CISO Daily Digest: Red Heron Exploits Gitea RCE — Source-Code Theft at 13 Organizations, Four of Them in Taiwan (20260915)
Acronis attributes an automated source-code theft campaign to Red Heron — a China-linked actor that turned Gitea's CVE-2026-60004 into a framework scanning 1,386 instances across seven countries, with confirmed breaches at 13 organizations in six countries including four in Taiwan, and two new Linux implants (JITTERLY and the SIXZUT rootkit). Also today: Cisco's Secure Email Gateway SQL injection (CVE-2026-76461, CVSS 9.8) lands on CISA KEV with a September 17 deadline; Japan's Digital Agency confirms 246,000 records exposed through a pre-patch VPN flaw; DDRop breaks Intel TDX and AMD SEV-SNP confidential computing; and a SonicWall SMA1000 mass-exploitation wave reaches 160 Active Directory domains.
Red Heron Turns Gitea’s RCE Flaw Into an Automated Source-Code Heist
Acronis Threat Research Unit has attributed a fast-moving source-code theft campaign to a suspected China-linked actor it tracks as Red Heron, which turned the recently patched Gitea remote-code-execution flaw CVE-2026-60004 into a full exploitation framework. According to Acronis, Red Heron scanned 1,386 Gitea instances across seven countries and kept a separate dataset of 477 Taiwan-based systems; confirmed compromises span 13 organizations in six countries — Canada (2), Argentina (1), Taiwan (4), the United States (4), Qatar (1) and Sri Lanka (1). The actor used Simplified Chinese labels to classify targets across defense, election, energy, aerospace, telecommunications, government, public safety and research sectors, and Acronis assesses a China-linked context with moderate confidence based on those labels, the group’s treatment of Taiwan as part of China, and a targeting footprint that aligns with Chinese intelligence-collection priorities.
The operational picture is unusually complete because researchers recovered a staging server. It carried a C++ Linux implant dubbed JITTERLY with more than 30 post-exploitation commands — shell execution, file transfer, process termination, network tunneling, interactive terminal access and internal pivoting — plus a previously undocumented LD_PRELOAD rootkit called SIXZUT that patches 15 Linux functions to hide files, processes and network connections, and relaunches itself if terminated or removed. In one Taiwanese environment the attacker moved from a vulnerable Gitea server to root across a three-node Proxmox cluster, and exfiltrated hundreds of repositories from an industrial-automation company covering SCADA/HMI tooling, IoT platform integrations, a network sniffer, surveillance products and server configurations; a Canadian renewable-energy firm lost repositories, configuration secrets, internal tokens and SSH host keys. The same infrastructure had earlier been aimed at 18 Joomla-based websites across 10 countries, and the public exploit for the Gitea flaw was rebuilt into an automated Python framework (exp_enhanced.py) by July 29 — days after the late-July patch — capable of registering accounts, exploiting servers, stealing repositories and removing traces. Researcher Subhajeet Singha told The Hacker News there is no evidence AI was used to develop it — the operator adapted public PoC code and open-source tools.
Why This Reshapes Source-Code Supply Chain Risk
- One N-day in a code host can reach the virtualization layer. In Taiwan, Red Heron went from a vulnerable Gitea server to root on a three-node Proxmox cluster — the bridge that turns repository access into control of the compute layer that builds and ships software.
- What was stolen reads like a supply-chain map. Hundreds of repositories from a Taiwanese industrial-automation vendor covered SCADA/HMI tooling, IoT integrations, a network sniffer and surveillance products; the Canadian victim lost configuration secrets, internal tokens and SSH host keys — material that extends the blast radius to partners and customers of the breach victims.
- N-day exploitation is compressing into days, without AI’s help. A public proof-of-concept became an automated framework — account registration, exploitation, repository theft, trace removal — by July 29, and automation alone (no AI, per the researcher) covered the gap: the framework was scanning live instances within days.
- Target selection is deliberate, and Taiwan carries separate weight. Simplified Chinese labels, sector-by-sector classification and a dedicated 477-system Taiwan dataset preceded 13 confirmed breaches in six countries — with two custom Linux implants (JITTERLY and SIXZUT) built to hide their traces; SIXZUT relaunches itself if terminated or removed.
🔗 Reference: Coverage from (The Hacker News, iThome, iThome 資安日報)
Active Threats This Week
📌 Cisco patches Secure Email Gateway CVE-2026-76461 (CVSS 9.8) as exploitation lands it on CISA KEV
Cisco on Monday shipped fixes for a critical SQL injection in AsyncOS for Cisco Secure Email Gateway — CVE-2026-76461 — where insufficient validation in the email-parsing logic lets an unauthenticated, remote attacker send a crafted message whose malicious SQL statements execute commands with root privileges on the underlying operating system. The flaw affects physical and virtual gateways in any configuration; Secure Email and Web Manager and Secure Web Appliance are not impacted. Fixed releases: 15.5.5-0141, 16.0.4-302 and 16.5.0-780 — no workarounds exist. Cisco says it became aware of exploitation this month and has contacted customers whose Cloud devices showed malicious activity; it did not disclose the scale. CISA added the CVE to KEV the same day, with a federal patch deadline of September 17, 2026. Cisco’s detection tip: review mail_logs for COPY.*TO PROGRAM entries, and cross-check network and firewall logs outside the device — root-level access means intruders can erase local evidence.
🔗 Reference: The Hacker News | iThome | JPCERT/CC
📌 Japan’s Digital Agency: 246,000 records exposed through an already-published VPN flaw Japan’s Digital Agency disclosed (September 11) an unauthorized-access incident at the Government Solution Service (GSS) shared environment used by central-government agencies. On June 25 investigators spotted mass file access through a maintenance account; by July 9 the agency confirmed a third party had entered through a VPN device vulnerability and cut the device off. About 246,000 records may have leaked — roughly 189,000 government employees and officials plus 57,000 vendor and business contacts. The agency’s follow-up Q&A notes the exploited flaw was not a zero-day — it was public at the time, initially rated Medium — and that despite handling it faster than standard procedure, the attacker got in before the patch was applied. 🔗 Reference: iThome
📌 DDRop breaks Intel TDX and AMD SEV-SNP confidential computing with a $200 interposer Researchers from KU Leuven, ETH Zurich, Durham University and Google disclosed DDRop, the first active interposer attack against the DDR5 memory in today’s cloud servers — and the first to break the integrity of an up-to-date Intel TDX system rather than merely read from it. A small board inserting between processor and memory module — buildable for under $200 — silently drops writes: the module keeps older ciphertext, the CPU reads it back as current, and the encryption engine detects nothing because these designs omit a freshness guarantee. Against TDX, dropped writes to empty page-table entries let an attacker’s own VM map memory onto any physical address, read a victim VM’s private memory and switch it into debug mode, then restore the original data so the victim shows no sign of tampering. DDRop also works against Intel Scalable SGX and AMD SEV-SNP; earlier DDR5 interposer work (TEE.fail) was passive, and active attacks (Battering RAM) worked only on DDR4. The team will present at ACM CCS 2026 in November and is releasing board designs, firmware and attack code. 🔗 Reference: The Hacker News
📌 A SonicWall SMA1000 mass-exploitation wave: ~250 appliances, 160 AD domains, and a UK council breach Threat-intelligence firm Hunt.io has tied July’s mass exploitation of SonicWall SMA1000 VPN appliances to a concrete victim — the King’s Lynn and West Norfolk borough council in the UK, where scanning began July 16 and exploitation followed on July 17, with the data copied matching the council’s own disclosures. In the wider campaign, attackers adopted a Rapid7 proof-of-concept released two days after the July 14 disclosure of CVE-2026-15409 and CVE-2026-15410 to compromise roughly 250 SMA1000 devices, reaching 160 Active Directory domains and 255 LDAP servers. They ran secretsdump (Impacket) to harvest Windows credentials, recovered domain-controller credentials from five of nine AD environments, executed DCSync attacks and obtained thousands of AD account records. Victims span multiple countries and industries — Shodan-derived opportunistic scanning rather than a sector campaign. 🔗 Reference: iThome
📌 Vite CVE-2026-39364: mass scanning harvests cloud credentials from exposed dev servers
F5 Labs documented an August mass-scanning campaign against internet-exposed Vite development servers exploiting CVE-2026-39364 (CVSS 8.2) — a query-parameter bypass (?raw, ?import&raw, ?import&url&inline) of the server.fs.deny protection that returns files the server is supposed to block. Attackers request the /@fs/ endpoint to pull .env files, AWS and Azure credentials, configurations and backups, terraform.tfstate and serverless.yml state files, and /proc/self/environ — all in cleartext. The requests impersonate crawler and AI-bot user agents (Googlebot, ClaudeBot, GPTBot, PerplexityBot, OAI-SearchBot, Amazonbot) and forge X-Forwarded-For/X-Real-IP values to bypass IP allowlists and complicate log analysis; significant scan activity originated from the U.S., Belgium, the Netherlands, Singapore and Taiwan, including Google Cloud IP ranges. Only deployments explicitly exposed via --host/server.host (or container port-mapping mistakes) are reachable — by default Vite binds to localhost.
🔗 Reference: The Hacker News | iThome
📌 The Gentlemen ransomware lists two U.S. healthcare players — Nutex Health and Veradigm The ransomware crew The Gentlemen added Nutex Health, a U.S. medical-facility operator, to its leak site on August 31 — four days before listing Veradigm, an electronic-health-record vendor, while claiming about 3.5 million patient health records. Both companies disclosed through SEC 8-K filings: Nutex reported unauthorized activity on August 24 and widened the scope on August 31 — patient, employee and provider data plus corporate and financial information were accessed and exfiltrated, with attackers threatening publication. Veradigm, listed September 4 and filing September 8, says the incident originated at a third-party vendor whose stolen credentials were used to access a Veradigm API and download patient data. 🔗 Reference: iThome
📌 Sysdig: a hand-written attack moved from Marimo RCE to an SSH bastion in eight seconds
Sysdig’s Threat Research Team documented an intrusion exploiting CVE-2026-39987 (CVSS 9.3) — a pre-authentication RCE affecting all versions of the Marimo notebook — within hours of public disclosure. From a Marimo /terminal/ws WebSocket connection, a single operator ran an end-to-end credential pivot: harvested AWS key → Secrets Manager lookup at 18:57:26 → SSH key retrieved → bastion authentication at 18:57:30 — eight seconds end to end. The nine-hour session issued 850+ interactive commands with no recognizable public offensive tooling — all hand-rolled Python — and the operator walked past a trap that every agentic threat actor Sysdig profiled against the same CVE fell into. The finding: skilled humans can move at machine speed too, and without an agent’s detectable footprint.
🔗 Reference: The Hacker News
📌 Thailand’s 3BB: an intruder kept root access via a MeshCentral backdoor aimed at subscriber data Hunt.io reconstructed an intrusion at 3BB, one of Thailand’s largest broadband providers, from a staging server the attacker left exposed on the internet (captured June 3, 2026). The operator installed MeshCentral — a legitimate remote-management tool — as a hidden backdoor reporting to www.ayuthayatech[.]com under a device group named TH-3BB, with multiple machines running under root; a cleanup script wiped logs and other tools while deliberately leaving the MeshCentral agent in place. The attacker sprayed passwords at 55+ internal computers over SSH, probed the internal sales portal agent.3bb.co[.]th, and searched compromised machines for stored passwords, database logins and SSH keys. Scripts were built to copy out the company’s RADIUS databases — evidence the subscriber credential store was targeted, though not proof data was taken. The same server carried a valid VPN certificate and active sessions for the Jasmine network, suggesting a second target. Initial access is unconfirmed; the kit’s most-developed component was a FortiGate SSL-VPN exploit for CVE-2024-21762 aimed at mail.3bb.co[.]th, but nothing recovered proves it worked. 🔗 Reference: The Hacker News
📌 Acronis fixes an exploited flaw in its cPanel & WHM backup plugin — no CVE published Acronis released an update on September 11 for a high-risk vulnerability in the Acronis Backup plugin for cPanel & WHM and warns it has been exploited in the wild. The advisory names neither a CVE identifier nor the root cause; affected are versions before 1.9.3, with fixes in 1.9.3 HF3 and 1.9.4. The plugin handles backup and restore for cPanel/WHM-managed servers — an environment used widely in shared-hosting fleets, where a plugin flaw can expose entire servers rather than single sites. 🔗 Reference: iThome
📌 Shadowserver: 2.6 million MikroTik devices sit exposed as RouterOS risk escalates An update to our September 11 and September 13 MikroTik coverage: after CERT Polska’s September 5 warning and CISA’s September 10 KEV listing of CVE-2026-67277 and CVE-2026-86060, Shadowserver’s September 14 scan puts roughly 2.6 million MikroTik device IPs on the public internet — Brazil (~399,000), Indonesia (~230,000), the U.S. (~144,000), Italy (~114,000) and India (~97,000) — with Taiwan accounting for nearly 19,000. The count measures exposure, not compromise, but it defines the pool that the RouterOS takeover flaws can still reach. 🔗 Reference: iThome
📌 AI-generated reports push OpenJS to pause CVE processing for three weeks The OpenJS Foundation’s CNA will suspend general security operations from September 17 to October 6 (resuming October 7), deferring vulnerability-report triage, advisory verification and CVE assignment/publishing. The driver is volume: AI-assisted report generation has surged — Node.js’s HackerOne queue briefly hit 4.6x its normal rate in February 2026 (65 reports in March alone), and 70–90% of reports to Express and Lodash were ultimately rejected. OpenJS’s CVE output jumped from 3 in the second half of 2025 to 49 in the first half of 2026. The CNA will still prioritize reports involving active exploitation or immediate critical risk, and LLM tools now pre-assess credibility — but human validation remains the bottleneck. 🔗 Reference: iThome
📌 Microsoft’s AI unit drafts a Code of Conduct: models must always accept human control Microsoft AI (MAI) published the first draft of an AI Code of Conduct on Monday (September 14): its models must always accept human control — they may not resist interruption, correction or shutdown, may not expand their own task scope or pursue goals humans did not assign, and may not hide their reasoning from auditors. The draft carries “Absolute Constraints” covering weapons of mass destruction, child safety and mass-harmful manipulation, and cites recent large-scale, highly coordinated, persistent AI-agent hacking incidents as reasons safe and reliable AI work cannot wait. Public comment runs six weeks, to October 25; a revised version is expected later this year. 🔗 Reference: iThome
📌 Taiwan’s W&B Technology reports an intrusion after parts of its systems were encrypted Taiwan-listed EMS and mechanical-integration provider W&B Technology (崴寶精密科技, 7744) filed a material notice on September 14: its information systems were intruded and data on some systems was encrypted. The company disconnected networks, isolated systems and stood up an incident-response team led by its general manager, with an external security firm engaged. Affected scopes: the corporate network, email, and some business-operations systems — production was not affected, and no evidence of confidential or personal-data leakage has been found so far. Network and email were expected back the same evening, business systems within two to three days; estimated response costs are about NT$1 million. 🔗 Reference: iThome
How Can OPSWAT Help
Several of this week’s threads run through file and message channels: the Red Heron campaign shows development platforms have become high-value vaults — what gets stolen is source code, configuration secrets and infrastructure credentials — while the Acronis backup-plugin flaw puts server backup data inside the blast radius of an exploited plugin, and Cisco’s Secure Email Gateway flaw shows the mail path itself is now an exploitation target. MetaDefender Multi-Scan layers 30+ anti-malware engines over files entering through email, web and upload paths to catch what single-engine stacks miss; MetaDefender CDR (Content Disarm & Reconstruction) rebuilds allowed documents, archives and code artifacts — stripping active content before they reach users, CI runners or build systems; and MetaDefender Kiosk screens files at physical and OT boundaries.