Gogs Zero-Day Exposes Servers to Remote Code Execution

2026-05-29T13:24:08Z1b7a3db0807f3bbb487a46e02ae87dca47c47d83b94f1aaa88d70d359671aa6a
23andMeAI-assisted-attacksBTMOBCarnivalChromeEdamameFortiClientGogsGreyVibeProject-LightwellRCEandroidargument-injectiondata-breachexploithotfixlawsuitmalwareopen-source-securitypatchingremote-code-executionsupply-chain-securityvulnerabilityzero-day

What happened

This SecurityWeek feed highlights multiple high-impact security events: a Gogs zero-day (CVSS 9.4) — an argument-injection RCE exploitable via authenticated pull requests with malicious branch names; Chrome 148 addressing 151 vulnerabilities including critical RCEs; and a FortiClient EMS vulnerability that was exploited in the wild and required hotfixes. Other notable items include a new BTMOB Android malware enabling full device takeover, a Carnival breach exposing ~6 million records, California’s lawsuit against 23andMe over a 2023 breach, Russia-linked GreyVibe attackers using AI to enhance

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
1b7a3db0807f3bbb487a46e02ae87dca47c47d83b94f1aaa88d70d359671aa6a
Enrichment time
2026-05-29T13:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.