SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

Red Heron

❔ UnknownLast active: 2026-09-23First seen: 2026-09-15
12
linked CVEs
Targeted industries
DefenseGovernmentEnergyAerospaceTelecommunicationsEducationFinanceTechnologyNGO
Targeted regions
United States of AmericaAlbaniaAustraliaAustriaBelarusBelgiumBrazilBritish Indian Ocean TerritoryBulgariaChileChinaColombiaCosta RicaCzechiaDenmarkEstoniaFinlandFranceGermanyGreeceGuadeloupeHong KongHungaryIcelandIndiaIran, Islamic Republic ofIrelandItalyJapanLatviaLithuaniaMadagascarMalaysiaMaltaMartiniqueMonacoMongoliaNetherlandsNorwayPakistanPanamaPhilippinesPolandPortugalRomaniaRussian FederationSlovakiaSloveniaSouth AfricaSpainSwedenSwitzerlandTaiwanThailandUkraineUnited Arab EmiratesUnited Kingdom of Great Britain and Northern IrelandUzbekistan
A Chinese-speaking threat actor tracked as Red Heron rapidly weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, within days of public disclosure in July 2026. The actor scanned 1,386 Gitea instances across seven countries, successfully compromising organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka. Activities included source code theft, credential collection, SSH persistence, and lateral movement, with one case escalating from a vulnerable Gitea server to root access across a three-node Proxmox cluster. An exposed staging server revealed targeting taxonomies using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, and government sectors. The campaign deployed JITTERLY, a C++ Linux implant with 30+ post-exploitation commands, embedding SIXZUT, a previously undocumented LD_PRELOAD rootkit capable of hiding files, processes, and network connections while protecting the implant from termination.
Source: otx · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits12 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2026-34908
suspected

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

CVSS 10.0
KEV
CVE-2026-34909
suspected

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

CVSS 10.0
KEV
CVE-2026-34910
suspected

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

CVSS 10.0
KEV
CVE-2023-54391
suspected

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

CVSS 9.8
CVE-2026-54569
suspected

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many, and getusers, do not enforce the senaite.core: Access JSON API permission before resolving attacker-selected objects. In src/bika/lims/jsonapi/init.py, set_fields_from_request passes raw request values for RecordsField and RecordField instances to eval() before field mutator write-permission checks execute. An anonymous attacker can discover the bika_setup object identifier through @@uuid, send a value such as RejectionReasons to /@@API/update, and execute arbitrary Python in the Zope worker before a later mutation failure rolls back ZODB changes. The same unsafe evaluation pattern is present in src/senaite/core/browser/fields/record.py and src/senaite/core/browser/fields/records.py. Successful exploitation can expose or modify laboratory data, files, and accounts and can disrupt the service.

CVSS 9.8
CVE-2026-56271
suspected

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and impersonate any user, including administrators, resulting in authentication bypass.

CVSS 9.8
CVE-2026-60004
suspected

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVSS 9.8
KEV
CVE-2026-63030
suspected

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

CVSS 9.8
KEV
CVE-2026-7273
suspected

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

CVSS 8.8
KEV
CVE-2026-60137
suspected

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

CVSS 5.9
KEV
CVE-2022-0847
suspected

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

KEV
CVE-2026-79756
suspected

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboard on the local/Docker platform is incomplete. The fix added validateFunctionName for function names and common.Quote() for the named-resource shell command path, but the list-all resource path (triggered when no specific resource name is provided) still interpolates the resourceNamespace parameter unquoted into a /bin/sh -c command string. An unauthenticated attacker can inject shell metacharacters via the X-Nuclio-Function-Namespace, X-Nuclio-Project-Namespace, or X-Nuclio-Function-Event-Namespace HTTP headers to achieve arbitrary command execution inside the dashboard container. This issue has been patched in version 1.17.4.

🔍 Detection Coverage3 Sigma
Derived from linked CVEs — not a direct actor match
criticalvia CVE-2026-60137
WordPress Wp2shell Webshell Plugin Access
highvia CVE-2026-60137
WordPress Wp2shell Exploitation Tool User-Agent
mediumvia CVE-2026-60137
WordPress Wp2shell REST Batch Endpoint Exploitation
🧬 YaraComing soon
🛰️ Infrastructure & IOCs15
sha2562ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1—2026-09-23
sha2560f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6—2026-09-23
sha2560e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f—2026-09-23
ip74.48.66.73—2026-09-23
ip172.245.247.21—2026-09-23
domainp3.981666.xyz—2026-09-23
ip104.225.153.141—2026-09-23
urlhttps://gitea.redacted.com.ar/api/v1/metrics—2026-09-15
md53a1e96289832518bff2feeb868bc61a4—2026-09-15
domaingitea.redacted.com.ar—2026-09-15
sha25628b132ad55bd310bb5cf3ddb4ace580529ad735204a48cf388830d9039843d8e—2026-09-15
domainxcyoibfhuufz.com—2026-09-15
domains2.981666.xyz—2026-09-15
sha256b441f793c87e54cb7e3f7205e25442aa19920d325cb6af41d2afdc8a0b5cf54f—2026-09-15
md588264a49750b3280e63894fb7445a9c2—2026-09-15
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.