Gogs 0-Day Vulnerability Exploited in the Wild to Hack 700+ Instances
ID: dd9058cd-6ce6-553b-aa61-f07cd5cf5ab9
STIX ID: report--dd9058cd-6ce6-553b-aa61-f07cd5cf5ab9
Feed Name: cybersecurityNews.com
**Active zero-day RCE in Gogs (CVE-2025-8110):** A symlink-bypass vulnerability in Gogs' API is being actively exploited in the wild to overwrite host files via committed symlinks and the PutContents endpoint, enabling remote code execution. Researchers linked exploitation starting July 10, 2025, to an automated campaign that created short random repositories on internet-facing, open-registration instances; ~1,400 public instances were identified with ~700 confirmed compromised. The payload is Supershell (Go-based C2) packed/obfuscated with UPX and garble; reported IoCs include several C2 IPs. Administrators are advised to disable open registration, restrict access, and scan for anomalous repositories and PutContents activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
