exploitation of two chained RCE vulnerabilities with public PoC — BleepingComputer

[P1 PATCH NOW]≤24h

ThemeFusion Avada WordPress Theme — Unauthenticated zero-click RCE vulnerability chain — BleepingComputer

[P1 PATCH NOW]≤24h

Ubiquiti Products — Three maximum-severity remote unauthenticated vulnerabilities patched — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Gitea instances immediately to version 1.27.1 or later to remediate CVE-2026-60004, which is actively exploited in the wild.
2[P1] Apply the latest security patches for Microsoft SharePoint to block the active exploitation chain of the two critical RCE vulnerabilities ([CVE-TBD-SharePoint1] and [CVE-TBD-SharePoint2]).
3[P1] Update the Avada WordPress theme immediately to the latest patched version to mitigate the zero-click RCE vulnerability chain ([CVE-TBD-Avada]).
4[P1] Deploy the latest firmware updates for all Ubiquiti devices to patch the three maximum-severity remote unauthenticated vulnerabilities.
5[P2] Update Google Chrome to version 152 or later to address over 300 security vulnerabilities, including those discoverable via automated AI tools.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 29 Aug | Active Exploitation of PaperCut and Cosmos EVM Older → [SecurityIntel] 26 Aug | MiniOrange SSO Flaws Target WordPress Websites
Powered by Buttondown, the easiest way to start and grow your newsletter.