Red Heron Gitea RCE exploitation campaign
Campaign
Summary
Hide ▲
Show ▼
The Red Heron campaign rapidly weaponized CVE-2026-60004 in Gitea to compromise internet-facing instances, exposing source code, credentials, and connected infrastructure across multiple countries. The operation expanded from initial scanning into persistent access, credential collection, and lateral movement, including root-level access on a three-node Proxmox cluster. The activity matters because it combined fast exploitation with post-compromise follow-on access against organizations in multiple sectors.
Related Happenings
Red Heron Gitea CVE-2026-60004 exploitation wave
Exploitation Wave
H score22
First: 14.09.2026 19:56
Last: 14.09.2026 19:56
Sources 1
How related:
"Red Heron has been observed weaponizing CVE-2026-60004, a critical Gitea remote code execution vulnerability, to scan thousands of instances across seven countries, turning a publicly-available exploit for the flaw into a full-fledged automated Python framework ("exp_enhanced.py") starting July 29, 2026."
About this happening:
An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...
Red Heron Gitea CVE-2026-60004 exploitation wave
Exploitation WaveHow related: "Red Heron has been observed weaponizing CVE-2026-60004, a critical Gitea remote code execution vulnerability, to scan thousands of instances across seven countries, turning a publicly-available exploit for the flaw into a full-fledged automated Python framework ("exp_enhanced.py") starting July 29, 2026."
About this happening: An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...
Timeline
-
14.09.2026 19:56 1 articles · 2h ago
Red Heron weaponizes CVE-2026-60004 in Gitea
Exploitation ObservedRed Heron turned public proof-of-concept code for CVE-2026-60004 into an automated Python framework, exp_enhanced.py, and began scanning and exploiting internet-facing Gitea instances on July 29, 2026. The tooling registered accounts, exploited vulnerable servers, stole repositories, and removed selected traces while targeting systems across seven countries.
Show sources
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries — thehackernews.com — 14.09.2026 19:56
-
14.09.2026 19:56 2 articles · 2h ago
Red Heron compromises 13 organizations across six countries
Initial DisclosureAcronis TRU attributed the multi-national Gitea campaign to Red Heron, linking it to confirmed compromises in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka. The analysis said the activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster, and identified a staging server hosting the JITTERLY implant and the SIXZUT LD_PRELOAD rootkit.
Show sources
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries — thehackernews.com — 14.09.2026 19:56
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries — thehackernews.com — 14.09.2026 19:56