Find notable cyber news and cases, enriched with sources, timelines, and signals.

Red Heron Gitea RCE exploitation campaign

Campaign
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

The Red Heron campaign rapidly weaponized CVE-2026-60004 in Gitea to compromise internet-facing instances, exposing source code, credentials, and connected infrastructure across multiple countries. The operation expanded from initial scanning into persistent access, credential collection, and lateral movement, including root-level access on a three-node Proxmox cluster. The activity matters because it combined fast exploitation with post-compromise follow-on access against organizations in multiple sectors.

Related Happenings

Red Heron Gitea CVE-2026-60004 exploitation wave

Exploitation Wave
H score22 First: 14.09.2026 19:56 Last: 14.09.2026 19:56 Sources 1

How related: "Red Heron has been observed weaponizing CVE-2026-60004, a critical Gitea remote code execution vulnerability, to scan thousands of instances across seven countries, turning a publicly-available exploit for the flaw into a full-fledged automated Python framework ("exp_enhanced.py") starting July 29, 2026."

About this happening: An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...

Timeline

  1. 14.09.2026 19:56 1 articles · 2h ago

    Red Heron weaponizes CVE-2026-60004 in Gitea

    Exploitation Observed

    Red Heron turned public proof-of-concept code for CVE-2026-60004 into an automated Python framework, exp_enhanced.py, and began scanning and exploiting internet-facing Gitea instances on July 29, 2026. The tooling registered accounts, exploited vulnerable servers, stole repositories, and removed selected traces while targeting systems across seven countries.

    Show sources
  2. 14.09.2026 19:56 2 articles · 2h ago

    Red Heron compromises 13 organizations across six countries

    Initial Disclosure

    Acronis TRU attributed the multi-national Gitea campaign to Red Heron, linking it to confirmed compromises in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka. The analysis said the activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster, and identified a staging server hosting the JITTERLY implant and the SIXZUT LD_PRELOAD rootkit.

    Show sources