news.mlab.sh
3 results
vulnerability

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

A critical remote code execution vulnerability (CVE-2026-60004) in Gitea is actively being exploited to deploy cryptocurrency miners. The vulnerability, stemming from default open registration, allows attackers to gain repository write access and execute malicious Git hooks. A hosting provider reported a significant CP…

The Hacker News · 4d ago Critical