- Path traversal vulnerability in GitLab
ThreatNoir Morning Brief — September 15
Morning Review in IT Security — September 15, 2026
September 15, 2026 brings critical security developments across multiple threat vectors, from supply chain vulnerabilities to sophisticated nation-state campaigns and hardware-level attacks. Organizations face urgent patching requirements and emerging threats that demand immediate attention.
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 represents a critical threat to software supply chains worldwide. This path traversal vulnerability carries a maximum CVSS score of 10.0 and affects both GitLab Community Edition and Enterprise Edition instances. The severity of this flaw demands immediate patching across all affected deployments, as the vulnerability's potential to compromise repository integrity could have cascading effects throughout dependent software projects and organizations.
Source: Dark Reading
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a novel hardware attack called DDRop that fundamentally undermines the memory protection mechanisms in Intel TDX and AMD SEV-SNP confidential computing environments. The attack operates by silently dropping writes to server memory, causing processors to read outdated encrypted data as if it were current information. This sophisticated approach requires an attacker with prior software control of the target server and brief physical access to insert a specialized circuit, representing a significant evolution in hardware-level threats against cloud infrastructure and sensitive computing environments.
Source: The Hacker News
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
The Chinese threat actor Red Heron has been attributed to a coordinated campaign exploiting a recently disclosed remote code execution vulnerability in Gitea. The group rapidly targeted internet-facing Gitea instances across multiple nations, successfully compromising 13 organizations. According to the Acronis Threat Research Unit, Red Heron conducted reconnaissance of 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems, demonstrating systematic targeting of version control infrastructure. The campaign has been linked to the deployment of malware families JITTERLY and SIXZUT, indicating a sophisticated supply chain and infrastructure attack strategy.
Source: The Hacker News
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The notorious Russian threat group Sandworm has resumed operations with an upgraded variant of Cyclops Blink, the botnet malware that the FBI successfully disrupted in 2022. The group is exploiting chained Cisco vulnerabilities to deploy this revived malware, demonstrating continued sophistication in leveraging multiple attack vectors to compromise network infrastructure. This resurgence indicates that threat actors have invested in enhancing previously disrupted tools and remain focused on establishing persistent access to critical systems.
Source: Dark Reading
Conclusion
Today's threat landscape reflects an escalation across multiple attack categories, from maximum-severity software vulnerabilities affecting development infrastructure to nation-state actors deploying revived botnets and hardware-level attacks targeting cloud security foundations. Organizations must prioritize immediate patching of GitLab and Gitea instances, implement enhanced monitoring for Cisco infrastructure, and evaluate their resilience against both software and hardware-level threats in confidential computing environments.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Data Destruction: Archived by Attacker (related to memory manipulation)
- Gitea remote code execution vulnerability exploited by Red Heron.
- JITTERLYC++ Linux implant used by Red Heron for post-exploitation activities.
- SIXZUTLD_PRELOAD rootkit used by Red Heron to hide malicious activity.
- Cyclops BlinkUpgraded version of the botnet malware