Threat Brief — 2026-09-15 — Ransomware Joins vCenter Rush, Gitea Rootkit Surfaces
Executive summary: Ransomware operators have begun exploiting the critical VMware vCenter RCE patched in July, widening the attacker profile beyond initial access brokers. The Gitea CVE-2026-60004KEV exploitation story has developed further with a Linux rootkit now observed in post-compromise activity. Microsoft shipped an emergency out-of-band update to repair RDS, WSL, and USB-audio breakage caused by its September patches. Two mass-exploitation campaigns—Vite dev-server credential theft and Marimo RCE pivoting to SSH bastions in seconds—underscore how quickly public PoCs translate into real-world compromise.
Top items
- VMware vCenter RCE now exploited by ransomware gangs. CISA warns that ransomware crews have joined ongoing attacks against a critical vCenter vulnerability patched in July. The flaw enables unauthenticated remote code execution on vCenter Server; with ransomware actors now involved, the risk extends from initial access to full encryption operations. First reported 2026-09-15. (src: BleepingComputer)
- Gitea RCE exploitation evolves: Linux rootkit now deployed. A public proof-of-concept for Gitea CVE-2026-60004KEV has been refined over several days to mass-exploit servers, exfiltrate source code, and deploy a Linux rootkit to cover tracks. The vulnerability remains in CISA's Known Exploited Vulnerabilities catalog. First reported 2026-09-11 by xakep; new development is the rootkit and mass-exploitation capability. (src: SecurityLab)
- Mass-scanning campaign extracts cloud credentials from exposed Vite dev servers. Attackers are automatically targeting internet-exposed Vite development servers to siphon AWS, Azure, and other cloud credentials. Development servers should never be internet-facing; any exposed instance should be treated as potentially compromised. First reported 2026-09-14 by BleepingComputer. (src: The Hacker News)
- Human attacker exploits Marimo RCE, reaches SSH bastion in eight seconds. Sysdig reports a skilled human operator chaining a Marimo remote code execution vulnerability to pivot to an SSH bastion within eight seconds—demonstrating that AI-accelerated exploitation timelines are matched by capable human operators. First reported 2026-09-15. (src: The Hacker News)
- Microsoft ships emergency out-of-band update for September patch breakage. September updates broke Remote Desktop Services on Windows Server, WSL, and certain USB audio devices. Microsoft has now released an emergency "patch for a patch" to address the RDS failures that left some servers unable to accept RDP connections. First reported 2026-09-10 by BleepingComputer; new development is the emergency fix. (src: SecurityLab), (src: xakep)
- Five alleged Black Axe cybercrime syndicate leaders extradited to US. The extradited individuals face wire fraud and money laundering charges related to global-scale cyber-enabled financial fraud. The Black Axe syndicate has been a persistent threat in business email compromise and advance-fee fraud operations. (src: BleepingComputer)
- Hundreds of OpenAI contractors reportedly read ChatGPT user conversations. Even with usernames removed, chat content is not fully anonymous—contractors under Project Lily had broad access to user conversations, raising concerns about data-handling practices and insider risk at AI providers. First reported 2026-09-15 by xakep. (src: SecurityLab)
Themes
AI compressing the exploitation window. Multiple findings this week reinforce that AI tooling is shrinking the gap between vulnerability disclosure and mass exploitation. The Gitea rootkit story shows a public PoC maturing into mass exploitation with stealth capabilities within days, while the Marimo finding demonstrates that human operators can match AI-accelerated timelines. Defenders should assume near-zero patch latency for any vulnerability with public proof-of-concept code. (src: BleepingComputer)
