{"id":1740,"date":"2026-09-17T16:10:28","date_gmt":"2026-09-17T10:40:28","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1740"},"modified":"2026-09-21T12:47:14","modified_gmt":"2026-09-21T07:17:14","slug":"red-heron-gitea-rce","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/","title":{"rendered":"Red Heron Gitea RCE: How CVE-2026-60004 Led to Linux Compromise"},"content":{"rendered":"<p>The Red Heron Gitea RCE campaign exploited CVE-2026-60004, a critical remote code execution vulnerability affecting Gitea versions 1.17 through 1.27.0, to compromise internet-facing Gitea servers.<\/p>\n<p>A threat actor tracked as Red Heron exploited the Gitea RCE vulnerability CVE-2026-60004 against internet-facing Gitea servers. The campaign progressed beyond initial server compromise into source-code theft, credential collection, persistence, and lateral movement. Acronis Threat Research Unit linked the activity to a Chinese-speaking threat cluster.<\/p>\n<p>CVE-2026-60004 affects Gitea 1.17 through versions before 1.27.1. The vulnerability abuses Gitea&#8217;s <code>diffpatch<\/code> API to install and execute a Git hook from repository-controlled content. Gitea patched the issue in version 1.27.1.<\/p>\n<p>The campaign matters because Gitea can sit close to source code, deployment infrastructure, application secrets, and other internal systems. In this case, Red Heron reportedly turned access to exposed Gitea servers into a broader Linux infrastructure compromise.<\/p>\n<h2>Red Heron Gitea RCE campaign at a glance<\/h2>\n<table style=\"font-weight: 400; width: 99.7393%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-60004<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Affected product<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Gitea<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Vulnerability<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Remote code execution through\u00a0<code>diffpatch<\/code>\u00a0Git hook installation<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Affected versions<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">&gt;= 1.17 and &lt; 1.27.1<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Patched version<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">1.27.1<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVSS<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">9.8, CVSS v3.1<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CWE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CWE-94: Improper Control of Generation of Code<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Execution context<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Gitea OS\/service account<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Exploitation<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Confirmed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CISA KEV<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Added August 25, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td style=\"width: 33.2049%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Campaign<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 118.177%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Red Heron<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The CVE record gives CVE-2026-60004 a CVSS v3.1 score of 9.8 and identifies versions 1.17 through versions before 1.27.1 as affected. CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2026.<\/p>\n<h2>How CVE-2026-60004 Turns a Gitea Patch Into a Git Hook<\/h2>\n<p>The defining mechanism behind <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-60004?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=red_heron_gitea_rce\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-60004<\/a> sits inside Gitea&#8217;s <code>diffpatch<\/code> functionality.<\/p>\n<p>Gitea processes attacker-controlled patches inside a temporary bare Git clone. With Git 2.32 or later, submitting the same crafted patch twice can create an add\/add collision. Git&#8217;s three-way fallback can then write an executable <code>post-index-change<\/code> file into the bare repository&#8217;s <code>hooks<\/code> directory.<\/p>\n<p>Because the repository root of a bare clone is also <code>$GIT_DIR<\/code>, that file becomes a live Git hook. Git invokes the hook during the index operation, causing attacker-controlled commands to execute as the Gitea service account.<\/p>\n<p>The exploit trigger requires Git 2.32 or newer, an enabled <code>diffpatch<\/code> route, and a writable and executable temporary filesystem. The attacker also needs ordinary repository write access. With open registration enabled, an unauthenticated visitor can obtain that access by registering an account and creating a repository.<\/p>\n<p>Open registration is not inherently required for exploitation. Instead, it provides one path through which an unauthenticated visitor can obtain the required repository write access.<\/p>\n<p>This distinction matters. CVE-2026-60004 is fundamentally a repository-write-to-server-code-execution vulnerability. Open registration can create a path to that prerequisite on exposed deployments.<\/p>\n<h2>How the Red Heron Gitea RCE Expanded Into Linux Infrastructure<\/h2>\n<p>Acronis Threat Research Unit said Red Heron rapidly weaponized CVE-2026-60004 against internet-facing Gitea instances. The operation progressed from source-code theft into persistent access, credential collection, and lateral movement.<\/p>\n<p>Reporting on the Acronis investigation says the actor scanned 1,386 Gitea instances across seven countries, while maintaining another dataset containing 477 Taiwan-based systems. Researchers confirmed compromises at 13 organizations across Canada, Argentina, Taiwan, the United States, Qatar, and Sri Lanka.<\/p>\n<p>Targets spanned sectors including defense, energy, aerospace, telecommunications, government, public safety, elections, and research.<\/p>\n<p>The campaign eventually reached infrastructure beyond the original Gitea servers. Acronis reported lateral movement and deeper infrastructure access, showing why a compromised development platform should not be treated as an isolated web-server incident.<\/p>\n<h2>JITTERLY and SIXZUT Added Persistence and Concealment<\/h2>\n<p>Analysis of infrastructure associated with Red Heron revealed a C++ Linux implant called JITTERLY.<\/p>\n<p>JITTERLY provides more than 30 post-exploitation commands covering capabilities such as:<\/p>\n<ul>\n<li>shell execution<\/li>\n<li>file transfer<\/li>\n<li>process termination<\/li>\n<li>network tunneling<\/li>\n<li>interactive terminal access<\/li>\n<li>internal pivoting<\/li>\n<\/ul>\n<p>Researchers also identified SIXZUT, a previously undocumented <code>LD_PRELOAD<\/code> rootkit associated with the backdoor. SIXZUT patches Linux functions to conceal files, processes, and network connections. It can also interfere with attempts to terminate malicious components and help relaunch them after removal.<\/p>\n<p>Because <code>LD_PRELOAD<\/code> rootkits can intercept user-space library calls, ordinary process or file listings may return manipulated results and hide malicious artifacts. File-integrity monitoring can still surface unauthorized changes, but defenders should not rely on a single user-space view when investigating a suspected rootkit.<\/p>\n<p>That changes the incident-response problem. Removing the original Gitea exploit path does not establish that a previously compromised server is clean.<\/p>\n<p>Teams investigating affected hosts should therefore treat patching and post-compromise investigation as separate tasks.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/How-Can-Organizations-Secure-a-Growing-Linux-Device-Fleet.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How Can Organizations Secure a Growing Linux Device Fleet?<\/h4><p>Explore how centralized, policy-driven management can help IT teams secure and maintain growing Linux fleets. <\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/how-can-organizations-secure-a-growing-linux-device-fleet\/\" aria-label=\"How Can Organizations Secure a Growing Linux Device Fleet?\"><\/a><\/div><\/div><\/div>\n<h2>What Enterprises Should Do About CVE-2026-60004<\/h2>\n<p>Upgrade Gitea first. Gitea identifies 1.27.1 as the patched version, while all releases from 1.17 through 1.27.0 fall within the affected range. Organizations should deploy 1.27.1 or a later supported release.<\/p>\n<p>Then investigate whether vulnerable instances were exposed during the exploitation window.<\/p>\n<p>Security teams should:<\/p>\n<ul>\n<li>Inventory internet-facing and internally accessible Gitea instances.<\/li>\n<li>Review whether open registration was enabled.<\/li>\n<li>Audit accounts and repository write permissions.<\/li>\n<li>Review Gitea hosts for unexpected processes, files, hooks, outbound connections, and persistence.<\/li>\n<li>Rotate credentials and application secrets exposed to a compromised Gitea service account.<\/li>\n<li>Investigate connected infrastructure before returning affected systems to service.<\/li>\n<li>Review source repositories and deployment pipelines for unauthorized changes.<\/li>\n<\/ul>\n<p>The Gitea advisory notes that successful exploitation can expose application secrets, environment secrets, mounted repositories, database credentials, OAuth credentials, and reachable internal services. The actual exposure depends on each deployment&#8217;s isolation and Gitea service-account privileges.<\/p>\n<h2>How Hexnode UEM Supports Linux Response to the Red Heron Campaign<\/h2>\n<p>The response operates at two different layers. Server-level remediation requires teams to update Gitea and investigate the affected application and infrastructure. Endpoint fleet governance can use Hexnode UEM to manage supported Linux systems, monitor compliance, and deploy validated administrative scripts across managed hosts.<\/p>\n<p>For organizations managing supported Linux systems, <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> provides centralized Linux device management. Hexnode UEM supports Linux endpoint management, including compliance policies and platform-specific management capabilities on supported Linux distributions.<\/p>\n<h3>Track Linux security posture<\/h3>\n<p>Administrators can use compliance policies to identify managed Linux systems that fall outside defined organizational requirements. This can help teams surface systems requiring administrative attention during a wider remediation effort.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\" https:\/\/www.hexnode.com\/uem\/platform\/linux-device-management\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" target=\"_blank\">\r\n    \t\tExplore Hexnode Linux Management<\/a>\r\n    \t\t<\/center><\/p>\n<h3>Run incident-specific administrative scripts<\/h3>\n<p>Hexnode UEM supports remote Bash script execution on supported Linux endpoints. During an incident like Red Heron, administrators can use validated custom scripts for approved investigation or administrative workflows across managed systems.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/features\/hexnode-genie\/\">Hexnode Genie<\/a> can help administrators generate scripts from natural-language prompts. Administrators can then review and refine the generated code in the Script Editor before saving it to the Hexnode Repository.<\/p>\n<p>Before deployment, administrators should manually review and test AI-generated scripts on a test system. Separately, Hexnode UEM supports deploying validated Bash scripts to supported Linux endpoints through the Execute Custom Script action.<\/p>\n<p>However, custom scripting and Hexnode Genie are administrative execution and script-generation capabilities, not proof that Hexnode detects JITTERLY, SIXZUT, or exploitation of CVE-2026-60004.<\/p>\n<p>Likewise, Hexnode UEM does not replace the Gitea application upgrade. Gitea administrators should update the server through their established application or deployment workflow.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/linux_thumbnail-50kb.jpg?format=webp\" class=\"resource-box__image\" alt=\"Linux Platform Capability Statement\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/linux_thumbnail-50kb.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/linux_thumbnail-50kb-300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/linux_thumbnail-50kb-768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/linux_thumbnail-50kb-133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"linux_thumbnail-50kb\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Linux Platform Capability Statement\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore how Hexnode UEM helps IT teams centrally manage supported Linux endpoints.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/linux-device-management\/'>\n                            Download the infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does exploiting CVE-2026-60004 require open registration?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Open registration is not inherently required. The attacker needs repository write access. Open registration can provide one route for an unauthenticated visitor to obtain that access.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is upgrading Gitea enough after suspected CVE-2026-60004 exploitation?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Post-exploitation activity involving persistence, credential collection, lateral movement, JITTERLY, and SIXZUT is required. Organizations with suspected compromises should investigate affected systems after patching.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can Hexnode UEM patch Gitea directly?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Hexnode documentation does not establish Gitea as a supported application in its native patch-management workflow. Gitea should therefore be upgraded through the application or server deployment process your organization uses. Hexnode UEM can support the surrounding Linux management workflow through capabilities such as compliance monitoring, on-demand OS updates, and validated custom script execution on supported Linux endpoints.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Patch Gitea, Then Investigate Beyond Gitea<\/h3>\n<p>The Red Heron campaign demonstrates the risk created when a source-code platform also becomes an execution foothold.<\/p>\n<p>CVE-2026-60004 allowed repository-controlled content to become an executable Git hook on vulnerable Gitea servers. Red Heron then reportedly expanded access into source-code theft, persistence, credential collection, and lateral movement.<\/p>\n<p>Organizations running affected versions should upgrade to Gitea 1.27.1 or later and investigate systems that may already have been compromised. Where JITTERLY or SIXZUT is suspected, simply closing the initial vulnerability is not sufficient to establish host integrity.<\/p>\n<p>For managed Linux infrastructure, Hexnode UEM can support device management, compliance monitoring, and custom administrative script execution on supported Linux endpoints. The Gitea patch and incident investigation must still happen at the affected server and infrastructure layers.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Bring Your Linux Endpoints Under Centralized Management<\/h5><p>Explore Linux device management, compliance policies, and remote administrative capabilities with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Red Heron Gitea RCE campaign exploited CVE-2026-60004, a critical remote code execution vulnerability affecting&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1777,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,21],"class_list":["post-1740","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Red Heron Gitea RCE: CVE-2026-60004 Attacks<\/title>\n<meta name=\"description\" content=\"Red Heron exploited Gitea RCE CVE-2026-60004 to steal source code, establish persistence, and compromise Linux infrastructure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Red Heron Gitea RCE: CVE-2026-60004 Attacks\" \/>\n<meta property=\"og:description\" content=\"Red Heron exploited Gitea RCE CVE-2026-60004 to steal source code, establish persistence, and compromise Linux infrastructure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T10:40:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T07:17:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Red Heron Gitea RCE: How CVE-2026-60004 Led to Linux Compromise\",\"datePublished\":\"2026-09-17T10:40:28+00:00\",\"dateModified\":\"2026-09-21T07:17:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/\"},\"wordCount\":1449,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/\",\"name\":\"Red Heron Gitea RCE: CVE-2026-60004 Attacks\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp\",\"datePublished\":\"2026-09-17T10:40:28+00:00\",\"dateModified\":\"2026-09-21T07:17:14+00:00\",\"description\":\"Red Heron exploited Gitea RCE CVE-2026-60004 to steal source code, establish persistence, and compromise Linux infrastructure.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Red Heron Gitea RCE How CVE-2026-60004 Led to Linux Compromise\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/red-heron-gitea-rce\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Red Heron Gitea RCE: How CVE-2026-60004 Led to Linux Compromise\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Red Heron Gitea RCE: CVE-2026-60004 Attacks","description":"Red Heron exploited Gitea RCE CVE-2026-60004 to steal source code, establish persistence, and compromise Linux infrastructure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/","og_locale":"en_US","og_type":"article","og_title":"Red Heron Gitea RCE: CVE-2026-60004 Attacks","og_description":"Red Heron exploited Gitea RCE CVE-2026-60004 to steal source code, establish persistence, and compromise Linux infrastructure.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-17T10:40:28+00:00","article_modified_time":"2026-09-21T07:17:14+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Red Heron Gitea RCE: How CVE-2026-60004 Led to Linux Compromise","datePublished":"2026-09-17T10:40:28+00:00","dateModified":"2026-09-21T07:17:14+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/"},"wordCount":1449,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp","articleSection":["Malware","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/","url":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/","name":"Red Heron Gitea RCE: CVE-2026-60004 Attacks","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp","datePublished":"2026-09-17T10:40:28+00:00","dateModified":"2026-09-21T07:17:14+00:00","description":"Red Heron exploited Gitea RCE CVE-2026-60004 to steal source code, establish persistence, and compromise Linux infrastructure.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Red-Heron-Gitea-RCE-How-CVE-2026-60004-Led-to-Linux-Compromise.jpeg?format=webp","width":1340,"height":754,"caption":"Red Heron Gitea RCE How CVE-2026-60004 Led to Linux Compromise"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/red-heron-gitea-rce\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Red Heron Gitea RCE: How CVE-2026-60004 Led to Linux Compromise"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1740"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1740\/revisions"}],"predecessor-version":[{"id":1755,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1740\/revisions\/1755"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1777"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}