Find notable cyber news and cases, enriched with sources, timelines, and signals.

Red Heron Gitea CVE-2026-60004 exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning framework. The activity has already driven compromises in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka and moved beyond initial access into repository theft and credential collection. The wave raises immediate risk for internet-facing self-hosted development platforms because exposed instances can be scanned at scale and quickly turned into persistent footholds.

Related Happenings

Red Heron Gitea RCE exploitation campaign

Campaign
H score17 First: 14.09.2026 19:56 Last: 14.09.2026 19:56 Sources 1

How related: "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,"

About this happening: The Red Heron campaign rapidly weaponized CVE-2026-60004 in Gitea to compromise internet-facing instances, exposing source code, credentials, and connected infrastruct...

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave
H score53 First: 05.09.2026 10:31 Last: 05.09.2026 10:31 Sources 1

About this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...

Gitea diffpatch endpoint RCE (CVE-2026-60004)

Vulnerability
H score41 First: 29.07.2026 10:47 Last: 29.07.2026 10:47 Sources 1

About this happening: CVE-2026-60004 is a critical remote code execution flaw in Gitea that lets a user with repository write access run shell commands as the Gitea service account. The...

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...

Timeline

  1. 14.09.2026 19:56 2 articles · 2h ago

    Red Heron weaponizes CVE-2026-60004 against internet-facing Gitea

    Exploitation Observed

    Red Heron began weaponizing CVE-2026-60004 against internet-facing Gitea instances, converting public proof-of-concept code into an automated Python framework called exp_enhanced.py and scanning thousands of instances across seven countries.

    Show sources
  2. 14.09.2026 19:56 1 articles · 2h ago

    Red Heron's Gitea campaign exposes JITTERLY, SIXZUT, and cross-border compromises

    Campaign Scope Update

    Red Heron's Gitea campaign was linked to 13 organizations across six countries, with compromises in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka, and analysis of a staging server uncovered the C++ Linux implant JITTERLY and the LD_PRELOAD rootkit SIXZUT. The activity progressed from source-code theft to credential collection, persistent access, lateral movement, and root-level access to a three-node Proxmox cluster.

    Show sources