- Report dated September 13.
What changed
Acronis published an investigation linking the Red Heron actor to exploitation of an already patched Gitea vulnerability. Recovered records showed compromises in Canada, Argentina, Taiwan, the United States and Sri Lanka. The researchers connected the activity to JITTERLY, a Linux implant containing the previously undocumented SIXZUT rootkit.
Why it matters
The findings suggest that a compromised source-code server can become a route to persistent infrastructure access. Acronis describes credential collection and lateral movement alongside repository theft, making the investigation relevant beyond the immediate question of whether the Gitea patch was installed.
What remains unproven
Acronis assesses a China-linked operational context with moderate confidence and has not linked Red Heron to an established group. Its recovered records provide a partial view of historical activity, rather than a census of current victims.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
