Threat Intelligence

Suspected Chinese Hackers Exploit Gitea Flaw to Breach 13 Organisations Worldwide

The Hacker News · 15 Sept 2026
Key Takeaway Any organisation running a self-hosted Gitea instance should patch against CVE-2026-60004 immediately and check for signs of unauthorised access, as attackers are actively scanning for and exploiting this flaw worldwide.

A suspected China-linked threat actor tracked as Red Heron has been exploiting a recently disclosed critical vulnerability in Gitea, a popular self-hosted code repository platform, to compromise internet-facing servers around the world. Security researchers at Acronis found the group scanned nearly 1,400 Gitea instances across seven countries, with confirmed compromises in Canada, Argentina, Taiwan, the United States, Qatar and Sri Lanka. Affected sectors include defense, election infrastructure, energy, aerospace, telecommunications, government, public safety and research.

The attacks moved beyond simple source-code theft, escalating to persistent access, credential harvesting, and lateral movement, in one case reaching root-level control of a multi-node virtualisation cluster. Investigators linked the campaign to a Linux implant called JITTERLY, which can run shell commands, transfer files, tunnel network traffic and pivot within compromised environments. The implant also carries a previously unseen rootkit, SIXZUT, that hides malicious files, processes and network activity, and can relaunch itself if removed, making detection and cleanup significantly harder.

The vulnerability being exploited, CVE-2026-60004, is a critical remote code execution flaw in Gitea. Researchers noted the group turned a public proof-of-concept exploit into an automated scanning framework, allowing rapid, large-scale targeting of vulnerable servers.

Gitea RCE Vulnerability China-linked Threat Actor Linux Malware Rootkit

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.