vulnerability Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload A critical remote code execution vulnerability (CVE-2026-60004) in Gitea is actively being exploited to deploy cryptocurrency miners. The vulnerability, stemming from default open registration, allows attackers to gain repository write access and execute malicious Git hooks. A hosting provider reported a significant CP… The Hacker News · 4d ago Critical CVE-2026-60004remote code executioncryptojackinggit hook
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa
vulnerability Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup A critical vulnerability (CVE-2026-59774) in Gitea versions 1.22.1 through 1.27.0 allows unauthenticated attackers to read files accessible to the service account. While a direct remote code execution exploit hasn't been… The Hacker News · Aug 5, 2026 Critical CVE-2026-59774CVE-2026-60004CVE-2026-20896vulnerabilityorg-moderemote code execution
threat-intel Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent Google removed three AI agent workflows from its ADK Python repository after a public GitHub issue allowed a malicious bot to trigger a privileged code-fixing agent, leading to potential code execution and credential exp… The Hacker News · Aug 4, 2026 High botcredential exposuregit
vulnerability New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands A critical remote code execution (RCE) vulnerability in Gitea allows a user with repository write access to plant a Git hook and execute shell commands as the Gitea service account. The vulnerability, tracked as CVE-2026… The Hacker News · Jul 29, 2026 High CVE-2026-60004rcegitvulnerability
vulnerability Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A researcher, depthfirst, has published a proof-of-concept exploit targeting GitLab 18.11.3 and earlier, allowing authenticated users to execute arbitrary commands as the ‘git’ user. The vulnerability stems from flaws wi… The Hacker News · Jul 25, 2026 High rcejupyterjson
vulnerability Unpatched Cursor Vulnerability Exposes Users to Code Execution A critical, unpatched vulnerability in Cursor, a popular AI-assisted development environment, allows for code execution simply by opening a project containing a malicious git.exe binary. Despite being reported to Cursor… SecurityWeek · Jul 15, 2026 Critical cursorgitcode execution
vulnerability Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution A vulnerability in Cursor, a Git repository hosting platform for Windows, allows malicious cloned repositories to execute arbitrary code on the user's system. The flaw stems from Cursor's tendency to run a `git.exe` file… The Hacker News · Jul 15, 2026 High CVE-2026-26268CVE-2026-10591CVE-2020-26233gitwindowscode execution
vulnerability Cursor IDE Auto-Executes Malicious Code in Poisoned Repos A security vulnerability in Cursor IDE allows attackers to automatically execute malicious code embedded in poisoned Git repositories. Researchers at Mindgard discovered the flaw in December, but Cursor has not addressed… Dark Reading · Jul 14, 2026 High gitrepositorymalware
threat-intel Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads xAI's Grok Build coding CLI has been uploading entire Git repositories, including commit history and sensitive data like API keys and passwords, to a Google Cloud Storage bucket. The issue was discovered by cereblab, who… The Hacker News · Jul 14, 2026 High data-breachgitcredentials
threat-intel GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verifie… The Hacker News · Jul 8, 2026 High gitsignaturevulnerability
threat-intel Critical Gitea Flaw Under Active Exploitation, Researchers Warn A critical vulnerability in Gitea’s reverse-proxy authentication mechanism is being actively exploited, allowing attackers to bypass authentication and gain unauthorized access to Gitea instances. The flaw, tracked as CV… SecurityWeek · Jul 7, 2026 Critical CVE-2026-20896vulnerabilityauthenticationgit
threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
vulnerability Gogs Zero-Day Exposes Servers to Remote Code Execution A critical zero-day vulnerability has been discovered in the open-source self-hosted Git service, Gogs, allowing for remote code execution (RCE) on affected servers. The flaw, identified by Rapid7, stems from an argument… SecurityWeek · May 29, 2026 Critical CVE-2025-8110zero-dayremote code executiongit
vulnerability Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical remote code execution (RCE) vulnerability has been identified in Gogs, a popular self-hosted Git service, allowing authenticated users to execute arbitrary code. The flaw, detailed by Jonah Burgess, stems from… The Hacker News · May 28, 2026 Critical rcegitrebase
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp