Verification cutoff
September 15, 2026, 13:59 UTC.
Prepared by Jonathan Brown
Command View
This edition covers material verified through the cutoff above. “Active exploitation,” affected-version, and remediation statements are tied to named primary sources. Research telemetry, recovered attacker artifacts, exposure estimates, and victim-confirmed impact are identified separately.
Priority posture
- RED: Cisco confirms active exploitation of CVE-2026-76461 against Secure Email Gateway. Acronis documents Red Heron exploitation of CVE-2026-60004 against Gitea. Hunt.io’s recovered evidence establishes compromise of 3BB-linked telecom systems, although the FortiGate initial-access path remains unproven.
- AMBER: Automated exploitation attempts against exposed Vite development servers seek cloud credentials and infrastructure state. F5’s telemetry establishes scanning and exploit behavior, not a production-victim count.
- WATCH: Japan’s GSS intrusion is confirmed and contained, with approximately 246,000 personal-information records potentially exposed rather than confirmed stolen. Microsoft’s September 14 out-of-band updates address material RDS, Hyper-V shared-folder, and USB-audio regressions.
- CONTEXT: LiteSpeed, AOMEI, and Siemens disclosures require product-owner action, but no public evidence at the cutoff establishes current malicious exploitation of those weaknesses.
No newly verified destructive OT event or safety-system outage met the inclusion threshold by the cutoff.
Today’s decisions
- RED — Email security owners: identify every Cisco Secure Email Gateway appliance and virtual machine; move to the Cisco-fixed AsyncOS release for its train, then hunt each cluster member for compromise before declaring the fleet clean.
- RED — DevSecOps / platform owners: upgrade every Gitea deployment to 1.27.1 or later, restrict registration and public reachability, and treat suspicious hosts as potentially persistence-compromised rather than merely vulnerable.
- RED — Telecom / network owners: search for the 3BB campaign’s MeshCentral and infrastructure indicators; validate FortiGate SSL-VPN exposure and remediate CVE-2024-21762 without treating the recovered exploit as proof of the initial-entry route.
- AMBER — Cloud engineering: remove Vite development servers from public reach, update affected Vite and vite-plus versions, and rotate any cloud or deployment secrets that an exposed instance could return.
- WATCH — Government and remote-access owners: use Japan’s GSS case to override score-only patch queues for internet-facing VPN infrastructure; review whether “medium” flaws on high-value gateways can wait for ordinary maintenance windows.
- WATCH — Windows service owners: deploy Microsoft’s September 14 out-of-band fixes through a controlled change window; explicitly validate Remote Desktop Services, Hyper-V Linux guest shared folders, and multichannel USB audio.
Threat and Resilience Ledger
RED — Email security boundary | Global — Cisco Secure Email Gateway zero-day exploited for root command execution
An unauthenticated remote attacker can send a crafted email through an affected gateway, inject SQL, and progress to arbitrary command execution as root on the underlying operating system. Because the vulnerable device is an email trust boundary, compromise can expose message traffic, credentials, routing controls, and a privileged foothold into adjacent systems.
Cisco designates the flaw CVE-2026-76461, CWE-89, CVSS 3.1: 9.8 Critical. Cisco Secure Email Gateway physical and virtual appliances are affected regardless of configuration. Cisco Secure Email and Web Manager and Cisco Secure Web Appliance are not affected. Cisco’s fixed releases are:
- AsyncOS 15.5 and earlier: 15.5.5-014
- AsyncOS 16.0: 16.0.4-302
- AsyncOS 16.5: 16.5.0-780
Cisco strongly recommends migration to 16.5.0-780 where support and change constraints permit. Cisco states that Secure Email Cloud devices have been upgraded to 16.5.0-780.
Patch immediately; there is no workaround. Search mail_logs on every device in each cluster for suspicious COPY ... TO PROGRAM activity and compare appliance findings with external firewall, proxy, DNS, and transfer telemetry. Root access can alter or erase local evidence. For a suspected virtual-appliance compromise, preserve evidence, deploy a clean VM on a fixed release, rebuild configuration, renew credentials and cryptographic material, and monitor for re-entry. For suspected physical-appliance compromise, engage Cisco TAC.
Evidence: Cisco PSIRT says it became aware of active exploitation in September 2026 while investigating a TAC case. Cisco published advisory version 1.0 on September 14 at 16:00 GMT. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog the same day. This is vendor-confirmed exploitation, not scanning telemetry or a third-party exposure estimate.
Attribution: unknown.
Confidence: high for vulnerability, affected products, fixed versions, and exploitation; all are Cisco-confirmed.
Uncertainty: Cisco has not publicly described the attacker, victim count, campaign scope, payloads, or earliest exploitation date.
Sources: Cisco Security Advisory cisco-sa-esa-inj-2bLVGmhX, September 14, 2026; CVE Program — CVE-2026-76461; CISA item-specific alert, September 14, 2026; SecurityWeek corroboration.
RED — Source-code and virtualization control planes | Global — Red Heron weaponizes Gitea RCE across high-value sectors
Acronis Threat Research Unit reports that a Chinese-speaking actor it tracks as Red Heron used Gitea code execution to steal source code, collect credentials, persist, move laterally, and in one documented environment obtain root-level access to a three-node Proxmox cluster. Target labeling covered defense, elections, energy, aerospace, telecommunications, government, and research—making self-hosted source control a direct route into software, virtualization, and administrative trust planes.
CVE-2026-60004, CWE-94, CVSS 3.1: 9.8 Critical, affects Gitea 1.17 and later but earlier than 1.27.1; the patched version is 1.27.1. The diffpatch route can install and execute a Git hook. Exploitation requires repository write access, Git 2.32 or newer, the route enabled, and a writable/executable temporary filesystem. With default open registration, an outside visitor can create an account and repository and obtain the needed write access.
Upgrade to 1.27.1 or later; disable open registration unless required; restrict internet reachability and unneeded diffpatch access. Hunt for new accounts/repositories created after disclosure, diffpatch calls, Gitea-spawned shells or download tools, unexpected authorized_keys, /etc/ld.so.preload, libglthread.so.2, .ld_aux_cahe, and /tmp/.X11-unix.lk. The reported JITTERLY implant and SIXZUT LD_PRELOAD rootkit can hide activity and relaunch processes. If compromise is suspected, acquire evidence from known-good or offline media, rebuild, and rotate application secrets, tokens, database credentials, SSH material, and reachable service credentials.
Evidence: Acronis says it recovered attacker staging infrastructure and documented successful compromises in Canada, Argentina, Taiwan, the United States, and Sri Lanka. Its campaign analysis also describes scanning of 1,386 Gitea instances across seven countries and a separate 477-system Taiwan dataset. Those figures are research datasets and scanning scope, not a count of confirmed victims. The technical vulnerability and version range are independently documented in the Gitea GitHub security advisory.
Attribution: Acronis assesses a PRC-linked context with moderate confidence but does not map Red Heron to an established named group.
Confidence: high that exploitation occurred and that the listed versions are vulnerable; moderate on national alignment.
Uncertainty: the full victim count, persistence duration, and degree of victim validation outside Acronis’s recovered evidence remain undisclosed.
Sources: Acronis Threat Research Unit, “Red Heron Exploits Gitea N-Day Flaw in Multinational Campaign, Exposing New Linux Rootkit,” September 13, 2026; Gitea GitHub Security Advisory GHSA-rcr6-4jqh-j84m; CVE Program — CVE-2026-60004.
RED — Telecommunications and subscriber access | Thailand — 3BB environment compromised and subscriber-access systems targeted
Hunt.io recovered an exposed attacker staging directory and MeshCentral management data tied to 3BB / Triple T Broadband in Thailand. The artifacts show active connections to systems grouped as TH-3BB, root access on several hosts, internal activity against more than 55 systems, credential harvesting, and targeting of RADIUS databases. A persistent MeshCentral agent could preserve access after cleanup. A valid-looking OpenVPN certificate referencing the Jasmine network was also present; its current validity and any Jasmine compromise are not established.
The toolkit included a complete exploit and reverse-shell workflow for Fortinet CVE-2024-21762, an SSL-VPN out-of-bounds write. Hunt.io identified a targeted FortiGate 60F at a build consistent with approximately FortiOS 7.2.5. Vendor-designated affected FortiOS ranges are 7.4.0–7.4.2, 7.2.0–7.2.6, 7.0.0–7.0.13, 6.4.0–6.4.14, 6.2.0–6.2.15, and 6.0.0–6.0.16. Fixed releases are 7.4.3, 7.2.7, 7.0.14, 6.4.15, 6.2.16, and 6.0.17 or later in the respective trains.
Search for 92.63.180[.]133 on ports 8888/9443, www.ayuthayatech[.]com, MeshCentral group TH-3BB, /usr/local/bin/.rc, and /usr/local/mesh_services/meshagent/. Review unexpected root sessions, RADIUS queries, newly issued or reused VPN certificates, and deletion/cleanup activity. Patch affected FortiOS; if patching cannot be completed, disable SSL-VPN—the vendor states that disabling web mode alone is not sufficient. Rotate credentials and certificates reachable from any affected management or subscriber-access system.
Evidence: Hunt.io says it captured the directory on June 3, 2026; it contained 298 files, 30 directories, and roughly 19 MB of tools and output. Recovered internal command output and MeshCentral state support confirmed intrusion and privileged access. However, the recovered evidence does not conclusively establish CVE-2024-21762 as the initial-access vector, and attempts to access RADIUS data do not by themselves prove that subscriber records were exfiltrated. Hunt.io says it notified the affected parties and relevant CERT before publication.
Attribution: unknown.
Confidence: high for compromise of 3BB-linked systems and the recovered tools; moderate that the FortiGate flaw was used successfully against the target.
Uncertainty: initial access, dwell time, data theft, current persistence, and impact outside the observed environment are unconfirmed. No public 3BB incident statement was located by the cutoff.
Sources: Hunt.io, “Thai Broadband: FortiGate SSLVPN & MeshCentral Intrusion,” September 14, 2026; Fortinet PSIRT Advisory FG-IR-24-015; CVE Program — CVE-2024-21762; The Hacker News corroboration.
AMBER — Cloud and development exposure | Global — Automated Vite exploitation seeks cloud and infrastructure secrets
F5 Labs honeynet telemetry shows automated requests crafted to retrieve .env files, AWS and Azure credentials, Terraform state, deployment files, and process-environment data from internet-exposed Vite development servers. Disclosure of these files can convert a development-server mistake into cloud-account, database, CI/CD, or infrastructure takeover.
CVE-2026-39364, CWE-200, is rated CVSS 4.0: 8.2 High by the GitHub advisory. Affected Vite versions are 7.1.0–7.3.1 and 8.0.0–8.0.4; fixed versions are 7.3.2 and 8.0.5. vite-plus 0.1.15 and earlier is affected; 0.1.16 is fixed. An application is vulnerable only when the development server is exposed to the network, the sensitive file is within server.fs.allow, and a matching server.fs.deny rule is expected to block it. Vite binds to localhost by default.
Remove development servers from public reach; update to 7.3.2, 8.0.5, or vite-plus 0.1.16 as applicable. Hunt access logs for /@fs/ requests combined with ?raw, ?import&raw, ?import&url&inline, encoded traversal, and requests for .env, .aws, .azure, terraform.tfstate, serverless.yml, or /proc/*/environ. If an affected server was exposed, assume returned secrets may be compromised and rotate them; do not rely on attacker-supplied User-Agent, X-Forwarded-For, or X-Real-IP values for attribution.
Evidence: F5 recorded 807 session-grouped attacks and roughly 32,000 raw events during August 2026. Requests used @fs paths and query-string bypasses while cycling through credential and infrastructure-state wordlists. This is credible exploit-attempt telemetry against honeypots; it is not proof that 807 production systems were compromised or that any particular credential was successfully used.
Attribution: unknown; source infrastructure included cloud ranges and forged proxy headers, so apparent source countries are not reliable attribution.
Confidence: high for the vulnerable versions and observed scanning; medium for successful theft outside F5’s controlled telemetry.
Uncertainty: victim count, downstream cloud access, and campaign ownership are unknown.
Sources: F5 Labs, “Cloud Takeover: Mass Scanning for Exposed Vite Endpoints,” September 11, 2026; Vite GitHub Security Advisory GHSA-v2wj-q39q-566r; CVE Program — CVE-2026-39364.
WATCH — Government remote-access infrastructure | Japan — Government Solution Service discloses VPN-enabled intrusion
Japan’s Digital Agency says a third party exploited a known vulnerability in a VPN device protecting the Government Solution Service (GSS), used a maintenance-operations account to access large numbers of files, and may have exposed about 246,000 personal-information records concerning government personnel and people supporting government work.
The possible-exposure set includes approximately 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 addresses, with overlap among fields. It excludes the general public’s personal information and, according to the agency, does not contain My Number identifiers, bank-account data, or pension numbers. The agency detected abnormal file access on June 25, confirmed the VPN exploitation on July 9, disabled the maintenance account, isolated the equipment, patched the flaw, changed relevant credentials, and reported no subsequent suspicious access or communications. Government service availability was not disrupted.
Inventory internet-facing VPNs by business criticality as well as CVSS; shorten remediation deadlines for gateways that terminate privileged or government access. Alert on maintenance-account use outside approved windows, bulk file access, and VPN-to-administration pivots. Where supplier or CVE details are unavailable, use device logs, identity telemetry, credential rotation, and independent external-attack-surface validation rather than waiting for product attribution.
Evidence: These facts are from the Digital Agency’s September 11 announcement and September 12 Q&A. The agency says files containing the records may have leaked because exfiltration could not be ruled out; the 246,000 figure is not a confirmed count of stolen records. No related secondary misuse had been confirmed by the cutoff.
Attribution: unknown.
Confidence: high for the confirmed intrusion, exploited VPN weakness, timeline, containment, and possible-exposure set.
Uncertainty: the VPN vendor, product, version, and CVE remain undisclosed. The agency says the flaw was public before the attack and was initially rated Medium, but withholds technical details for security reasons.
Sources: Digital Agency, Government of Japan, incident announcement, September 11, 2026, and incident Q&A, updated September 12, 2026; BleepingComputer English-language corroboration.
WATCH — Operational reliability | Global — Microsoft issues out-of-band fixes for September update regressions
Microsoft reports that Windows updates released on September 8 can make Remote Desktop Services stop responding—blocking new sessions and, in some cases, local or remote sign-in—break host-folder sharing in Hyper-V-based Linux virtual machines, and disrupt some USB Audio Class 1.0 multichannel devices. Microsoft released out-of-band cumulative updates on September 14.
The relevant OOB updates are KB5129194 (Windows 11 26H1), KB5129195 (Windows 11 25H2/24H2), KB5129241 (hotpatch), KB5129242 (Windows 11 23H2), KB5129235 (Windows Server 2025), KB5129237 (Windows Server 2022), KB5129236 (Windows 10 22H2/LTSC 2021), KB5129238 (Windows 10 LTSC 2019/Server 2019), KB5129239 (Windows 10 LTSB 2016/Server 2016), KB5129243 (Windows Server 2012 R2), and KB5129244 (Windows Server 2012). Microsoft says the Windows 11 26H1/25H2/24H2 OOB packages also include the CVE-2026-62721 security fix; the 26H1 package additionally includes CVE-2026-85921.
Use an accelerated but staged deployment: test RDS brokers/session hosts, privileged-access jump systems, Hyper-V Linux guests that depend on shared folders, and affected audio workflows; then expand. Avoid a blanket uninstall of the September security update because removal also withdraws its security fixes. Maintain console or out-of-band administrative access during the change.
Evidence: Microsoft Windows message-center advisories and OOB release notices.
Confidence: high for affected functions and KB mapping.
Uncertainty: fleet-specific failure rates are not published and depend on role and configuration.
Sources: Microsoft Windows Message Center, September 14, 2026; Microsoft Update Catalog; BleepingComputer and The Verge corroboration.
Defensive Posture Changes
Email and edge appliances
- Move Cisco Secure Email Gateway from vulnerability-only handling to incident-exposure handling: patch plus evidence review, credential/material renewal, and rebuild when compromise is suspected.
- Require an owner and completion evidence for each physical appliance, VM, and cluster member; cloud status does not cover customer-managed appliances.
Source-code and virtualization control planes
- Treat internet-exposed Gitea with open registration as an external-code-execution surface, not a low-risk developer service.
- Separate Gitea service identities from hypervisor administration and secrets; enforce least privilege between repositories, CI/CD, databases, and Proxmox or other virtualization APIs.
- Rootkit-capable compromises require known-good/offline collection and rebuild criteria.
Telecom and remote access
- Correlate VPN exploitation, RMM/management agents, RADIUS access, and certificate use across separate log planes so cleanup on one host cannot erase the incident narrative.
- Elevate gateway patch priority based on control-plane consequence and reachability, not CVSS alone; Japan’s GSS incident demonstrates that a published Medium flaw can still produce high-value compromise.
Cloud and development exposure
- Block public Vite development services at ingress and CI/CD policy layers.
- Maintain a rotation playbook for
.env, cloud profiles, Terraform state, signing material, and deployment secrets exposed through file-read vulnerabilities.
Change reliability
- Treat Microsoft’s OOB packages as an availability restoration with security content. Validate emergency access before touching RDS or jump-host estates and keep rollback criteria role-specific.
Regional and Sector Pulse
North America — RED
Cisco’s globally deployed email-security gateway is under vendor-confirmed exploitation. Acronis also documented Red Heron compromises in Canada and the United States. North American operators should prioritize email-appliance hunting and Gitea control-plane review today.
Latin America and the Caribbean — RED
Acronis documented a successful Red Heron compromise in Argentina. No additional independently verified, region-specific destructive critical-systems event met the cutoff.
Europe — AMBER
F5 observed Vite exploit traffic using infrastructure in Belgium and the Netherlands, but cloud-hosting geography does not establish operator location or attribution. Microsoft’s OOB Windows remediation has broad European operational relevance. No verified new Europe-specific destructive OT incident met the cutoff.
Africa — CONTEXT
No independently verified new Africa-specific critical-systems compromise met the inclusion threshold by the cutoff. Global Cisco, Gitea, Vite, Windows, and VPN-edge actions still apply to exposed regional operators.
Middle East — CONTEXT
No independently verified new Middle East-specific critical-systems compromise met the inclusion threshold by the cutoff. The absence of a qualifying public report is not evidence of low threat activity.
Asia — RED
The 3BB compromise in Thailand includes privileged access and targeting of subscriber-authentication infrastructure. Japan confirmed exploitation of a known VPN flaw in GSS. Acronis documented a Red Heron compromise in Taiwan and targeting across high-value Asian sectors.
Russia — CONTEXT
No independently verified new Russia-specific critical-systems development met the cutoff. The 3BB campaign’s exposed staging infrastructure should not be geographically attributed from hosting data alone.
China — WATCH
Acronis assesses a PRC-linked context for Red Heron with moderate confidence based on recovered campaign evidence and Chinese-language targeting, but does not connect the actor to a recognized group. Treat this as an analytic attribution assessment, not government confirmation.
Indo-Pacific, including India — RED
Thailand, Taiwan, Japan, and Sri Lanka place the day’s confirmed or researcher-documented activity squarely in the Indo-Pacific. No India-specific compromise met the verification threshold, but regional operators should apply the Gitea, VPN, Cisco email-gateway, and Vite exposure actions.
Vulnerability and Supplier Watchlist
Cisco Secure Email Gateway
Issue: CVE-2026-76461, CWE-89; unauthenticated SQL injection leading to root command execution.
Affected scope: Cisco Secure Email Gateway physical and virtual appliances, regardless of configuration. Secure Email and Web Manager and Secure Web Appliance are not affected.
Fixed release: AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780 according to the installed train; Cisco strongly recommends 16.5.0-780 where supported.
Severity: CVSS 3.1: 9.8 Critical.
Status: RED — Cisco-confirmed active exploitation; no workaround.
Gitea
Issue: CVE-2026-60004, CWE-94; remote command execution through diffpatch Git-hook installation.
Affected scope: Gitea 1.17 and later but earlier than 1.27.1, subject to the documented Git, route, and filesystem prerequisites. Default open registration enables the no-prior-credentials path.
Fixed release: Gitea 1.27.1 or later.
Severity: CVSS 3.1: 9.8 Critical.
Status: RED — Acronis-documented campaign exploitation and successful compromise.
Fortinet FortiOS / 3BB campaign
Issue: CVE-2024-21762, SSL-VPN out-of-bounds write; a complete exploit and reverse-shell workflow appeared in the recovered 3BB-linked toolkit.
Affected scope: FortiOS 7.4.0–7.4.2, 7.2.0–7.2.6, 7.0.0–7.0.13, 6.4.0–6.4.14, 6.2.0–6.2.15, and 6.0.0–6.0.16.
Fixed release: 7.4.3, 7.2.7, 7.0.14, 6.4.15, 6.2.16, or 6.0.17 and later in the corresponding train.
Severity: Critical in the Fortinet advisory.
Status: RED for the confirmed 3BB-linked compromise; unproven as its initial-access CVE.
Vite / vite-plus
Issue: CVE-2026-39364, CWE-200; query manipulation can bypass server.fs.deny and return sensitive files.
Affected scope: Vite 7.1.0–7.3.1 and 8.0.0–8.0.4; vite-plus 0.1.15 and earlier. Exposure additionally requires a network-reachable development server and the documented server.fs.allow / server.fs.deny conditions.
Fixed release: Vite 7.3.2 or 8.0.5; vite-plus 0.1.16.
Severity: CVSS 4.0: 8.2 High.
Status: AMBER — mass exploit-attempt telemetry; no verified production-victim count.
Microsoft Windows September out-of-band updates
Issue: September 8 update regressions affecting Remote Desktop Services, Hyper-V Linux guest host-folder sharing, and some USB Audio Class 1.0 multichannel devices.
Affected scope: The Windows client and server branches mapped by Microsoft to KB5129194, KB5129195, KB5129241, KB5129242, KB5129235, KB5129237, KB5129236, KB5129238, KB5129239, KB5129243, and KB5129244.
Fixed release: The applicable September 14, 2026 out-of-band cumulative update.
Severity: Operational reliability condition; not a standalone vulnerability rating.
Status: WATCH — confirmed regressions with vendor fixes available.
LiteSpeed Web Server Enterprise
Issue: Critical privilege escalation allowing a malicious low-privilege website user to gain root on a shared server and cross isolation controls including CageFS.
Affected scope: LiteSpeed Web Server Enterprise earlier than 6.3.7. The notices do not establish OpenLiteSpeed exposure or the status of 6.4 release candidates.
Fixed release: LiteSpeed Web Server Enterprise 6.3.7 or later. LiteSpeed warned that auto-update availability could be delayed.
Severity: Described as Critical by cPanel; no CVE or CVSS score was published by the cutoff.
Status: WATCH — no public exploitation evidence, workaround, or indicators at cutoff.
AOMEI Backupper
Issue: CVE-2026-12780, CWE-732; incorrect permissions on amwrtdrv.sys permit an unprivileged local user to write arbitrary physical-disk sectors.
Affected scope: AOMEI Backupper 8.4.0. With Secure Boot disabled, the primitive can support pre-OS or UEFI-level code execution; BitLocker key exposure is configuration-dependent.
Fixed release: CERT/CC says to update to a corrected release but did not identify an exact fixed version in its September 14 revision.
Severity: Refer to the CERT/CC note and CVE record; do not infer an unpublished vendor score.
Status: WATCH — local access required and no active exploitation reported.
Siemens SCALANCE LPE9403
Issue: CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, and CVE-2025-40578; adjacent-network, unauthenticated memory-handling flaws that can crash the root-running DCP daemon.
Affected scope: Versions earlier than V4.0 HF0 for CVE-2025-40575 through CVE-2025-40577; all versions for CVE-2025-40578.
Fixed release: V4.0 HF0 or later for CVE-2025-40575 through CVE-2025-40577. Siemens states that no fix is planned for CVE-2025-40578.
Severity: CVSS 4.0: 5.3 Medium for each issue.
Status: WATCH — no exploitation reported; disable PROFINET DCP where operationally feasible.
Outlook and Uncertainty
Next 24 hours
Cisco exploitation detail. Expect additional incident-response reporting, indicators, or victim disclosures around CVE-2026-76461. Any new Cisco revision that changes fixed builds, rebuild guidance, or compromise indicators should trigger an immediate briefing update.
Copycat Gitea activity. Public exploit detail and confirmed campaign use make secondary opportunistic exploitation likely. A spike in newly registered accounts, repository creation, or diffpatch traffic should be treated as possible pre-exploitation activity.
3BB validation. A victim, CERT, Fortinet, or law-enforcement statement could clarify initial access, data loss, persistence, and current containment. Until then, keep “confirmed telecom compromise” separate from “FortiGate CVE proven as entry.”
Supplier clarification. Watch for a LiteSpeed CVE and root-cause mapping, an exact AOMEI fixed version, and any Siemens change to the no-fix status of CVE-2025-40578.
What is not known
Cisco attacker identity, campaign scale, earliest exploitation, and payload set.
Red Heron’s full victim count and independent confirmation of affected organizations.
3BB’s initial-access vector, subscriber-data impact, and current persistence status.
Japan GSS VPN vendor, product, version, CVE, and confirmed exfiltration.
Successful production compromise or cloud-token use arising from the observed Vite scanning.
LiteSpeed CVE/CVSS, affected 6.4 release-candidate status, exploitation, workaround, and indicators.
AOMEI’s exact fixed release and vendor-confirmed update path.
Trigger for escalation
Any COPY ... TO PROGRAM indicator or unexplained transfer activity on Cisco Secure Email Gateway.
Gitea service-child shells, new post-disclosure accounts/repositories, diffpatch anomalies, or LD_PRELOAD artifacts.
MeshCentral contact with the listed 3BB infrastructure, unexpected RADIUS access, or reuse of recovered VPN certificates.
Evidence that Vite-exposed credentials were used against cloud APIs, CI/CD, or state backends.
Widespread RDS or Hyper-V shared-folder failures after September security updates or the OOB rollout.
A vendor or government statement that changes any affected-version, fixed-version, exploitation, or impact assessment above.
Sources
Cisco Secure Email Gateway / CVE-2026-76461
Cisco security advisory:
CVE record:
https://www.cve.org/CVERecord?id=CVE-2026-76461
CISA item-specific alert:
Forwarding-safe reproduction of the CISA item:
https://www.cyberict.com/article/cisa-2026-09-14-cisa-adds-one-known-exploited-vulnerability-catalog
SecurityWeek corroboration:
Red Heron Gitea campaign / CVE-2026-60004
Acronis Threat Research Unit campaign analysis:
Gitea GitHub security advisory:
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
CVE record:
https://www.cve.org/CVERecord?id=CVE-2026-60004
3BB / Triple T Broadband intrusion and FortiGate tooling
Hunt.io primary investigation:
https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion
Fortinet PSIRT advisory FG-IR-24-015:
https://fortiguard.fortinet.com/psirt/FG-IR-24-015
CVE record:
https://www.cve.org/CVERecord?id=CVE-2024-21762
The Hacker News corroboration and initial-access qualification:
https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
Vite credential-scanning activity / CVE-2026-39364
F5 Labs primary telemetry report:
Vite GitHub security advisory:
https://github.com/vitejs/vite/security/advisories/GHSA-v2wj-q39q-566r
CVE record:
https://www.cve.org/CVERecord?id=CVE-2026-39364
Japan Government Solution Service intrusion
Digital Agency incident announcement:
https://www.digital.go.jp/news/2026-0911-01
Digital Agency incident Q&A:
https://www.digital.go.jp/press/5fc99139-a4e2-4b7b-8b0c-d475e926143f
BleepingComputer English-language corroboration:
Microsoft September out-of-band Windows updates
Microsoft Windows message center:
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center
Microsoft Update Catalog search for KB5129195:
https://www.catalog.update.microsoft.com/Search.aspx?q=KB5129195
BleepingComputer initial Remote Desktop Services issue report:
The Verge OOB update summary:
https://www.theverge.com/news/995302/microsoft-out-of-band-windows-11-update-fix-issues
LiteSpeed Web Server Enterprise privilege escalation
cPanel security advisory:
LiteSpeed 6.3.7 release announcement:
LiteSpeed Web Server changelog:
https://docs.litespeedtech.com/lsws/changelog/
The Hacker News report:
https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
AOMEI Backupper / CVE-2026-12780
CERT/CC Vulnerability Note VU#687587:
https://kb.cert.org/vuls/id/687587
CVE record:
https://www.cve.org/CVERecord?id=CVE-2026-12780
Siemens SCALANCE LPE9403 PROFINET DCP flaws
Siemens ProductCERT advisory SSA-327438:
https://cert-portal.siemens.com/productcert/html/ssa-327438.html
Nozomi Networks technical research:
CVE-2025-40575 record:
https://www.cve.org/CVERecord?id=CVE-2025-40575
CVE-2025-40576 record:
https://www.cve.org/CVERecord?id=CVE-2025-40576
CVE-2025-40577 record:
https://www.cve.org/CVERecord?id=CVE-2025-40577
CVE-2025-40578 record:
https://www.cve.org/CVERecord?id=CVE-2025-40578
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Member discussion: