Cybersecurity · September 15, 2026
A threat group tracked as Red Heron, suspected to have ties to China, has been rapidly weaponizing a newly disclosed remote code execution flaw in the Gitea git-hosting platform to breach internet-facing servers worldwide. Acronis's Threat Research Unit found the group scanned well over a thousand exposed Gitea instances spanning seven countries, with a particular focus on systems located in Taiwan. The campaign has reportedly compromised organizations across thirteen entities in six different nations.
// source: thehackernews.com ↗