SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, August 27, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY FBI Disrupts Chinese Espionage Proxy Infrastructure | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by the FBI's disruption of the Chinese state-sponsored "QTFY" proxy infrastructure (QScan and QTRouter) targeting US critical infrastructure, alongside active exploitation of a Gitea RCE vulnerability (CVE-2026-60004). Additionally, critical remote code execution vulnerabilities are actively targeted in Microsoft SharePoint, the Avada WordPress theme, and unpatched Kaltura mwEmbed video player libraries, while Iranian state-sponsored group Nimbus Manticore expands its backdoor arsenal. Organizations must prioritize patching exposed DevOps, content management, and remote collaboration platforms to mitigate these high-impact vectors. |
|
■ CRITICAL STORIES Critical Avada WordPress theme flaw enables zero-click RCE This zero-click vulnerability chain allows unauthenticated threat actors to execute arbitrary PHP code on servers hosting the highly popular Avada WordPress theme, posing an immediate risk of full site takeover. |
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI and DOJ dismantled the QScan and QTRouter platforms, which functioned as a technical "quartermaster" proxy network enabling Chinese cyber espionage actors to scan and exploit IoT devices across federal agencies and critical infrastructure. |
CISA Warns of Exploited Gitea Vulnerability CISA added CVE-2026-60004, a remote code execution vulnerability in the Gitea DevOps platform, to its Known Exploited Vulnerabilities catalog, signaling active wild exploitation that requires immediate patching. |
New GPUThor attack defeats NVIDIA ECC protection for root access Security researchers disclosed a novel Rowhammer-style attack targeting NVIDIA GPUs that bypasses Error-Correcting Code (ECC) protections to achieve denial-of-service and root-level privilege escalation. |
|
■ CVEs IDENTIFIED CVE-2026-60004 Gitea DevOps Platform — Remote Code Execution |
[CVE-TBD-Avada] Avada WordPress Theme — Zero-click Remote Code Execution |
[CVE-TBD-GPUThor] NVIDIA GPUs — ECC Bypass, Privilege Escalation, and DoS |
[CVE-TBD-SharePoint1] Microsoft SharePoint — Remote Code Execution (Chained Vulnerability 1) |
|
■ THREAT ACTORS QTFY (QScan / QTRouter) | State-Sponsored (China) |
Infrastructure disrupted by FBI; used for scanning and proxying attacks against US federal agencies and critical infrastructure. |
Nimbus Manticore | State-Sponsored (Iran / IRGC) |
Expanded infrastructure across Europe and Middle East; deployed TWOSTROKE-like backdoor and SSH tunneler. |
Unknown Russian Influence Actors | State-Sponsored / Influence Group |
Used VPNs and ChatGPT accounts to generate and distribute social media propaganda; accounts banned by OpenAI. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Used to exploit Gitea (CVE-2026-60004), Avada WordPress theme, and Microsoft SharePoint. |
| T1090 | | Proxy | Chinese QTFY group used QTRouter and QScan proxy networks to route operational traffic and scan targets. |
| T1566.002 | | Phishing: Spearphishing Link | NovaCookies campaigns used fake DocuSign notifications to redirect users to AitM phishing pages. |
| T1539 | | Steal Web Session Cookie | NovaCookies AitM proxy captured Microsoft 365 session cookies to bypass MFA. |
| T1021.004 | | Remote Services: SSH | Nimbus Manticore deployed an SSH tunneler for secure remote access and persistence. |
| T1496 | | Resource Hijacking | Attackers targeted exposed LiteLLM AI gateways to deploy cryptominers. |
|
■ PATCH PRIORITY Gitea — Active in-the-wild exploitation of CVE-2026-60004 RCE — SecurityWeek |
Microsoft SharePoint — Active exploitation of two chained RCE vulnerabilities with public PoC — BleepingComputer |
ThemeFusion Avada WordPress Theme — Unauthenticated zero-click RCE vulnerability chain — BleepingComputer |
Ubiquiti Products — Three maximum-severity remote unauthenticated vulnerabilities patched — BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Gitea instances immediately to version 1.27.1 or later to remediate CVE-2026-60004, which is actively exploited in the wild. |
| 2 | [P1] Apply the latest security patches for Microsoft SharePoint to block the active exploitation chain of the two critical RCE vulnerabilities ([CVE-TBD-SharePoint1] and [CVE-TBD-SharePoint2]). |
| 3 | [P1] Update the Avada WordPress theme immediately to the latest patched version to mitigate the zero-click RCE vulnerability chain ([CVE-TBD-Avada]). |
| 4 | [P1] Deploy the latest firmware updates for all Ubiquiti devices to patch the three maximum-severity remote unauthenticated vulnerabilities. |
| 5 | [P2] Update Google Chrome to version 152 or later to address over 300 security vulnerabilities, including those discoverable via automated AI tools. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |