No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out
2026-05-29T19:24:03Z•b6593c8d1b55d0d3113c09b47d058215c5f8a1466e450194e0801d8dc0e8e702
AI-abuseCiscoDrupalGitHubGogsRCESecure-WorkloadShinyHuntersVSCode-extensionapi-keysbotnetcredential-exposurecritical-patchdata-breachexploitprompt-injectionransomwaresupply-chaintenant-isolationvulnerabilityzero-day
What happened
Multiple high-impact security stories: a critical RCE in open-source Git service Gogs has an exploit module available and no vendor fix/response; Drupal warned of a highly critical core patch; Cisco disclosed a tenant-boundary 'perfect 10' Secure Workload admin flaw. Other notable incidents include supply-chain exfiltration via a poisoned VS Code extension targeting GitHub, large data leaks by ShinyHunters (Charter, Carnival), a 17M-device botnet disruption in the Netherlands, exposed secrets and API keys (including a US cyber agency GitHub repo and short-lived Google API keys), and growing AI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- b6593c8d1b55d0d3113c09b47d058215c5f8a1466e450194e0801d8dc0e8e702
- Enrichment time
- 2026-05-29T19:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.