Weekly review

ThreatNoir Morning Brief — September 15

2026-09-15Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 15, 2026

September 15, 2026 brings critical security developments across multiple threat vectors, from supply chain vulnerabilities to sophisticated nation-state campaigns and hardware-level attacks. Organizations face urgent patching requirements and emerging threats that demand immediate attention.

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 represents a critical threat to software supply chains worldwide. This path traversal vulnerability carries a maximum CVSS score of 10.0 and affects both GitLab Community Edition and Enterprise Edition instances. The severity of this flaw demands immediate patching across all affected deployments, as the vulnerability's potential to compromise repository integrity could have cascading effects throughout dependent software projects and organizations.

Source: Dark Reading

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Researchers have disclosed a novel hardware attack called DDRop that fundamentally undermines the memory protection mechanisms in Intel TDX and AMD SEV-SNP confidential computing environments. The attack operates by silently dropping writes to server memory, causing processors to read outdated encrypted data as if it were current information. This sophisticated approach requires an attacker with prior software control of the target server and brief physical access to insert a specialized circuit, representing a significant evolution in hardware-level threats against cloud infrastructure and sensitive computing environments.

Source: The Hacker News

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

The Chinese threat actor Red Heron has been attributed to a coordinated campaign exploiting a recently disclosed remote code execution vulnerability in Gitea. The group rapidly targeted internet-facing Gitea instances across multiple nations, successfully compromising 13 organizations. According to the Acronis Threat Research Unit, Red Heron conducted reconnaissance of 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems, demonstrating systematic targeting of version control infrastructure. The campaign has been linked to the deployment of malware families JITTERLY and SIXZUT, indicating a sophisticated supply chain and infrastructure attack strategy.

Source: The Hacker News

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

The notorious Russian threat group Sandworm has resumed operations with an upgraded variant of Cyclops Blink, the botnet malware that the FBI successfully disrupted in 2022. The group is exploiting chained Cisco vulnerabilities to deploy this revived malware, demonstrating continued sophistication in leveraging multiple attack vectors to compromise network infrastructure. This resurgence indicates that threat actors have invested in enhancing previously disrupted tools and remain focused on establishing persistent access to critical systems.

Source: Dark Reading

Conclusion

Today's threat landscape reflects an escalation across multiple attack categories, from maximum-severity software vulnerabilities affecting development infrastructure to nation-state actors deploying revived botnets and hardware-level attacks targeting cloud security foundations. Organizations must prioritize immediate patching of GitLab and Gitea instances, implement enhanced monitoring for Cisco infrastructure, and evaluate their resilience against both software and hardware-level threats in confidential computing environments.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).