Tag

Gitea

All articles tagged with #gitea

Early Probes Emerge Against Patched Gitea Docker Flaw CVE-2026-20896
security1 month ago

Early Probes Emerge Against Patched Gitea Docker Flaw CVE-2026-20896

Threat actors are probing a critical Gitea Docker vulnerability (CVE-2026-20896) that allowed unauthenticated users to impersonate others via the X-WEBAUTH-USER header when reverse-proxy trust was misconfigured; the weakness affected Gitea 1.26.2 and was fixed in 1.26.3 by removing the wildcard and requiring opt-in reverse-proxy authentication. Sysdig detected the first in-the-wild activity 13 days after disclosure across roughly 6,200 internet-facing instances; admins should patch promptly and review proxy settings.

Target staff verify leaked internal code; access to private git server tightened
security7 months ago

Target staff verify leaked internal code; access to private git server tightened

Multiple Target current and former employees confirm that the leaked internal source code and documentation match real Target systems, with references to real platforms and codenames; the company has accelerated a security change that restricts access to the on‑prem git.target.com Git server to corporate networks or VPN, making it unavailable from the public internet; investigators note a suspected connection to a previously infected workstation and the threat actor’s claim of an 860GB dataset, though Target has not disclosed whether a breach or insider involvement is under investigation.