
Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Malware
A Chinese-speaking threat actor tracked as Red Heron has exploited a remote-code-execution vulnerability in Gitea to steal source code, establish persistence, and deploy a previously undocumented Linux rootkit. The campaign weaponized CVE-2026-60004, a CVSS 9.8 flaw in Gitea’s diffpatch functionality, within days of public proof-of-concept code emerging in July. The vulnerability affects Gitea versions 1.17 […]
The post Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Malware appeared first on Cyber Security News.