A suspected Chinese threat actor, dubbed Red Heron, has been linked to the rapid exploitation of a recently disclosed security flaw in Gitea to compromise internet-facing instances as part of a multi-national campaign This article explores vulnerability red heron. . (4), Qatar (1), and Sri Lanka (1), with the threat actor employing Simplified Chinese labels to target sectors including defense, elections, energy, aerospace, telecommunications, government, public safety, and research.

The Singapore-based cybersecurity firm has assessed Red Heron to be operating within a China-linked context, with moderate confidence, due to the presence of Simplified Chinese, Taiwan's classification as part of China, and a targeting footprint consistent with China's intelligence collection priorities.

An analysis of a staging server belonging to the adversary has revealed a C++ Linux implant called JITTERLY, which includes more than 30 post-exploitation commands related to shell execution, file transfer, process termination, network tunneling, interactive terminal access, and internal pivoting. Days after the July 2026 disclosure of the vulnerability, Red Heron leveraged public proof-of-concept code to develop an automated framework that could register accounts, exploit vulnerable servers, steal repositories, and obliterate selected traces. Data was exfiltrated from a Taiwanese industrial automation company, including hundreds of repositories related to a SCADA/HMI tool, IoT platform integrations, a network sniffer, server configurations, a surveillance and monitoring product, and internal business applications.