Rapid7 disclosed a CVSS 9.4 argument-injection bug in Gogs’ “rebase before merging” workflow that enables any authenticated user to execute arbitrary commands on the server. Attackers can compromise the host, read all repos (including private), steal credentials, and modify code—posing serious multi-tenant and supply chain risks. No vendor fix exists; admins should restrict registration and repo creation, audit rebase settings, and hunt logs for suspicious --exec branch names.
Source: Rapid7
FortiClient EMS zero‑day now mass‑exploited to drop credential stealers
Threat actors continue to exploit a critical FortiClient Endpoint Management Server flaw to gain remote code execution and deploy malware across managed endpoints. Fortinet issued hotfixes in April and urged immediate patching; defenders should also review EMS access logs and endpoint telemetry for unusual software pushes and lateral movement.
Source: Security Week
Chrome 148 fixes 151 vulnerabilities, including critical RCE—patch fleets now
Google shipped Chrome 148 with fixes for 151 security issues, some critical and potentially exploitable for remote code execution. Enterprise admins should accelerate updates across Windows, macOS, Linux, and mobile channels and revalidate extension posture to minimize attack surface and downgrade risks from exploit chains.
Source: Security Week
IBM and Red Hat pour $5B into Project Lightwell to secure open-source supply chains
Project Lightwell commits $5B and 20,000+ engineers to build a trusted clearinghouse and AI-enabled capability set to find and fix OSS vulnerabilities from upstream through production. The initiative aims to harden dependency chains without breaking running workloads—signal that enterprise OSS consumption will shift toward curated, continuously secured components.
Source: Security Week
ESET APT report: Oil shipments, drone makers, and poisoned libraries targeted
ESET’s latest APT Activity Report (Q4 2025–Q1 2026) shows China-, North Korea-, Russia-, and Iran-aligned groups recalibrating toward geopolitically sensitive targets. Campaigns hit government agencies, strategic industries, advanced tech sectors, and included a poisoned code library—underscoring the growing blend of espionage, supply-chain compromise, and regional conflicts.
Source: HelpNet Security
Microsoft dissects ‘The Gentlemen’ ransomware’s self‑propagating Go encryptor
Microsoft details a Go-based ransomware used by Storm-2697 affiliates that combines per-file ephemeral keys with aggressive self-propagation and parallel lateral movement. The analysis provides IOCs and technique mapping defenders can use to harden admin shares and credentials, contain spread, and improve ransomware readiness.
Source: Microsoft MMPC
CISA adds LiteSpeed cPanel Plugin RCE to KEV; urgent patching required
CISA added CVE-2026-48172 (CVSS 10) in the LiteSpeed User-End cPanel plugin to the Known Exploited Vulnerabilities catalog, signaling active in-the-wild exploitation. Affected versions prior to 2.4.5 allow unauthenticated remote code execution; organizations should patch immediately and verify plugin inventories, especially on shared hosting footprints.
Source: Security Affairs
You May Also Be Interested In...