
highCyber Attacks
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Acronis Threat Research Unit has attributed a rapid exploitation campaign targeting internet-facing Gitea instances to a Chinese threat actor tracked as Red Heron. The actor scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems. Thirteen organizations across six countries have been confirmed compromised, with potential access to source code, CI/CD pipelines, and sensitive data. The exact CVE identifier and patch details were not specified in the reported snippet.
The Hacker News1 min read