Urgent.News

What's breaking now, across thousands of outlets.

Tech

My Homelab Got Hacked - A Postmortem

My Forgejo instance was hacked by an RCE vulnerability on February 28th. The attacker exploited CVE-2026-60004, a recently discovered vulnerability in Gitea, the software that Forgejo is based on. This vulnerability allows an attacker to execute arbitrary code on a server by exploiting a bug in Gitea's diffpatch endpoint.

The attacker initially appeared to be a new user, testpoc26188, who had been created without the admin's knowledge. The attacker then created a single repository, poc-78614, with two files - a README and a hooks folder containing a shell script named post-index-change. This script was the key to the attack.

The shell script was found to be an exploit for the CVE-2026-60004 vulnerability. It was identical to a published proof-of-concept (POC), with only minor differences in the Git commit and tree values. The only other difference was the addition of a curl command to download a second-stage script from the attacker's server, which was located on RackNerd's infrastructure.

The attacker used the POST /api/v1/repos/USER/REPO/diffpatch endpoint three times to trigger the exploit. They then downloaded a 3.23MB and a 6.43MB payload, which were likely x86 binaries. These binaries were designed to coordinate with the attacker's server to obtain or create a crypto wallet address.

No reverse shell or lateral movement was detected on the host machine or other containers. The rest of the network appeared clean. The main indicator of compromise (IOC) for this vulnerability is the repeated calls to the POST /api/v1/repos/USER/REPO/diffpatch endpoint. The attacker's IP was 107.172.180.205, a VPN server located in Rancho Cucamonga, near Los Angeles.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at phunky.cafe →

More in Tech

More from Wednesday 12 August →