https://reddit.com/r/cybersecurity/comments/1wgh4hr/red_heron_exploits_gitea_nday_flaw_in/: Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
Published Sep 14, 2026
·Updated
Affected Software
1 affected component
gitea=CVE-2026-60004
Frequently Asked Questions
1
Which deployments appear to be most exposed?
Internet-facing Gitea instances were targeted. The actor scanned 1,386 instances across seven countries and maintained a separate dataset of 477 systems in Taiwan.
2
What impact was observed after compromise?
The campaign progressed from source-code theft to persistent access, credential collection, and lateral movement. In one case, the actor obtained root-level access to a three-node Proxmox cluster.
3
Which types of organizations were prioritized?
The actor’s target classifications included defense, elections, energy, aerospace, telecommunications, government, and research. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka.