CVE Tools

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The Hacker NewsBy The Hacker News

PoC publicWindows DefenderMabna Institute

Our summary

Security researchers have disclosed critical remote code execution vulnerabilities in Gogs (CVE-2026-52813) and n8n (CVE-2026-33696), prompting immediate patch releases. Additionally, the U.S. Department of Justice has formally charged seventeen individuals affiliated with the Iran-based Mabna Institute for orchestrating a massive cyber-theft campaign targeting global academic institutions.

Administrators should update Gogs to version 0.14.3 and n8n to versions 2.14.1, 2.13.3, or 1.123.27 to mitigate these risks. This week’s intelligence also highlights new exploitation techniques involving Microsoft Defender components and AI-assisted vulnerability discovery.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store