Researchers at Wiz uncovered a zero-day flaw in Gogs after they traced unusual malware activity back to the platform. Attackers now exploit the bug to overwrite files and run malicious commands, and they’ve already hit more than 700 exposed servers. The activity began in July, marked by strange auto-generated repositories. Wiz urges administrators to shut off open registration and restrict internet access before the intrusions spread further.
