Red Heron Uses Gitea RCE Across 13 Targets
7 Articles
7 Articles
Red Heron Uses Gitea RCE Across 13 Targets
Threat activity attributed to Red Heron exploited a remote code execution flaw in Gitea to compromise 13 organizations in six countries. The operation is described as a multi-country intrusion set focused on initial access through exposed code-hosting...
Red Heron exploits Gitea RCE flaw in multinational campaign targeting industrial and government organizations
Researchers from Acronis Threat Research Unit (TRU) detailed how a Chinese-speaking threat actor tracked as Red Heron exploited the critical CVE-2026-60004 remote code execution flaw in internet-facing Gitea instances within days of public proof-of-concept code appearing. The campaign scanned 1,386 Gitea instances across seven countries and maintained a separate database of 477 Taiwan-based systems, with
Acronis Uncovers Global Cyberattack Campaign Exploiting Software Flaw, Reveals New Hidden Malware
Acronis Threat Research Unit (TRU) has uncovered a global cyberattack campaign in which a Chinese-speaking hacking group, tracked as Red Heron, exploited a security flaw in Gitea, a widely used code-hosting platform, to break into organizations across several countries. The attackers stole source code, harvested login credentials, and in one case gained complete administrative control over a victim's entire server infrastructure. Acronis researc…
Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances
Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red Heron, quickly turned public exploit code into an automated attack framework that stole source code, collected credentials, installed backdoors, and moved deeper into victim networks. The […]
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)
The Acronis Threat Research Unit has uncovered an international attack campaign on publicly accessible Gitea servers. The Red Heron group automated the use of a critical vulnerability to steal source code, access data and internal configurations. The target was among other things organizations from the energy and industry sector as well as systems related to elections. A newly discovered Linux rootkit enabled the [...] The post Red Heron utilize…
Coverage Details
Bias Distribution
- 100% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium








