CYBER DELTA FORCESearch

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.

CDF News DeskThe Hacker News14 Sept 2026, 10:26 pm
Image courtesy of The Hacker News. Original report
CDF REPORT

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

MORE IN VULNERABILITIES

More cybersecurity reporting

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesSecurityWeek · 15 Sept 2026, 4:36 pm4 in 5 Singapore Business Websites Have WordPress VulnerabilitiesThe Cyber Express · 15 Sept 2026, 1:53 pmCisco Secure Email Gateway zero-day exploited to gain root command executionThe Hacker News · 15 Sept 2026, 11:41 am'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · 15 Sept 2026, 3:07 am