The state-sponsored threat actor Red Heron exploited a remote code execution vulnerability in Gitea to compromise 13 organizations across six countries in a rapid, targeted campaign.
Attackers are actively exploiting a critical code injection vulnerability in Gitea, a widely used self-hosted Git service, prompting warnings from U.S. CISA.
Threat actors are actively attempting to exploit a critical vulnerability in Gitea Docker images less than two weeks after it was patched. The flaw allows unauthenticated clients to escalate privileges by abusing the 'X-WEBAUTH-USER' header.