ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Over 8,300 internet-exposed Gitea instances remain unpatched against CVE-2026-60004, a critical code injection flaw actively exploited in remote code execution attacks. The vulnerability, reported by Shai Rod, lets authenticated attackers execute shell commands via the diffpatch API endpoint. Gitea patched it in version 1.27.1, and CISA ordered federal agencies to patch by August 28.
Tracked by ByteBrief