Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Red Heron Exploits Gitea Vulnerability to Compromise 13 Organizations Across Six Countries


Red Heron, a suspected Chinese threat actor, exploited a Gitea vulnerability to compromise 13 organizations across six countries. The attack highlights the importance of maintaining robust cybersecurity measures to prevent such incidents.

  • Red Heron, a suspected Chinese threat actor, exploited a Gitea vulnerability to compromise 13 organizations across six countries.
  • The attack began with scanning 1,386 Gitea instances across seven countries and progressed to persistent access, credential collection, and lateral movement.
  • The attack used a C++ Linux implant called JITTERLY with over 30 post-exploitation commands.
  • A previously undocumented LD_PRELOAD rootkit called SIXZUT was used to hide files, processes, and network connections.
  • The attack highlights the importance of maintaining robust cybersecurity measures, staying up to date with security patches, and being vigilant with system monitoring.



  • The threat landscape continues to evolve with new and sophisticated cyber attacks being reported on a regular basis. In this context, a recent cyber attack has been reported where Red Heron, a suspected Chinese threat actor, exploited a Gitea vulnerability to compromise 13 organizations across six countries. The attack highlights the importance of maintaining robust cybersecurity measures to prevent such incidents.

    The attack began when Red Heron scanned 1,386 Gitea instances across seven countries, including Taiwan, Canada, Argentina, the U.S., Qatar, and Sri Lanka. The threat actor then maintained a separate dataset of 477 Taiwan-based systems, which were compromised as part of the attack. The attack progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster.

    The attack also involved the use of a C++ Linux implant called JITTERLY, which supported more than 30 post-exploitation commands related to shell execution, file transfer, process termination, network tunneling, interactive terminal access, and internal pivoting. The JITTERLY implant was previously documented by a researcher who goes by the online alias "dmpdump" in July 2026. The implant was found to be sharing overlaps with the AdaptixC2 agent.

    Furthermore, the attack involved the use of a previously undocumented LD_PRELOAD rootkit called SIXZUT, which was capable of hiding files, processes, and network connections by patching 15 different Linux functions to cover up traces of malicious activity and prevent the malware from being detected and killed. The rootkit was also found to be capable of relaunching if it got terminated or removed.

    The attack highlights the importance of maintaining robust cybersecurity measures to prevent such incidents. It also highlights the importance of staying up to date with the latest security patches and updates to prevent exploitation of known vulnerabilities. The attack also highlights the importance of being vigilant and monitoring systems for suspicious activity.

    In conclusion, the recent cyber attack by Red Heron highlights the importance of maintaining robust cybersecurity measures to prevent such incidents. It also highlights the importance of staying up to date with the latest security patches and updates to prevent exploitation of known vulnerabilities.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Red-Heron-Exploits-Gitea-Vulnerability-to-Compromise-13-Organizations-Across-Six-Countries-ehn.shtml

  • https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html


  • Published: Mon Sep 14 12:41:42 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us