LIVE · cybersecurity feed
Live wire
CVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attack
CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

zeroday.news ·

A critical vulnerability in Gitea, a self-hosted Git service, is now being actively exploited by attackers, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw, tracked as CVE-2026-60004, is a code injection vulnerability that allows an authenticated user with repository write access to execute arbitrary shell commands on affected servers.

The vulnerability was reported by Salesforce security researcher Shai Rod. It enables an attacker to submit malicious patches via the `diffpatch` API endpoint, leading to the execution of commands with the privileges of the Gitea service account. Gitea's security team confirmed that the `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content.

A significant concern is that Gitea instances often have self-registration enabled by default. This configuration allows unauthenticated attackers to register an account, create a new repository, and then exploit the vulnerability without needing prior credentials. This effectively lowers the barrier for entry for malicious actors.

Gitea released version 1.27.1 on July 27 to address CVE-2026-60004 and urged users to upgrade their servers promptly. Despite the patch availability, the cybersecurity watchdog Shadowserver is currently tracking nearly 5,000 Gitea instances exposed online, though it is unclear how many of these have been secured or are honeypots.

CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities (KEV) catalog on August 26. The agency subsequently issued a directive to U.S. Federal Civilian Executive Branch (FCEB) agencies, mandating that they secure their Gitea servers by August 28, in accordance with Binding Operational Directive (BOD) 26-04. CISA emphasized that this type of vulnerability is a frequent attack vector and poses significant risks.

While CISA did not provide specific details on the ongoing attacks, the inclusion of the vulnerability in the KEV catalog and the urgent directive suggest active exploitation in the wild. Reports indicate that attackers have been deploying cryptocurrency mining malware on unpatched Gitea servers.

This incident follows another critical Gitea vulnerability, CVE-2026-20896, an authentication bypass flaw that was exploited in July. That vulnerability affected Gitea instances configured with reverse proxy authentication headers, such as X-WEBAUTH-USER, enabled.

giteacode injectionvulnerabilitycisaexploitation
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-15409critical

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal grou

vulnerability

Four in Five AI Tools Run with No IT Oversight, New Research Finds

Reco report reveals growing shadow AI problem and surge in vulnerability disclosures

phishingcritical

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mim

breach

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.

mfa

The MFA Identity Trap: When Authentication Creates a False Sense of Security

Organizations are falling into an 'MFA Identity Trap' by conflating identity verification, authentication, and threat detection. This confusion can lead to a false sense of security, where systems successfully authenticate attackers instead of blocking them. A clear distinction between these processes is crucial for effective security.

security

RightCrowd Pass unifies mobile, physical, and biometric credentials

RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometric credentials, what began as a single access program can fragment into three separate systems, each with its own issuan