From Live Exploitation to Zero-Day Discovery: Investigating Attacks on Gogs (opens in new tab)
A single infected server led us into a much larger story\. While investigating suspicious repositories on exposed \*\*\*\* Git servers, we uncovered signs of active exploitation: commands hidden inside repository configurations, payloads fetching remote shells, and infrastructure linked to a custom-packed Supershell C2\. What at first looked like an opportunistic abuse of a known bug turned out to be something more: an unpatched zero-day vulnerability, already being leveraged in the wild\. Wh...
Read the original article