Threat Brief — 2026-09-14 — Red Heron hits Gitea, DDRop sinks confidential VMs
Executive summary: A Chinese threat actor dubbed Red Heron is rapidly exploiting a recently disclosed Gitea RCE to compromise internet-facing instances across at least 13 organisations in six countries. Researchers disclosed DDRop, a hardware-level attack that silently drops memory writes to break Intel TDX and AMD SEV-SNP confidential-computing protections. Microsoft published two Windows elevation-of-privilege CVEs and revised patch guidance for a third, while WordPress rolled out automated pre-distribution security reviews for all plugin updates.
Top items
- Red Heron exploits Gitea RCE in multi-national campaign. A Chinese threat actor tracked as Red Heron is mass-scanning and exploiting a recently disclosed Gitea remote code execution vulnerability against internet-facing instances, compromising 13 organisations across six countries. The speed of exploitation after disclosure indicates the window between advisory and active targeting is narrowing. Organisations running exposed Gitea instances should treat this as an immediate priority. (src: The Hacker News)
- DDRop attack breaks Intel TDX and AMD SEV-SNP confidential computing. Researchers disclosed a hardware attack that silently drops write operations to server memory, causing processors to read stale encrypted data and undermining the integrity guarantees of Intel TDX and AMD SEV-SNP trusted execution environments. This is a research disclosure, not an observed in-the-wild attack, but it affects the foundational security model of confidential VMs on both major x86 platforms. (src: The Hacker News)
- CVE-2026-62721 — Windows User-Mode Power Service EoP, revised patch guidance. Microsoft updated this vulnerability with security update links for Windows 11 versions 26H1, 25H2, and 24H1 to address a missed fix. The advisory recommends installing the updates as soon as possible. (src: Microsoft Security Response Center)
- CVE-2026-85921 — Windows Secure Kernel Mode EoP via double-free. A double-free condition in Windows Secure Kernel Mode allows an authorised attacker to elevate privileges locally. This is a local privilege escalation requiring prior access, but the Secure Kernel attack surface makes it notable for hardened environments. (src: Microsoft Security Response Center)
- WordPress launches automated pre-distribution plugin security reviews. WordPress.org now runs automated security analysis on every plugin release before it is distributed through the update API, blocking high-risk updates from reaching sites. This is a defensive supply-chain improvement that reduces the blast radius of malicious or vulnerable plugin updates across the WordPress ecosystem. (src: The Hacker News)
- September Windows update breakage expands to WSL. The ongoing story of September 2026 Windows Server updates breaking Remote Desktop Services, first reported 2026-09-10 by BleepingComputer, now includes reports that the same update cycle also breaks Windows Subsystem for Linux — adding a second regression to the patch batch that closed hundreds of vulnerabilities. (src: SecurityLab.ru)
Themes
Attack window compression. Red Heron's rapid exploitation of a recently disclosed Gitea flaw is the latest in a pattern this week — from Vite dev-server scanning to PaperCut exploitation — where threat actors weaponise disclosures faster than defenders can patch. The interval between advisory and active targeting is no longer measured in weeks.
Patch regressions compounding. Microsoft's September update cycle closes hundreds of vulnerabilities but introduces functional breakage in both RDS and WSL. This creates a operational tension: organisations that delay patching to avoid regressions remain exposed to the very CVEs the updates address.
Supply-chain gating as defense. WordPress's automated plugin review and the broader industry conversation about patch automation with brakes (id 11805) reflect a shift toward pre-distribution validation rather than post-deployment detection.
