ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
CISA added CVE-2026-60004, a critical Gitea code injection flaw, to its KEV catalog after active exploitation. The vulnerability allows authenticated users with repository write access to execute shell commands via the diffpatch API endpoint. Gitea patched it in version 1.27.1, and federal agencies must patch by August 28.
Tracked by ByteBrief