hacker-news · Crawled Sep 14, 2026

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

2 IoCs 1 CVEs
Read original article ↗

AI Summary

A suspected Chinese threat actor known as Red Heron has exploited CVE-2026-60004, a critical remote code execution vulnerability in Gitea, to compromise 13 organizations across six countries. The campaign targeted sectors including defense, government, energy, and telecommunications, using automated exploitation to gain initial access, steal source code, and establish persistent access. The attackers deployed a custom Linux backdoor named JITTERLY and a novel LD_PRELOAD rootkit called SIXZUT to maintain stealth and enable post-exploitation activities such as credential theft, lateral movement, and data exfiltration.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Filename exp_enhanced.py Details →
Filename exp.py Details →