<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Red Heron Hackers Exploit Critical Gitea Flaw to Hijack Servers

Attackers have compromised 13 organizations in six countries through a critical Gitea flaw. Upgrade to 1.27.1 and disable open registration.
Content Team

Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.

The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.

Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.

Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo