Key Facts

Acronis Threat Research Unit reports that Red Heron weaponized CVE-2026-60004 against internet-facing Gitea instances. The reported activity included source-code theft, credential collection, persistence, and lateral movement.

Technical Details

Acronis reports that the actor scanned 1,386 Gitea instances across seven countries and used an automated framework based on public proof-of-concept code. Its researchers also describe JITTERLY, a Linux implant containing an LD_PRELOAD rootkit they track as SIXZUT.

Impact & Mitigation

Gitea operators should apply the vendor’s security update and investigate exposed instances for unauthorized account creation, repository access, or suspicious Git-hook activity. Acronis reports that CVE-2026-60004 was patched in Gitea 1.27.1.

Sources

By Allan