Gogs Zero-Day Exposes Servers to Remote Code Execution
2026-05-29T13:24:08Z•1b7a3db0807f3bbb487a46e02ae87dca47c47d83b94f1aaa88d70d359671aa6a
23andMeAI-assisted-attacksBTMOBCarnivalChromeEdamameFortiClientGogsGreyVibeProject-LightwellRCEandroidargument-injectiondata-breachexploithotfixlawsuitmalwareopen-source-securitypatchingremote-code-executionsupply-chain-securityvulnerabilityzero-day
What happened
This SecurityWeek feed highlights multiple high-impact security events: a Gogs zero-day (CVSS 9.4) — an argument-injection RCE exploitable via authenticated pull requests with malicious branch names; Chrome 148 addressing 151 vulnerabilities including critical RCEs; and a FortiClient EMS vulnerability that was exploited in the wild and required hotfixes. Other notable items include a new BTMOB Android malware enabling full device takeover, a Carnival breach exposing ~6 million records, California’s lawsuit against 23andMe over a 2023 breach, Russia-linked GreyVibe attackers using AI to enhance
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 1b7a3db0807f3bbb487a46e02ae87dca47c47d83b94f1aaa88d70d359671aa6a
- Enrichment time
- 2026-05-29T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.