September 21, 2026 Emerging Threats Weekly

Sep 21, 2026

This week’s briefing covers:

00:00 – Intro

00:40 [VULNERABILITY] GitLab CVE-2026-85706 Moves From Patch Release to Confirmed Exploitation
GitLab's CVE-2026-85706 became a priority vulnerability during this reporting period because exploitation was confirmed shortly after GitLab shipped fixes. The flaw affects the repository commits API in self-managed GitLab Community Edition and Enterprise Edition

03:28 [CAMPAIGN] Automated Vite Scanning Targets Cloud Credentials in Exposed Development Environments
F5 Labs reported a sustained scanning campaign against internet-exposed Vite development servers, with activity highlighted on September 11. Its honeypot telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis window, a substantial increase over the earlier baseline.

06:24 [AI] AI-assisted Iranian Malware and Phishing Lowers the Barrier to Multi-stage Intrusion
Anthropic reported an Iranian threat actor, tracked as GTG-30006, that used free Claude.ai accounts across 16 single-operator organizations to develop malware, delivery infrastructure and a phishing portal. The disclosure was part of the September 10 threat report and is relevant to enterprise defenders because it shows how low-cost access to a general-purpose model can support a complete attack lifecycle without requiring a large specialist team.

09:25 [VULNERABILITY] Cisco Secure Email Gateway Zero-day Exposes the Mail Perimeter to Root Compromise
Researchers disclosed a new browser-based exploit kit, BlueMoon, that was already in operational use by at least four espionage-motivated clusters within days of its first observed deployment in late August. Proofpoint has not established how the actors obtained the kit, although the rapid adoption indicates that the capability was shared privately or supplied through a common source.

12:11 [THREAT ACTOR] Red Heron Rapidly Weaponizes Gitea and Deploys a New Linux Rootkit
A newly reported campaign tracked as Red Heron shows how quickly an actor can turn a public proof of concept into broad operational exploitation. According to reporting published on September 13, the actor weaponized CVE-2026-60004 in Gitea within days of the July 2026 advisory and used it to compromise internet-facing development platforms in multiple countries.

Dive deeper:

Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report

Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto

Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist

Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber

Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports

Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber

#krollcyber #threatintelligence #cyberthreats