Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gitea Vulnerability Exploited in Cryptojacking Attack

Gitea Vulnerability Exploited in Cryptojacking Attack

Posted on August 26, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical security flaw in Gitea, a widely used software platform. The vulnerability, identified as CVE-2026-60004 with a CVSS score of 9.8, permits remote code execution, allowing attackers to execute arbitrary shell commands.

Understanding the Gitea Security Flaw

This vulnerability affects all Gitea versions from 1.17 and was patched in version 1.27.1. The flaw is exploited by manipulating Gitea’s diffpatch endpoint, as detailed in an advisory by Gitea. The vulnerability can be leveraged by creating a repository with default open registration, enabling an unauthenticated individual to gain necessary write access.

Security researcher Shai Rod, also known as NightRang3r, discovered this issue. The vulnerability’s potential for exploitation lies in Gitea’s default settings, which allow external actors to create accounts and repositories, thus facilitating the execution of malicious codes without pre-existing credentials.

Exploitation Details and Impact

CISA’s addition of this flaw to its Known Exploited Vulnerabilities catalog underscores its severity. Although specific exploitation details remain undisclosed, a developer known as Andrey reported an attack using CVE-2026-60004 to deploy a cryptocurrency-miner-like payload on their Gitea instance. This incident was linked to unusual server activity detected by hosting provider HOSTKEY.

The attack exploited the open registration configuration in Gitea, allowing the attacker to register and gain repository write access. The vulnerability was accessed via HTTPS, with the attack vector avoiding exposure of Gitea’s SSH.

Mitigation and Ongoing Concerns

The payload involved a script that circumvented standard security processes, downloaded a miner, and executed it, significantly increasing CPU usage. While the precise nature of the payload remains unexamined, the activity aligns with cryptojacking campaigns targeting unpatched Gitea instances.

Federal agencies in the U.S. have been instructed to patch the vulnerability by August 28, 2026, prioritizing updates based on risk. It remains uncertain whether CISA’s catalog inclusion was due to this specific attack or other evidence of exploitation.

This incident highlights the critical importance of timely software updates and vigilant monitoring to prevent similar vulnerabilities from being exploited in the future.

The Hacker News Tags:CISA, cryptocurrency mining, Cryptojacking, CVE-2026-60004, Cybersecurity, Gitea, remote code execution, security flaw, Software Security, Vulnerability

Post navigation

Previous Post: CoreRAT Malware Empowers Hackers with Full System Control
Next Post: Microsoft Teams Restores Services After Outage

Related Posts

Kali365 Exploits Microsoft Login to Threaten US Firms Kali365 Exploits Microsoft Login to Threaten US Firms The Hacker News
GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories The Hacker News
Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger The Hacker News
Helping CISOs Speak the Language of Business Helping CISOs Speak the Language of Business The Hacker News
Ghostwriter Intensifies Phishing Attacks on Ukraine Ghostwriter Intensifies Phishing Attacks on Ukraine The Hacker News
Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Nutex Health Data Breach Exposes Sensitive Details
  • AI-Based Phishing Scheme Targets Apple Device Owners
  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Nutex Health Data Breach Exposes Sensitive Details
  • AI-Based Phishing Scheme Targets Apple Device Owners
  • Microsoft Teams Restores Services After Outage
  • Gitea Vulnerability Exploited in Cryptojacking Attack
  • CoreRAT Malware Empowers Hackers with Full System Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark