CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

Over 8,300 Gitea servers vulnerable to code execution attacks

Today's briefing highlights critical ServiceNow patches, ongoing Gitea server exploitation, physical robotics vulnerabilities, and employee data loss at Hasbro.

Critical remote code execution risks across cloud platforms, open-source infrastructure, and physical hardware dominate today's briefing. Enterprise security teams face urgent remediation tasks, led by maximum-severity vulnerabilities in business platforms and active internet-wide scanning targeting exposed code repositories.

Over 8,300 Gitea servers vulnerable to code execution attacks

Shadowserver reports that over 8,300 internet-exposed Gitea servers remain unpatched against a critical vulnerability currently being leveraged in active remote code execution attacks.

Why it matters
Organizations relying on exposed Gitea instances face imminent threat of compromise, as attackers are actively exploiting unpatched servers to execute arbitrary code.
  • Gitea
Read the original

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow patched four vulnerabilities in the ServiceNow AI Platform, including three CVSS 10.0 flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) that could allow unauthenticated remote code execution, privilege escalation, and SQL injection.

Why it matters
Unauthenticated attackers could execute arbitrary code, modify instance data, and escalate privileges on vulnerable self-hosted ServiceNow instances.
What to do
Apply ServiceNow security updates immediately to all self-hosted and partner-managed instances.
  • ServiceNow
  • injection
  • RCE
  • patch
Read the original

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC.

Why it matters
Attackers within Bluetooth or local network range can take full root control of affected humanoid robots, while lack of verified firmware patch guidance leaves devices vulnerable.
  • Unitree
  • RCE
  • IoT
  • Bluetooth
Read the original

Toy-making giant Hasbro disclose data breach affecting employees

Toy and game manufacturer Hasbro disclosed a security incident where unauthorized attackers gained access to personal and financial information belonging to employees.

  • Hasbro
Read the original

Key Reasons Why Identity Fabric Matters in 2026

An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure.

Why it matters
As enterprise infrastructure expands across hybrid environments, unmanaged workloads and identity policy gaps increase the attack surface for unauthorized access.
  • identity
  • cloud
Read the original

Key takeaways

  • ServiceNow issued patches for three CVSS 10.0 vulnerabilities allowing unauthenticated Remote Code Execution and SQL injection.
  • Over 8,300 internet-exposed Gitea servers remain unpatched against critical remote code execution flaws under active attack.
  • Security research revealed two root RCE flaw chains in the Unitree G1 EDU humanoid robot, including a path starting via Bluetooth Low Energy.
  • Hasbro confirmed a security incident involving unauthorized access to employee personal and financial information.
  • Gitea
  • Unitree
  • Hasbro
  • ServiceNow
  • RCE