Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

Cybersecurity · September 15, 2026

Cybersecurity·thehackernews.com

A threat group tracked as Red Heron, suspected to have ties to China, has been rapidly weaponizing a newly disclosed remote code execution flaw in the Gitea git-hosting platform to breach internet-facing servers worldwide. Acronis's Threat Research Unit found the group scanned well over a thousand exposed Gitea instances spanning seven countries, with a particular focus on systems located in Taiwan. The campaign has reportedly compromised organizations across thirteen entities in six different nations.

// source: thehackernews.com ↗

Back to Blog