Rose debug info
---------------

Programmer’s Digest #202

09/09/2026-09/16/2026 Red Heron Exploits Gitea RCE; GitLab CVE-2026-85706; CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV.

1. Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A suspected Chinese threat actor dubbed Red Heron has rapidly exploited CVE-2026-60004, a critical Gitea RCE flaw, scanning 1,386 instances across seven countries. Within days of the July 2026 disclosure, the group turned public PoC code into an automated Python framework, progressing from source-code theft to persistent access, credential harvesting, and lateral movement — including root access to a Taiwanese Proxmox cluster.

Confirmed compromises span Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka, hitting defense, election, energy, aerospace, telecom, and government targets. Acronis links the group to China with moderate confidence, citing Simplified Chinese labeling and targeting patterns. A staging server revealed JITTERLY, a C++ Linux implant supporting 30+ post-exploitation commands, paired with SIXZUT, an undocumented LD_PRELOAD rootkit that hides malicious activity across 15 Linux functions. Researchers found no evidence AI was used to build the framework.

2. GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

GitLab disclosed CVE-2026-85706 (CVSS 10.0) on September 10, 2026 — a path traversal flaw in its repository commits API that can expose SSH keys, database credentials, deploy tokens, and CI/CD variables via a single crafted request. Active exploitation began within 24 hours, and CISA has added it to its Known Exploited Vulnerabilities catalog. watchTowr researchers report in-the-wild probes already targeting the flaw and recommend patching public-facing self-hosted instances immediately or restricting access, while hunting logs for POST requests to the commits API containing “file.path” parameters.

Affected: Community and Enterprise Edition versions 18.7–19.1.8, 19.2–19.2.6, and 19.3–19.3.2. The same update also fixes CVE-2026-87719, an insecure deserialization bug exposing search configuration and credentials.

Post-patch, organizations should rotate potentially exposed credentials and check for compromise. GitLab’s CVE-2023-2825, a similar flaw, was also exploited within days — this one moved even faster.

3. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

CISA added five actively exploited flaws to its KEV catalog, covering JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Two Artifactory bugs (CVE-2026-42016, CVE-2026-42018) are being chained with a third, previously known flaw to bypass auth and gain admin control of self-hosted servers—Wiz observed attackers creating persistent admin accounts, deploying malicious Groovy plugins, and installing Rust-based backdoors between August 15 and September 8.

A ScreenConnect flaw (CVE-2026-84869, CVSS 9.9) lets attackers transfer and execute files through active remote sessions without authorization; Huntress linked it to three incidents spreading malicious VBScript payloads. Two RouterOS flaws, dubbed “MikroTrick” by CERT Polska, allow unauthenticated attackers to seize device control.

Federal agencies must patch RouterOS by September 13, ScreenConnect by September 14, and Artifactory by September 25. Organizations running these products should update immediately given confirmed in-the-wild exploitation.

4. CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

CISA added three actively exploited flaws to its KEV catalog, giving federal agencies until September 12 to patch: CVE-2026-20079 (CVSS 10.0), a Cisco Secure FMC authentication bypass allowing root access, now linked to three post-compromise clusters deploying web shells; CVE-2026-19490 (CVSS 9.3), a Citrix NetScaler auth bypass seeing active honeypot exploitation attempts; and CVE-2025-25249 (CVSS 7.3), a Fortinet buffer overflow tied to a Russian-speaking actor’s PivotC2 campaign, which has infected 178 devices across 3,000+ targeted IPs, mostly in the US.

Cisco separately confirmed exploitation of its flaw since August, and researchers note a broader pattern of China- and Russia-linked actors using compromised edge devices—including Cisco routers—as persistent footholds for espionage and financial gain, exploiting weak monitoring on perimeter appliances.

Organizations are urged to patch immediately, rotate credentials, and hunt for indicators of compromise.

5. AI-powered Attack Exploited PaperCut Flaws To Hack 395 Organizations

A likely Russian-speaking threat actor deployed hundreds of AI agents—combining OpenAI Codex and DeepSeek with commodity offensive tools—to build and run a global exploitation campaign against PaperCut NG/MF servers, according to GreyNoise. The agents developed exploits for two actively exploited flaws, CVE-2026-81578 and CVE-2026-82078, and used the Netlas scanning platform to generate target lists.

Since starting on August 31, the campaign has compromised at least 440 instances across 395 organizations in 48 countries, harvesting credentials from 280 victims and gaining admin privileges at 12. Education was hit hardest, with the US as the top target.

GreyNoise says the speed was extreme: RCE against a real victim in under four hours from an empty workspace, and one high school compromised end-to-end in seven minutes. Post-exploitation relied on DCSync to dump full domain credential databases, using tools like Mimikatz, Certipy, BloodHound, and Impacket.

Admins should apply PaperCut’s emergency patches immediately.

8 h   digest   programmers'