daily cyber × ai intelligence

index

tagged

[CVE-2026-60004]

3 editions · 3 items

September 15, 2026

  • Red Heron industrialized a public Gitea PoC within days. Acronis TRU assesses the cluster as China-linked with moderate confidence and says it began abusing CVE-2026-60004 on July 29. It scanned 1,386 instances across seven countries, kept a separate dataset of 477 Taiwan systems, and confirmed 13 organizational compromises in six countries. Activity reached root on a three-node Proxmox cluster and deployed JITTERLY plus the SIXZUT LD_PRELOAD rootkit. · Exploitation & Vulnerability Research

in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents

August 27, 2026

  • Gitea CVE-2026-60004 (CVSS 9.8) is under active exploitation, per CISA. Ordinary repository write access is enough to execute arbitrary shell commands as the Gitea user; the fix landed in 1.27.1 in late July, and reported attacks are dropping a miner-like payload (BleepingComputer, The Hacker News). Self-hosted Git is a high-value pivot into build pipelines — treat this as CI/CD compromise, not a web bug. · Vulnerabilities & Exploits

in When the Sandbox Isn't a Boundary