CVE
CVE-2026-27771
Gitea Composer package source links use insufficient permission checks
Exploitation IoCs 3
Domain corepack[.]org
Filename lib/.threadpool.rb
IP 165[.]154[.]236[.]93
MITRE ATT&CK TTPs 16
T1027 T1056.001 T1059 T1059.001 T1071.001 T1082 T1083 T1087.003 T1098 T1105 T1114 T1195.001 T1555 T1566 T1570 T1588
Obfuscated Files or Information
Defense Evasion
Keylogging
Collection
Command and Scripting Interpreter
Execution
PowerShell
Execution
Web Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Email Account
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Email Collection
Collection
Compromise Software Dependencies and Development Tools
Initial Access
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Lateral Tool Transfer
Lateral Movement
Obtain Capabilities
Resource Development
Source Articles
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
A critical vulnerability in Gitea, tracked as CVE-2026-59774, allows unauthenticated attackers to read arbitrary files accessible by the Gitea service account by exploiting the Org-mode markup renderer. The flaw exists in versions 1.22.1 through 1.27.0 and is triggered via a crafted Org-mode #+INCLUDE directive processed by the /{owner}/{repo}/markup endpoint. Although not direct remote code execution, attackers can chain the file-read capability with reading app.ini to extract the INTERNAL_TOKEN and subsequently inject Git hooks to achieve command execution. The vulnerability was discovered by XBOW Security and independently reported by Shai Rod, with no known in-the-wild exploitation observed at the time of disclosure.
hacker-news Aug 5, 2026
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news Aug 3, 2026