Gitea A.I CyberSecurity Scoring
Gitea
Company Information
Website:https://gitea.com
Employees number:3
Number of followers:905
NAICS:519
Industry Type:Information Services
Homepage:gitea.com
Gitea Risk Score (AI oriented)
Between 650 and 699
GiteaInformation Services
Updated:
26/09/2026
26/09/2026
683/1000
Weak
B
Gitea Global Score (TPRM)
xxxx
GiteaInformation Services
Score locked

GiteaWeak
Current Score
683B (WEAK)
01000
1 incidents
-80 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
683
SEPTEMBER 2026
683
AUGUST 2026
682
JULY 2026
681
JUNE 2026
679
MAY 2026
678
APRIL 2026
676
MARCH 2026
675
FEBRUARY 2026
673
JANUARY 2026
751
Breach
01 Jan 2026 • Gitea
Virlabs and Gitea: Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit
Red Heron Exploits Critical Gitea RCE Flaw to Deploy Linux Backdoor and Rootkit
671
CRITICAL-80
GITVIR1790403867
Red Heron Exploits Critical Gitea RCE Flaw to Deploy Linux Backdoor and Rootkit
A suspected Chinese-speaking threat actor, Red Heron, has been exploiting CVE-2026-60004, a critical remote code execution (RCE) vulnerability in Gitea (versions 1.17–1.27.0), to target internet-exposed source-code servers. The campaign, uncovered by Acronis Threat Research Unit, focuses on stealing proprietary repositories and deploying two malicious tools: the JITTERLY Linux backdoor and the SIXZUT rootkit.
The attack leverages Gitea’s vulnerable diffpatch API to gain remote execution, enabling threat actors to exfiltrate sensitive data including SCADA- and HMI-related source code from an industrial automation victim. The post-exploitation chain centers on JITTERLY, a C++ Linux implant with over 30 capabilities, such as remote shell execution, file transfers, SOCKS tunneling, and internal network pivoting.
To evade detection, Red Heron deploys SIXZUT, an LD_PRELOAD rootkit that conceals malicious files, processes, and network connections by intercepting Linux library functions. The rootkit also resists termination, automatically relaunching agents if stopped, and relies on /etc/ld.so.preload for persistence making cleanup risky without a full system rebuild.
Analysis of SIXZUT samples revealed an encrypted configuration linking to two JITTERLY agents:
- __hesti (p1.981666[.]xyz:6443)
- __root (p2.981666[.]xyz:8080)
These agents overlap with artifacts reported in 2026 HestiaCP intrusions, where administrators found unauthorized access and malicious files like /usr/lib/__hesti/__hesti and /lib/x86_64-linux-gnu/libnss_cache.so.2. The 981666[.]xyz infrastructure has also been tied to other Linux malware, including implants targeting UniFi devices, suggesting broader activity by the same or related actors.
Virlabs linked Red Heron to the theft of over 18,000 government records and exploitation across multiple device and software ecosystems, reinforcing the group’s sophisticated and persistent threat profile.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
751
NOVEMBER 2025
751
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Gitea ??
What was Gitea's A.I Rankiteo Cyber Score in September 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in August 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in July 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in June 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in May 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in April 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in March 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in February 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in January 2026 ??
What was Gitea's A.I Rankiteo Cyber Score in December 2025 ??
What was Gitea's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Gitea's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Gitea ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Gitea's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?