THE ESSENTIALS
  • Report dated September 13.

What changed

Acronis published an investigation linking the Red Heron actor to exploitation of an already patched Gitea vulnerability. Recovered records showed compromises in Canada, Argentina, Taiwan, the United States and Sri Lanka. The researchers connected the activity to JITTERLY, a Linux implant containing the previously undocumented SIXZUT rootkit.

Why it matters

The findings suggest that a compromised source-code server can become a route to persistent infrastructure access. Acronis describes credential collection and lateral movement alongside repository theft, making the investigation relevant beyond the immediate question of whether the Gitea patch was installed.

What remains unproven

Acronis assesses a China-linked operational context with moderate confidence and has not linked Red Heron to an established group. Its recovered records provide a partial view of historical activity, rather than a census of current victims.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. Acronis ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗