www.acronis.com Red Heron Exploits Gitea Vulnerability in Multinational Cyber Campaign
Article Content
- •Red Heron exploited CVE-2026-60004 in Gitea, affecting 1,386 instances across seven countries.
- •The campaign involved source-code theft and lateral movement, impacting multiple sectors.
- •JITTERLY implant and SIXZUT rootkit were used for post-exploitation activities.
A Chinese-speaking threat actor known as Red Heron has exploited CVE-2026-60004, a recently disclosed remote code execution vulnerability in Gitea, to compromise 1,386 instances across seven countries. The campaign has led to confirmed breaches affecting organizations in Canada, Argentina, Taiwan, the United States, Qatar, and Sri Lanka. Red Heron utilized an automated framework to scan for vulnerabilities, leading to source-code theft, credential collection, and lateral movement within compromised networks. The actor's operations included root-level access to a three-node Proxmox cluster and the deployment of a C++ Linux implant named JITTERLY, which supports over 30 post-exploitation commands. Additionally, a previously undocumented rootkit, SIXZUT, was discovered, capable of hiding malicious activities. The rapid exploitation of this n-day vulnerability highlights the risks associated with self-hosted development platforms. Current assessments indicate Red Heron operates within a context linked to the People's Republic of China.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Red Heron, Jitterly and CVE-2026-60004 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…