Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
- ID
- 24320
- Status
- summarized
- Published
- 15 Sep 2026, 12:56 AM
- Fetched
- 15 Sep 2026, 4:45 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 15 Sep 2026, 4:48 AM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
A suspected Chinese threat actor dubbed Red Heron is actively exploiting CVE-2026-60004, a critical remote code execution vulnerability in Gitea, scanning 1,386 instances across seven countries and confirming compromises at 13 organizations in six countries. The campaign progressed from source-code theft to root-level access on a three-node Proxmox cluster, using a C++ Linux implant called JITTERLY (30+ post-exploitation commands) and an LD_PRELOAD rootkit named SIXZUT that patches 15 Linux functions to hide its presence.
Why it matters
If you self-host Gitea for your code repositories, patch CVE-2026-60004 immediately or move to an isolated, non-internet-facing setup—Red Heron is scanning thousands of instances and the attack chain goes from RCE to source-code theft to full infrastructure compromise including Proxmox clusters. This is not theoretical; 13 organizations across six countries are already confirmed compromised.
Discussion angle
How many of us are running self-hosted Gitea or similar Git services exposed to the internet, and what's our patching discipline for self-hosted dev infrastructure versus managed services like GitHub or GitLab?