Skip to content
[SecurityIntel] 15 Sep | Red Heron Exploits Gitea RCE Internationally

[SecurityIntel] 15 Sep | Red Heron Exploits Gitea RCE Internationally

Buttondown • September 15, 2026

SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Tuesday, September 15, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY Red Heron Exploits Gitea RCE Internationally CRITICAL 5 C2 IPs 80 OTX IOCs 35 ARTICLES ■ ANALYST TLDR Today's threat landscape is highlighted by the exploitation of a Gitea remote code execution vulnerability by threat actor Red Heron, alongside active exploitation of JFrog Artifactory flaws to deploy backdoors. Additionally, hardware-level vulnerabilities like DDRop threaten confidential computing environments on Intel and AMD processors, while social engineering attacks successfully tricked Revolut into releasing sensitive customer data via fraudulent emergency requests. ■ CRITICAL STORIES CRITICAL #1 Red Heron Exploits Gitea RCE to Compromise 13 Organizations A suspected Chinese threat actor is actively scanning and exploiting a recently disclosed Gitea RCE vulnerability to rapidly compromise internet-facing instances across multiple countries. HIGH #2 New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing Researchers have demonstrated a hardware-level attack that bypasses memory protections in confidential computing environments by silently dropping memory writes, allowing processors to read stale encrypted data. HIGH #3 Three JFrog Artifactory Flaws Exploited for Backdoor Deployment Attackers are actively exploiting three vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges to administrator, and deploy persistent backdoors. INFO #4 Revolut handed customer data to fraudsters using government email account Fraudsters successfully used social engineering and compromised or spoofed legitimate government email accounts to submit fake emergency data requests, tricking Revolut into disclosing sensitive customer IDs and financial data. ■ CVEs IDENTIFIED [CVE-TBD] Gitea — Remote Code Execution (RCE) exploited by Red Heron Critical [CVE-TBD] JFrog Artifactory — Authentication bypass and privilege escalation leading to backdoor deployment Critical [CVE-TBD] Tencent Chinese-language input method editor — One-click remote code execution Critical [CVE-TBD] Intel TDX & AMD SEV-SNP — DDRop hardware memory protection bypass High ■ THREAT ACTORS Red Heron APT (Suspected Chinese) Exploiting Gitea RCE to compromise 13 organizations globally Black Axe Cybercrime Group Members extradited from South Africa for lucrative romance scams Hacking Cat Hacktivist (Pro-Ukraine) Deploying new malware and destructive attacks against Russian targets ■ ATT&CK TTPs T1190 Exploit Public-Facing Application | Red Heron exploiting Gitea RCE; attackers exploiting JFrog Artifactory flaws. T1133 External Remote Services | Attackers targeting exposed Vite development servers to steal cloud secrets. T1566 Phishing | Fake government websites in Central Asia collecting details; romance scams by Black Axe. T1114 Email Collection | Telegram Desktop flaw exfiltrating messages from HTML exports. T1539 Steal Web Session Cookie | Twitch browser extension exfiltrating OAuth session tokens. T1204.002 User Execution: Malicious File | ClickFix attacks delivered via hijacked HBO Max account. ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h Gitea — RCE actively exploited by Red Heron — [THN] [P1 PATCH NOW] ≤24h JFrog Artifactory — Three flaws exploited for admin privilege escalation and backdoors — [SW] [P1 PATCH NOW] ≤24h Tencent Chinese-language input method editor — One-click remote code execution — [SW] [P2 PATCH NOW] ≤72h Microsoft Remote Desktop Services (RDS) — Out-of-band emergency update to fix RDS failures — [BC] ■ RECOMMENDED ACTIONS TODAY 1 [P1] Patch the Gitea RCE vulnerability [ CVE-TBD ] immediately to prevent exploitation by the Red Heron threat actor. 2 [P1] Apply security patches for the three JFrog Artifactory vulnerabilities [ CVE-TBD ] to prevent authentication bypass and backdoor deployment. 3 [P1] Apply Microsoft's out-of-band emergency updates for Remote Desktop Services (RDS) and Hyper-V to resolve critical operational failures. 4 [P2] Update Tencent Chinese-language input method editor on Windows systems to mitigate the critical one-click remote code execution vulnerability [ CVE-TBD ]. 5 [P2] Audit and restrict internet exposure of Vite development servers to prevent unauthorized access and theft of AWS and Azure cloud secrets. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

SECURITYINTEL DAILY BRIEF

Tuesday, September 15, 2026

INTEL CONFIDENCE 100%

Red Heron Exploits Gitea RCE Internationally

Today's threat landscape is highlighted by the exploitation of a Gitea remote code execution vulnerability by threat actor Red Heron, alongside active exploitation of JFrog Artifactory flaws to deploy backdoors. Additionally, hardware-level vulnerabilities like DDRop threaten confidential computing environments on Intel and AMD processors, while social engineering attacks successfully tricked Revolut into releasing sensitive customer data via fraudulent emergency requests.

Red Heron Exploits Gitea RCE to Compromise 13 Organizations

A suspected Chinese threat actor is actively scanning and exploiting a recently disclosed Gitea RCE vulnerability to rapidly compromise internet-facing instances across multiple countries.

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Researchers have demonstrated a hardware-level attack that bypasses memory protections in confidential computing environments by silently dropping memory writes, allowing processors to read stale encrypted data.

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Attackers are actively exploiting three vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges to administrator, and deploy persistent backdoors.

Revolut handed customer data to fraudsters using government email account

Fraudsters successfully used social engineering and compromised or spoofed legitimate government email accounts to submit fake emergency data requests, tricking Revolut into disclosing sensitive customer IDs and financial data.

Gitea — Remote Code Execution (RCE) exploited by Red Heron

JFrog Artifactory — Authentication bypass and privilege escalation leading to backdoor deployment

Tencent Chinese-language input method editor — One-click remote code execution

Intel TDX & AMD SEV-SNP — DDRop hardware memory protection bypass

Exploiting Gitea RCE to compromise 13 organizations globally

Members extradited from South Africa for lucrative romance scams

Deploying new malware and destructive attacks against Russian targets

Gitea — RCE actively exploited by Red Heron — [THN]

JFrog Artifactory — Three flaws exploited for admin privilege escalation and backdoors — [SW]

Tencent Chinese-language input method editor — One-click remote code execution — [SW]

Microsoft Remote Desktop Services (RDS) — Out-of-band emergency update to fix RDS failures — [BC]

■ RECOMMENDED ACTIONS TODAY

C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools

IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB