Key Facts
Acronis Threat Research Unit reports that Red Heron weaponized CVE-2026-60004 against internet-facing Gitea instances. The reported activity included source-code theft, credential collection, persistence, and lateral movement.
Technical Details
Acronis reports that the actor scanned 1,386 Gitea instances across seven countries and used an automated framework based on public proof-of-concept code. Its researchers also describe JITTERLY, a Linux implant containing an LD_PRELOAD rootkit they track as SIXZUT.
Impact & Mitigation
Gitea operators should apply the vendor’s security update and investigate exposed instances for unauthorized account creation, repository access, or suspicious Git-hook activity. Acronis reports that CVE-2026-60004 was patched in Gitea 1.27.1.
