The Memory Was Encrypted and Also Stale (09/14/2026)
- › A hardware attack called DDRop defeats Intel TDX and AMD SEV-SNP by dropping writes so the processor reads stale encrypted data as current.
- › CISA confirmed active exploitation of the maximum severity GitLab flaw days after the patch landed.
- › The Chinese actor Red Heron scanned 1,386 Gitea instances and compromised 13 organizations across six countries.
- › A malicious Twitch browser extension leaked OAuth tokens from nearly 31,000 users to a Russian bot service.
- › A mass scanning campaign is targeting exposed Vite development servers to steal AWS and Azure credentials.
Confidential computing is the answer a great many organizations have given when asked how they can run sensitive workloads on somebody else’s hardware. The DDRop research does not break the encryption at all, which is what makes it worth reading. It makes the processor read old data and believe it is current.
Top 5 Critical Security Alerts
1. DDRop Defeats Confidential Computing Without Breaking the Crypto
Researchers disclosed a hardware attack called DDRop that undermines memory protection in Intel TDX and AMD SEV-SNP by silently dropping writes to a server’s memory, leaving the processor reading old encrypted values as though they were current. The attack requires physical access and a device on the memory bus, which puts it firmly in the hosting provider and supply chain threat model instead of the remote attacker one. Integrity and confidentiality are separate properties, and this class of work keeps demonstrating that a design can deliver the second without the first. The Hacker News has the research and The Register has the hardware detail.
Operator Note: If confidential computing is load-bearing in a compliance argument you have made to a customer or a regulator, go back and check whether that argument assumed integrity guarantees the technology does not provide.
2. The GitLab Maximum Severity Flaw Is Under Attack
CISA confirmed that attackers are exploiting the maximum severity GitLab path traversal flaw we covered on Friday, days after the patch was published and following in-the-wild probing within hours of disclosure. The interval from disclosure to confirmed exploitation was measured in days, which is shorter than most organizations’ emergency change process takes to approve a restart. Source repositories hold deployment configurations and CI variables, so file read against one is a credential problem. BleepingComputer has the confirmation and Infosecurity Magazine has the exploitation detail.
3. Red Heron Scanned 1,386 Gitea Instances and Hit 13
A Chinese threat actor tracked as Red Heron rapidly exploited a recently disclosed Gitea vulnerability, scanning 1,386 internet-facing instances across seven countries and compromising 13 organizations in six of them. The scan-to-compromise ratio is the useful number, because it says the operator was working an opportunistic list rather than selecting targets. Self-hosted developer infrastructure keeps appearing in these campaigns for the same reason every time, which is that it was stood up by a team that does not think of itself as running a production service. The Hacker News has the campaign.
Operator Note: Find every self-hosted developer service in your estate that answers from the internet, and decide today whether each one needs to.
4. A Twitch Extension Sent 31,000 OAuth Tokens to a Bot Service
A malicious cross-store browser extension calling itself Twitch Enhanced Viewer leaked OAuth tokens belonging to nearly 31,000 users to proxy servers run by a Russian commercial bot service. Browser extensions hold permissions most users grant once and never revisit, and an OAuth token is a live session rather than a password somebody can change. We wrote last week about extensions being the least examined software in most environments, and this is the version of that with a number attached. The Hacker News has the extension and Infosecurity Magazine has the scale.
5. Exposed Vite Dev Servers Are Being Mined for Cloud Keys
A mass scanning campaign is hitting internet-exposed Vite development servers to pull AWS and Azure credentials and configuration out of them. A development server is built to be permissive because it exists to make a developer’s day faster, and nothing about that design anticipated it answering from a public address. The credentials that end up in a local development configuration are frequently the ones nobody scoped down. BleepingComputer has the campaign.
Operator Note: Scan your own external ranges for development server default ports, because the person who exposed one did it to test something on a phone and has long since forgotten.
Additional Security Alerts
Threat Intelligence
- An attacker reached an SSH bastion eight seconds after exploiting Marimo: A human operator working at machine speed closed the gap between initial exploitation and lateral movement to a single breath. Infosecurity Magazine
- HBO Max’s Reddit account was hijacked to serve ClickFix ads: The compromised official account pushed malicious ads infecting both Windows and macOS with infostealers, which is the trusted-source version of a technique that already worked cold. BleepingComputer and TechCrunch
- Revolut has detailed what the fake government requests took: The fintech disclosed that data shared with an actor impersonating a government agency included financial information and passports. BleepingComputer
Patches and Platform Changes
- WordPress will review every plugin release before distribution: Automated security analysis now runs on each update before it reaches the update API, which moves the check ahead of the blast radius. The Hacker News
- September’s Windows Server updates are breaking Remote Desktop Services: Microsoft confirmed the RDS failures, which is worth knowing before you attribute an outage to something else. BleepingComputer
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.