Gogs Authentication Bypass Exposes Self-Hosted Git Infrastructure
A CVSS 9.4 vulnerability in Gogs permits authenticated users to execute arbitrary code. What this means for operators running self-hosted Git infrastructure.
Read article →Insights on offshore hosting, privacy, security and the cloud.
A CVSS 9.4 vulnerability in Gogs permits authenticated users to execute arbitrary code. What this means for operators running self-hosted Git infrastructure.
Read article →
Banking trojans Grandoreiro and BTMOB are actively targeting users in Spain, Portugal, Mexico, and Brazil. We examine the threat landscape and what operators should monitor.
Read article →
DLL side-loading remains a favoured technique among sophisticated threat actors targeting critical infrastructure. Learn how the attack works and what defences are most effective.
Read article →
Development tools remain a weak point in server security. We examine how compromised toolchains expose hosting environments and what to audit.
Read article →
When enforcement bodies issue DMCA subpoenas against domain registrars, what information must be handed over and what remains protected. A technical look at registrar obligations.
Read article →
npm's staged publishing feature adds a human review gate before packages go live. We examine the mechanics, limitations, and what operators should know.
Read article →