HackerFeeds

CyberSecurity News

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

The Hacker News
· September 14, 2026

AI summary

A Chinese threat actor known as Red Heron has been linked to the exploitation of a security vulnerability in Gitea, using it to compromise internet-facing instances in a campaign that affected 13 organizations across six countries. Red Heron scanned a large number of Gitea instances, totaling 1,386, across seven countries. The threat actor also maintained a separate dataset of 477 systems based in Taiwan. This exploitation was part of a rapid response to a recently disclosed security vulnerability in Gitea. The campaign's scope and targets indicate a coordinated effort by Red Heron. The affected organizations were compromised as a result of Red Heron's exploitation of the Gitea vulnerability.

Countries in focus

Read the full article at The Hacker Newsthehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.