Hackers Hijack 700+ Gogs Servers Using Unpatched Zero Day in Massive Global Attack
Hackers are exploiting an unpatched Gogs zero day (CVE-2025-8110) to gain remote code execution via symlink path traversal, compromising over 700 servers. Attackers create rogue repositories, deploy Supershell malware, and target exposed instances with open registration enabled.
Tappy Admin
3 min read
Dec 11, 2025
69 views
#Gogs
#zero day vulnerability
#CVE-2025-8110
#remote code execution
#path traversal
#Supershell malware
#server compromise
#cybersecurity
#Git servers
#exploitation campaign
#threat actors
#Wiz Research
#open registration risk
#self hosted Git
#RCE attack
Read More