AI Weekly Malaysia

Back to items Summaries

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

ID
24320
Status
summarized
Published
15 Sep 2026, 12:56 AM
Fetched
15 Sep 2026, 4:45 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
15 Sep 2026, 4:48 AM
Tags
Audience
developersvibe_coderssaas_founders

What happened

A suspected Chinese threat actor dubbed Red Heron is actively exploiting CVE-2026-60004, a critical remote code execution vulnerability in Gitea, scanning 1,386 instances across seven countries and confirming compromises at 13 organizations in six countries. The campaign progressed from source-code theft to root-level access on a three-node Proxmox cluster, using a C++ Linux implant called JITTERLY (30+ post-exploitation commands) and an LD_PRELOAD rootkit named SIXZUT that patches 15 Linux functions to hide its presence.

Why it matters

If you self-host Gitea for your code repositories, patch CVE-2026-60004 immediately or move to an isolated, non-internet-facing setup—Red Heron is scanning thousands of instances and the attack chain goes from RCE to source-code theft to full infrastructure compromise including Proxmox clusters. This is not theoretical; 13 organizations across six countries are already confirmed compromised.

Discussion angle

How many of us are running self-hosted Gitea or similar Git services exposed to the internet, and what's our patching discipline for self-hosted dev infrastructure versus managed services like GitHub or GitLab?

Top