CVE

CVE-2026-27771

Gitea Composer package source links use insufficient permission checks

Exploitation IoCs 3

Domain corepack[.]org
Filename lib/.threadpool.rb
IP 165[.]154[.]236[.]93

MITRE ATT&CK TTPs 16

Source Articles

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
A critical vulnerability in Gitea, tracked as CVE-2026-59774, allows unauthenticated attackers to read arbitrary files accessible by the Gitea service account by exploiting the Org-mode markup renderer. The flaw exists in versions 1.22.1 through 1.27.0 and is triggered via a crafted Org-mode #+INCLUDE directive processed by the /{owner}/{repo}/markup endpoint. Although not direct remote code execution, attackers can chain the file-read capability with reading app.ini to extract the INTERNAL_TOKEN and subsequently inject Git hooks to achieve command execution. The vulnerability was discovered by XBOW Security and independently reported by Shai Rod, with no known in-the-wild exploitation observed at the time of disclosure.
hacker-news Aug 5, 2026
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news Aug 3, 2026