Threat Brief — 2026-09-11 — Gitea RCE in the wild, GitLab max-severity patch
Two critical server-side vulnerabilities dominate today's brief: a Gitea RCE already exploited in the wild and added to CISA KEV, and a maximum-severity GitLab path traversal flaw requiring immediate patching. Separately, the Trezor contractor breach has evolved — 347,000 real internal emails are now being weaponised as phishing lures.
Top items
- Gitea RCE actively exploited (CVE-2026-60004KEV, CISA KEV). The Shadowserver Foundation reports over 8,300 internet-exposed Gitea instances remain unpatched against a critical arbitrary code execution vulnerability. The flaw is already being exploited in real attacks and has been added to CISA's Known Exploited Vulnerabilities catalog. (src: Xakep)
- GitLab maximum-severity path traversal (CVE-2023-2825). GitLab has urged immediate patching of a path traversal vulnerability rated maximum severity. Exploitation could allow unauthorised file access on affected instances. No evidence of active exploitation is cited in the advisory. (src: BleepingComputer)
- Trezor contractor breach evolves — 347,000 real emails turned to phishing bait. Building on the ShipMonk-related breach first reported 2026-09-05, attackers have now weaponised 347,000 emails from Trezor's genuine internal systems as phishing lures, significantly expanding the attack surface beyond the original data exposure. (src: SecurityLab)
- Conti affiliate sentenced to four years. Alexei Litvinenko, a participant in the Conti ransomware operation, has been sentenced to four years imprisonment. He stored data from 12 victims and developed malicious loaders for the group. (src: SecurityLab)
- US Congress proposes cutting hackers-for-hire from American cloud and software services. Legislation is being proposed to disrupt infrastructure used by three companies linked to thousands of attacks, targeting their access to US-hosted cloud and software platforms. (src: SecurityLab)
- Instagram copyright-claim extortion scheme identified. Attackers are weaponising copyright reporting to block bloggers' accounts, then demanding payment to release the complaints — turning platform DMCA processes into an extortion tool. (src: SecurityLab)
Themes
Server-side exploitation pressure. Both Gitea and GitLab flaws target self-hosted developer infrastructure that is frequently internet-exposed and may lag behind enterprise patch cycles. Attackers increasingly recognise these platforms as high-value targets with broad code and credential access.
Third-party supply chain as phishing amplifier. The Trezor development illustrates how a contractor breach compounds over time — stolen data doesn't just leak, it becomes material for more convincing follow-on attacks.
