# Red Heron Exploits Gitea Vulnerability Globally

Acronis Threat Research Unit has identified a multinational cyber campaign by the Chinese-speaking threat actor Red Heron exploiting a zero-day vulnerability (CVE-2026-60004) in Gitea, a self-hosted source-code management platform. This campaign, active since July 2026, rapidly escalated from source-code theft to persistent root-level access affecting critical infrastructure sectors including defense and telecommunications across multiple countries such as the United States, Canada, Taiwan, Argentina, and Sri Lanka. The incident underscores urgent cybersecurity risks for government agencies and contractors relying on self-hosted development platforms and highlights the need for enhanced vulnerability management, incident response capabilities, and supply chain security measures.

- Government procurement professionals should prioritize evaluating and mitigating risks associated with self-hosted software platforms like Gitea, especially in defense and telecommunications sectors.
- Contractors and vendors must assess their software development environments for vulnerabilities and implement robust patch management and monitoring to prevent exploitation.
- This campaign indicates a growing threat landscape targeting source-code repositories, emphasizing the importance of cybersecurity requirements in upcoming contracts and vendor assessments.
- Organizations involved in critical infrastructure should consider integrating advanced threat detection and response solutions to address sophisticated persistent threats demonstrated by Red Heron.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity
**Published:** September 14, 2026

### Government Entities
- Government of Canada
- Government of Argentina
- Government of Taiwan
- Government of United States (U.S.)
- Government of Sri Lanka

### Vendors
- Acronis Threat Research Unit (threat research and reporting)

### Key Quotes
> Within days of the vulnerabilitys July 2026 disclosure, Red Heron transformed public proof-of-concept code into an automated framework capable of registering accounts, exploiting vulnerable servers, stealing repositories, and removing selected traces.
> — Original poster

### Sources
- [Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit](https://www.reddit.com/r/cybersecurity/comments/1wgh4hr/red_heron_exploits_gitea_nday_flaw_in) - reddit-cybersecurity