Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

2026-08-26T07:24:01Z5e55efd13050db8d3683300e415de660bcc9accd6dfb2ab2af9a2c5ada728db7
CVE-2026-18963CVE-2026-21962CVE-2026-60004CVE-2026-61979AI securityApple phishingCISA KEVClickFixGiteaKeycloakLinux backdoorMFA bypassMicrosoft 365 phishingOracle WebLogicRATWordPressaccount takeoveractive exploitationauthentication bypasscritical infrastructurecyber espionagemalwaremodel poisoningnpm supply chainphishing-as-a-serviceprivilege escalationremote code execution

What happened

The feed reports multiple significant cybersecurity developments, led by active exploitation of critical vulnerabilities in Gitea (CVE-2026-60004), Oracle WebLogic/HTTP Server (CVE-2026-21962), Keycloak (CVE-2026-18963), and miniOrange SAML for WordPress (CVE-2026-61979). It also covers phishing-as-a-service campaigns targeting Apple and Microsoft 365 credentials, malicious npm packages, AI-agent and notebook security flaws, malware campaigns, RATs, espionage activity, and Linux/Windows server compromises. Organizations should prioritize patching actively exploited and critical vulnerabilities

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5e55efd13050db8d3683300e415de660bcc9accd6dfb2ab2af9a2c5ada728db7
Enrichment time
2026-08-26T07:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload · Baitaphish