This day 02:08 06:09 10:09 14:10 18:00 22:01
Info  2026-09-14 18:00Z · last 4h · 23 findings · glm-5.2:cloud

Threat Brief — 2026-09-14 — Red Heron hits Gitea, DDRop sinks confidential VMs

Executive summary: A Chinese threat actor dubbed Red Heron is rapidly exploiting a recently disclosed Gitea RCE to compromise internet-facing instances across at least 13 organisations in six countries. Researchers disclosed DDRop, a hardware-level attack that silently drops memory writes to break Intel TDX and AMD SEV-SNP confidential-computing protections. Microsoft published two Windows elevation-of-privilege CVEs and revised patch guidance for a third, while WordPress rolled out automated pre-distribution security reviews for all plugin updates.

Top items

Themes

Attack window compression. Red Heron's rapid exploitation of a recently disclosed Gitea flaw is the latest in a pattern this week — from Vite dev-server scanning to PaperCut exploitation — where threat actors weaponise disclosures faster than defenders can patch. The interval between advisory and active targeting is no longer measured in weeks.

Patch regressions compounding. Microsoft's September update cycle closes hundreds of vulnerabilities but introduces functional breakage in both RDS and WSL. This creates a operational tension: organisations that delay patching to avoid regressions remain exposed to the very CVEs the updates address.

Supply-chain gating as defense. WordPress's automated plugin review and the broader industry conversation about patch automation with brakes (id 11805) reflect a shift toward pre-distribution validation rather than post-deployment detection.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db