Red Heron turns the Gitea flaw into an industrial espionage campaign and drops a novel Linux rootkit
A Chinese-speaking actor tracked as Red Heron exploited CVE-2026-60004, the Gitea RCE, to scan 1,386 instances across seven countries and steal industrial source code. Patch self-hosted forges, lock down registration, and treat any exposed instance as already breached.