Chinese Red Heron Group Exploits Gitea Flaw to Breach Multiple Firms in Six Nations
Security researchers have linked a rapid, multi‑national intrusion campaign to the Chinese‑affiliated threat actor known as Red Heron, which leveraged a freshly disclosed remote‑code‑execution vulnerability in the open‑source Git service Gitea to gain footholds in at least 13 organizations spanning six countries.
Gitea, a lightweight, self‑hosted platform that many development teams use to manage source code, suffered a critical flaw that allows unauthenticated attackers to execute arbitrary commands on vulnerable servers. The vulnerability was publicly disclosed only weeks ago, giving defenders limited time to apply patches before the exploit surfaced in the wild.
According to the investigation, Red Heron conducted a systematic sweep of internet‑exposed Gitea installations, probing 1,386 instances across seven different regions. The scans identified servers that had not yet applied the security update, after which the group deployed a weaponised payload that granted full system control.
The compromised entities, described by researchers as a mix of technology firms, service providers and other mid‑size enterprises, reported that attackers were able to exfiltrate source code repositories and internal documentation. While the full extent of data loss remains under assessment, the breach underscores the risk of unpatched development tools serving as entry points for broader network infiltration.
Attribution to Red Heron was made possible through a combination of unique tooling signatures, command‑and‑control infrastructure, and patterns observed in previous campaigns linked to the group. The actor’s focus on supply‑chain‑adjacent software aligns with a broader trend of state‑linked actors targeting development pipelines to harvest intellectual property or position themselves for future attacks.
Security vendors and the Gitea project have issued urgent advisories urging administrators to update to the latest release, disable unauthenticated access, and enforce strict network segmentation for development environments. The episode serves as a reminder that even well‑known open‑source components can become vectors for sophisticated threat actors, prompting organizations to reassess their patch management and exposure monitoring practices.
Comments (0)
Be the first to comment.
Join the discussion