AUTO-UPDATED

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A China-linked threat actor known as Red Heron is exploiting a critical Gitea vulnerability to compromise government, defense, and research organizations across seven countries through automated attacks.

Key Points

  • Red Heron weaponized the CVE-2026-60004 remote code execution vulnerability to scan 1,386 Gitea instances globally.
  • The campaign utilizes a custom C++ Linux implant called JITTERLY and a stealthy rootkit named SIXZUT to maintain persistent access.
  • Confirmed compromises include targets in the United States, Taiwan, Canada, Argentina, Qatar, and Sri Lanka.
  • Attackers successfully moved laterally from compromised Gitea servers to gain root-level administrative access on a three-node Proxmox cluster.
  • Stolen data includes source code, SSH keys, configuration secrets, and internal tokens from sectors including energy, aerospace, and telecommunications.

Why it Matters

This campaign highlights the extreme speed at which threat actors can weaponize N-day vulnerabilities in self-hosted development platforms to gain deep network access. Organizations relying on Gitea or similar infrastructure must prioritize rapid patching to prevent attackers from stealing sensitive intellectual property and establishing long-term persistence.
Internet Published by info@thehackernews.com (The Hacker News)
Read original