Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are actively exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
🔗 Source: https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
#git
👉@sysadminoff
https://bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks
Attackers are actively exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
🔗 Source: https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
#git
👉@sysadminoff
https://bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks
BleepingComputer
Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
📰 Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive.
🔗 Source: https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html
#git
👉@sysadminoff
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive.
🔗 Source: https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html
#git
👉@sysadminoff