This Week's Signals: A Gitea RCE Race, Boston Scientific Goes Dark, and Rowhammer Beats NVIDIA's ECC

Our weekly wrap of the stories that did not get a standalone piece: an actively exploited Gitea RCE, Boston Scientific's global disruption, GPUThor's Rowhammer break, Chrome's 300-plus fixes, a 12.9M Carhartt breach, the NovaCookies phishing kit, and Trump's grid-equipment order.

Share
The CyberSignal weekly security roundup, with the signature flat red dot on a navy field.

The throughline this week is speed. A critical Gitea flaw went from patch to active exploitation and a CISA emergency deadline in under a month, Australia and the US both flagged a TeamCity server bug already being hit, and AI keeps showing up on both sides of the ledger: finding the bugs, patching them, and now topping the list of risks executives lose sleep over. Below are the stories that did not get a standalone piece, each with the short version and what a defender should actually do. The marquee coverage is linked at the end.

Active Exploitation and Urgent Patches

Gitea RCE lands on CISA's KEV. A critical remote code execution flaw in the self-hosted Git service Gitea, CVE-2026-60004 (CVSS 9.8), is being exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on August 25 with a federal remediation deadline of August 28, The Hacker News reported. The bug lets an attacker who holds ordinary repository write access plant an executable Git hook and run shell commands as the Gitea service account, and where open registration is enabled that write access is a self-service signup away. It was fixed in v1.27.1 back in late July, and reported attacks have dropped a miner-like payload. If you run Gitea, patch to 1.27.1 or later now, disable open registration, and audit repositories for unexpected hooks. This is squarely a vulnerability management triage call: KEV listing plus a low access bar means treat it as an emergency, not a monthly-cycle item.

TeamCity flaw hit on two continents. Australia's cyber agency and CISA both warned of active exploitation of CVE-2026-63077, a critical authentication bypass in JetBrains TeamCity On-Premises rated CVSS 9.8 that lets an unauthenticated attacker with HTTP access run operating system commands, Infosecurity Magazine reported. It affects all On-Premises versions, and CISA has added it to the KEV catalog. TeamCity sits inside the CI/CD pipeline, so a compromise there is a supply-chain problem, not just one server. If you run it, update to 2025.11.7 or 2026.1.3, or install the security patch plugin, and then hunt for signs of prior access before you assume you patched in time.

Chrome 152 clears more than 300 bugs. Google shipped Chrome 152 with fixes for 327 vulnerabilities, 10 of them critical, and 299 of the total were found internally, most by Google's AI tooling, per SecurityWeek. The number is a milestone for machine-found bugs, but human researchers are still turning up the high-value ones, including a flaw that earned a $25,000 bounty. Browsers are a primary attack surface and these are the kind of memory-safety issues that lead to code execution, so push the update and confirm users restart, since an unrestarted browser stays vulnerable.

Ubiquiti patches a wall of UniFi flaws. Ubiquiti disclosed 22 CVEs across its UniFi line, three of them at the maximum CVSS 10.0 and all but one rated critical at 9.0 or higher, CyberScoop reported. The three 10.0 bugs chain into a worst case: an access-control bypass for entry, a path traversal for arbitrary file read and write, then command injection for full code execution on the UniFi OS host. UniFi gear is common in small and mid-size networks and often sits at the edge, so update affected controllers and consoles promptly and keep their management interfaces off the public internet.

Novel Research and a Rising Risk

GPUThor breaks NVIDIA's ECC defense. University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA RTX A6000 workstation GPUs using GDDR6 memory that defeats error-correcting code, the very mitigation NVIDIA recommends, and yields both denial of service and privilege escalation to a root shell on the host, The Hacker News reported. The unsettling part is that ECC silently "repairs" some induced errors to wrong values with no flag raised, so corruption happens invisibly. This is research, not mass exploitation, but it matters for shared GPU environments, AI training clusters, and multi-tenant workstations. Defenders running those workloads should track NVIDIA's guidance, avoid treating ECC as a complete Rowhammer answer, and factor physical and tenant isolation into GPU hosting decisions.

AI vulnerability discovery tops Gartner's risk list. In a Gartner survey of 316 companies conducted across April and May 2026, AI discovery of cyber vulnerabilities came back as the number one emerging risk of 20, its first appearance in the quarterly report and a jump from not being in the top five the prior quarter, which was led by information-integrity risk, Help Net Security reported. Gartner's Kevin Mercado warned that AI is "making it increasingly difficult for traditional risk management approaches to keep pace." The practical read links straight to the patch stories above: if machines find flaws faster than teams can fix them, ranking work by real exposure and known exploitation beats working a CVSS-sorted queue. It is worth folding into your AI security planning now, not next budget cycle.

Breaches and Disruption

Boston Scientific goes dark on shipments. The medical-device maker Boston Scientific disclosed a cyberattack causing a "global disruption" to operations, including its ability to process and ship customer orders, and filed an 8-K with the SEC, The Record reported. The company said it uncovered the incident on Tuesday and that "the timeline for a full restoration is not yet known," per TechCrunch, and its shares fell on the news. A disruption that halts device shipments has downstream clinical consequences, so hospitals and distributors that depend on Boston Scientific supply should check inventory and contingency sourcing now, and anyone in healthcare manufacturing should read this as a reminder that operational availability, not just data theft, is the loss that hurts.

Carhartt breach is real, but half the claim. Carhartt confirmed a breach affecting 12.9 million individuals, roughly half of what the extortion group ShinyHunters had claimed, after analysis showed the leaked set was heavily padded with synthetic records, The Register reported. Troy Hunt's review for Have I Been Pwned found telltale junk, more supposed customers in Montenegro than the US and a cluster of birth dates in the early 1900s, and AI-assisted filtering cut the genuine count down sharply. The defender takeaway is about triage, not panic: treat extortion-group victim totals as marketing until verified, because over-counting drives needless notifications and misdirected response. It also shows how useful automated analysis has become for separating real exposure from padded leaks.

Phishing and Policy

NovaCookies rents out Microsoft 365 session theft. Island disclosed NovaCookies, an adversary-in-the-middle phishing-as-a-service kit sold at $320 a month that abuses genuine Docusign notifications to lure victims and capture authenticated Microsoft 365 sign-in sessions in real time, The Hacker News reported. Because the lure rides a real Docusign envelope and can bounce through legitimate Microsoft or Google sign-in endpoints first, the whole chain looks trustworthy until the browser hits attacker infrastructure. Stealing the session token sidesteps the password and many second factors. Defenders should push phishing-resistant MFA (FIDO2 or passkeys), enforce conditional-access and token-binding controls, and watch for impossible-travel and new-device session anomalies rather than trusting a login just because the sender looked genuine.

Trump order targets foreign gear in the power grid. President Trump signed an executive order declaring a national emergency over the bulk-power system and barring foreign-produced equipment deemed a national-security risk from being purchased or installed in US energy infrastructure, a move driven by cyber threats, CyberScoop reported. The scope reaches transformers, generators, battery storage, grid-connected inverters, turbines, and industrial control systems, along with their software and remote-access capabilities, and the Department of Energy has 120 days to publish implementing rules. For utilities and their suppliers this shifts vendor sourcing into a compliance question, so start inventorying where grid equipment and its firmware come from. It is a policy layer on top of the same worry running through this week's critical infrastructure security stories.

Top Stories This Week

The bigger pieces we published this week, if you missed them:

My read: Two forces are pulling in opposite directions this week, and defenders sit in the gap. On one side, the disclosure-to-exploitation window keeps collapsing: Gitea, TeamCity, and the Ubiquiti stack all moved fast, and Gartner's survey names the reason out loud, AI now finds flaws faster than teams can close them. On the other side, that same automation is quietly useful, patching hundreds of Chrome bugs and deflating a padded Carhartt leak from a scary headline to a verifiable number. The move is the unglamorous one: an emergency lane for anything internet-facing that ignores the patch calendar, phishing-resistant MFA before the next NovaCookies-style kit lands, and prioritization driven by known exploitation rather than raw CVSS. And GPUThor plus Boston Scientific are the reminder that availability and hardware, not just stolen records, are where the real disruption shows up.

Primary documents: