logo

Hackers exploit unpatched Gogs zero-day to breach 700 servers

ID: a76b4c5a-4b76-58e0-bd58-bef40015f2b2

STIX ID: report--a76b4c5a-4b76-58e0-bd58-bef40015f2b2

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-12-11

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

An actively exploited zero-day in Gogs (CVE-2025-8110) allows remote code execution by abusing symbolic links in the PutContents API to perform path traversal and overwrite system files; Wiz Research found over 1,400 internet-exposed Gogs instances with more than 700 showing compromise, observed repositories with random 8-character names, and Supershell-based malware communicating with C2 119.45.176.196. Administrators are advised to disable open registration, restrict access via VPN or allow lists, and check for suspicious PutContents API activity and random repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.