Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Red Heron Uses Gitea Exploit to Breach Global Firms

Red Heron Uses Gitea Exploit to Breach Global Firms

Posted on September 14, 2026 By CWS

A cyber espionage group, identified as Red Heron, has been linked to the swift exploitation of a newly revealed vulnerability in Gitea. This breach has impacted several organizations across six countries, indicating a multi-national campaign.

Details of the Gitea Exploit

The Acronis Threat Research Unit (TRU) reported that Red Heron conducted a scan of 1,386 Gitea instances spanning seven countries. A specific focus was placed on 477 systems located in Taiwan. The threat actor’s activities evolved from stealing source codes to gaining persistent access and conducting credential collection. This included achieving root-level access to a Proxmox cluster comprising three nodes.

The attack compromised organizations in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka. Red Heron categorized its targets using Simplified Chinese, concentrating on sectors such as defense, telecommunications, aerospace, and research.

Technical Insights into Red Heron’s Methods

Red Heron is suspected of operating with connections to China, supported by the use of Simplified Chinese and a targeting strategy aligned with Chinese intelligence priorities. A detailed analysis of a staging server revealed a C++ Linux implant named JITTERLY, capable of executing over 30 post-exploitation commands. These include shell execution and network tunneling.

Additionally, a rootkit labeled SIXZUT was identified within the backdoor, able to conceal files and processes by altering multiple Linux functions. This allows the malware to operate undetected and persist even after termination.

Exploitation and Broader Impact

The exploitation of CVE-2026-60004, a significant Gitea remote code execution vulnerability, was weaponized by Red Heron. The group adapted publicly available exploit code into a sophisticated Python framework, swiftly implementing this strategy following the vulnerability’s disclosure in July 2026.

Within a short timeframe, Red Heron automated the process of registering accounts, exploiting vulnerable servers, and removing traces. This rapid adaptation highlights the risks posed by vulnerabilities in self-hosted development platforms, which can be leveraged to access sensitive information.

In Taiwan, Red Heron transitioned from a vulnerable Gitea instance to gaining root-level administrative access across a Proxmox cluster. Further investigations revealed the group’s strategies, which included targeting Joomla websites and exfiltrating sensitive data from various industries, including industrial automation and renewable energy.

Implications and Future Considerations

Red Heron’s campaign underscores the critical need for robust cybersecurity measures. The group’s focus on sectors such as elections, defense, and energy indicates a strategic intent to gather intelligence while opportunistically exploiting available vulnerabilities.

The incident serves as a reminder of the importance of promptly addressing newly disclosed vulnerabilities to prevent exploitation and protect sensitive information.

The Hacker News Tags:China-linked threat, CVE-2026-60004, cyber espionage, Cybersecurity, Gitea, JITTERLY, Linux implant, Proxmox cluster, Red Heron, SIXZUT, Vulnerability

Post navigation

Previous Post: Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
Next Post: Massive Vite Server Vulnerability Exploited for Cloud Credential Theft

Related Posts

GodDamn Ransomware Employs PoisonX to Bypass Security GodDamn Ransomware Employs PoisonX to Bypass Security The Hacker News
Active Exploitation Detected in Gladinet and TrioFox Vulnerability Active Exploitation Detected in Gladinet and TrioFox Vulnerability The Hacker News
New Malware Threats: WordlistLoader and SynkLoader Unveiled New Malware Threats: WordlistLoader and SynkLoader Unveiled The Hacker News
AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories The Hacker News
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over  Billion Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion The Hacker News
Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark