Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Target Gitea RCE Flaw to Hijack Servers

Hackers Target Gitea RCE Flaw to Hijack Servers

Posted on September 15, 2026 By CWS

Cybercriminals are currently exploiting a severe remote code execution (RCE) vulnerability in Gitea, a popular source-code management service. Known as CVE-2026-60004, this flaw is being used to compromise servers that are accessible via the internet.

Details of the Exploit

A group of Chinese-speaking hackers, identified as Red Heron, have rapidly developed an automated attack framework from public exploit code. This framework allows them to steal source code, harvest credentials, install backdoors, and further infiltrate networks of affected organizations.

The vulnerability impacts Gitea versions 1.17 to 1.27.0, earning a critical Common Vulnerability Scoring System (CVSS) score of 9.8. A patch was issued with version 1.27.1 on July 27, 2026, resolving the issue linked to Gitea’s diffpatch feature, which processes repository patches using Git commands.

Mechanics of the Attack

The attack exploits the Git three-way merge function to introduce a malicious file into the repository’s hook directory. This enables the execution of harmful commands with the Gitea service account privileges whenever Git performs an index operation. Although attackers need write access to a repository, numerous exposed Gitea setups permit new user registrations, allowing malicious actors to exploit the vulnerability without needing existing credentials.

The Acronis Threat Research Unit revealed that Red Heron scanned over 1,386 Gitea servers across seven countries shortly after the proof-of-concept was released, including a separate focus on 477 servers in Taiwan. This group categorizes its targets using Simplified Chinese terms for various sectors, such as defense, energy, and telecommunications.

Impact and Recommendations

Confirmed attacks have been observed in countries like Canada, Argentina, Taiwan, the United States, and Sri Lanka. Hackers have automated the process of account registration, target exploitation, repository downloading, and trace removal from affected databases.

One notable breach involved a Canadian renewable-energy company where attackers accessed a wide range of sensitive data and systems. Similarly, Taiwanese servers hosted on Synology NAS were targeted, and attackers gained significant control over Proxmox clusters, potentially enabling the theft of entire virtual machine disk images.

Researchers have connected these activities to a Linux malware named JITTERLY, which offers various malicious capabilities, including command execution and network pivoting, while using an embedded rootkit called SIXZUT to evade detection.

Organizations using self-hosted Gitea are advised to update to version 1.27.1 or later promptly, disable open registration unless necessary, limit access to internet-facing instances, and closely monitor new accounts and repositories. Additionally, it is crucial to treat any stored secrets as compromised and rotate them accordingly.

Cyber Security News Tags:CVE-2026-60004, cyber attack, Cybersecurity, data breach, Gitea, Gitea servers, JITTERLY, Linux implant, network security, RCE vulnerability, Red Heron, remote code execution, security patch, software vulnerability, Threat Actors

Post navigation

Previous Post: Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate

Related Posts

Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years Cyber Security News
CISA Warns of Windows SMB Vulnerability Actively Exploited in Attacks CISA Warns of Windows SMB Vulnerability Actively Exploited in Attacks Cyber Security News
2.86 Billion Stolen Credentials Impact Cybersecurity Landscape 2.86 Billion Stolen Credentials Impact Cybersecurity Landscape Cyber Security News
Jetflicks Illegal Paid Streaming Service Operators Jailed for 7 Years Jetflicks Illegal Paid Streaming Service Operators Jailed for 7 Years Cyber Security News
GitLab Releases Critical Security Updates to Fix Vulnerabilities GitLab Releases Critical Security Updates to Fix Vulnerabilities Cyber Security News
TP-Link Security Flaws Allow DoS Attacks on Cameras TP-Link Security Flaws Allow DoS Attacks on Cameras Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Target Gitea RCE Flaw to Hijack Servers
  • Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate
  • Major Vulnerabilities Found in WordPress Plugin
  • Microsoft Sets AI Cybersecurity Boundaries in New Code
  • Leading Kubernetes Security Tools for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Target Gitea RCE Flaw to Hijack Servers
  • Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate
  • Major Vulnerabilities Found in WordPress Plugin
  • Microsoft Sets AI Cybersecurity Boundaries in New Code
  • Leading Kubernetes Security Tools for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark