Red Heron Exploits Gitea Flaw to Breach 13 Global Organizations

A Chinese-linked threat actor has rapidly weaponized a critical flaw in Gitea, a popular open-source code hosting platform, to compromise organizations in six countries. The attack moved quickly from initial access to deep system control, stealing sensitive code and credentials.
Cybersecurity researchers have identified a coordinated campaign by a threat actor tracked as Red Heron, which exploited a severe vulnerability in Gitea. This self-hosted platform is widely used by developers to manage source code. The group scanned nearly 1,400 instances across seven countries, with a specific focus on systems in Taiwan. The operation resulted in confirmed breaches at 13 organizations spanning Canada, Argentina, the United States, Qatar, Sri Lanka, and Taiwan.
The attackers did not just steal data; they established persistent control. In one notable incident, they moved from a vulnerable Gitea server to gaining root-level access on a multi-node Proxmox cluster. This allowed them to execute commands, transfer files, and hide their tracks. The campaign targeted sensitive sectors including defense, energy, aerospace, and government, indicating a focus on high-value intelligence collection.
Rapid Weaponization of Public Exploits
The speed of the attack is a key concern. Within days of the vulnerability, known as CVE-2026-60004, being disclosed, Red Heron converted public proof-of-concept code into an automated Python framework. This tool allowed them to register accounts, exploit servers, and steal repositories without manual intervention. As reported by The Hacker News, this highlights a critical risk: self-hosted development platforms often remain vulnerable long after patches are available, exposing source code and internal infrastructure to automated threats.
Advanced Tools for Evasion
To maintain access, the attackers deployed a sophisticated C++ implant named JITTERLY. This tool supports over 30 commands, including network tunneling and interactive terminal access, allowing for deep system control. More concerning is the presence of a rootkit called SIXZUT. This component hides files, processes, and network connections by patching core Linux functions. It also relaunches itself if terminated, making detection and removal significantly more difficult for defenders.
Broad Targeting of Critical Sectors
The scope of the data theft was extensive. From a Taiwanese industrial automation firm, the group exfiltrated hundreds of repositories related to SCADA tools and IoT integrations. A Qatar-based target lost data including AI chatbot code and workflow automation tools. The attackers also targeted Joomla-based websites and a quantitative trading firm in Argentina. This multi-vector approach suggests an intent to map out digital infrastructure rather than just stealing code, posing long-term security risks for affected organizations.






