Critical

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

The Hacker News
Actively Exploited

Overview

A Chinese hacking group known as Red Heron has exploited a recently discovered vulnerability in Gitea, a platform for managing Git repositories. This group scanned over 1,300 Gitea instances across multiple countries, successfully compromising 13 organizations in six different nations. Notably, they maintained a separate list of nearly 500 systems based in Taiwan. The rapid exploitation of this vulnerability highlights the risks associated with internet-facing applications, especially when they are not adequately secured. Organizations running Gitea should take immediate action to assess their systems and apply necessary updates to prevent similar attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Gitea instances, particularly those exposed to the internet, especially in Taiwan.
  • Action Required: Organizations should assess their Gitea installations and apply any available security patches or updates as soon as possible.
  • Timeline: Newly disclosed

Original Article Summary

A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU) said in an

Impact

Gitea instances, particularly those exposed to the internet, especially in Taiwan.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should assess their Gitea installations and apply any available security patches or updates as soon as possible.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Vulnerability, RCE.

Related Coverage

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

The Hacker News

Cisco has issued a warning about a serious vulnerability in its AsyncOS software for the Cisco Secure Email Gateway, identified as CVE-2026-76461. This flaw, which has a CVSS score of 9.8, allows unauthenticated remote attackers to execute root commands due to insufficient validation in the email parsing logic. The vulnerability is currently being exploited in the wild, putting users at significant risk. Organizations using affected versions of the Cisco Secure Email Gateway should take immediate action to protect their systems. This incident underscores the importance of timely updates and vigilance in cybersecurity practices.

Sep 15, 2026

Homebrew 7.0.0 is out, here’s what changed for security

Help Net Security

Homebrew, a popular package manager for macOS and Linux, released version 7.0.0 on Sunday, addressing eight security vulnerabilities in the process. The most critical issue involved a flaw that allowed unsigned removal metadata for casks—Homebrew's method for installing prebuilt applications—to execute commands with elevated privileges (sudo). To mitigate this risk, the development team removed the vulnerable recovery code and the related API accessors that could be exploited. This update is particularly important for developers who rely on Homebrew for managing their software installations, as it helps protect their systems from potential abuse. Users are encouraged to update to the latest version to safeguard against these vulnerabilities.

Sep 15, 2026

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

BleepingComputer

Japan's Digital Agency has reported a significant data breach affecting around 246,000 records containing sensitive personal information of government employees. The breach is linked to a flaw in a Virtual Private Network (VPN), which allowed unauthorized access to these records. This incident raises concerns about the security of government digital infrastructure and the potential for misuse of the exposed data. With personal information at risk, affected individuals may face identity theft or other privacy violations. The agency is urging immediate action to address the vulnerability and protect sensitive information moving forward.

Sep 14, 2026

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

darkreading

A severe vulnerability identified as CVE-2026-85706 has been discovered in both the GitLab Community Edition and Enterprise Edition. This flaw is categorized as a path traversal vulnerability and carries a maximum CVSS score of 10 out of 10, indicating its potential for serious exploitation. Organizations using affected versions of GitLab could see significant risks to their software supply chains, as attackers could exploit this vulnerability to access sensitive files and data. Companies using these GitLab instances are urged to take immediate action to protect their systems and data. The urgency of addressing this issue is underscored by the potential for attackers to exploit it in real-world scenarios, putting countless users and organizations at risk.

Sep 14, 2026

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

The Hacker News

An attacker gained unauthorized access to the network of 3BB, a major broadband provider in Thailand, using a legitimate remote management tool called MeshCentral. This allowed the attacker to maintain control over internal machines and potentially harvest subscriber credentials. The breach was discovered by the cybersecurity firm Hunt.io, which found an exposed server containing the attacker’s tools and a list of compromised data. This incident raises concerns about the security of management tools and the potential for attackers to exploit legitimate software for malicious purposes. Users of 3BB and similar services should be vigilant about their account security and monitor for any suspicious activity.

Sep 14, 2026

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

The Hacker News

Researchers have identified a new hardware attack named DDRop that compromises memory protection in Intel and AMD's confidential computing systems. This attack allows an unauthorized user, who already has control over the server's software, to manipulate memory writes. By inserting a small circuit, the attacker can cause the processor to read outdated encrypted data as if it were current. This vulnerability poses significant risks for organizations relying on Intel TDX and AMD SEV-SNP technologies for secure computing, as it undermines the confidentiality of sensitive data. Companies using these systems should be aware of the potential for exploitation and take action to secure their environments.

Sep 14, 2026