CVE Tools
Back to feed
Exploited in the wild Gitea Red Heron nation-state rce

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

A suspected Chinese state-linked threat actor named Red Heron has actively exploited the critical remote code execution vulnerability CVE-2026-60004 in Gitea, resulting in confirmed compromises across thirteen organizations in six countries. The campaign, which began shortly after the flaw's disclosure, involves automated scanning and exploitation to steal source code, credentials, and internal infrastructure details from victims in sectors such as defense, energy, and government.

The attackers deployed a Linux implant called JITTERLY along with a newly discovered LD_PRELOAD rootkit named SIXZUT to maintain persistence and evade detection by hiding processes and files. Analysis indicates that the group achieved root-level access on some victim networks, including moving laterally through a three-node Proxmox cluster in Taiwan.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store