Black Hat Europe 2025 | From Live Exploitation to Zero-Day Discovery: Investigating Attacks on Gogs
A single infected server led us into a much larger story. While investigating suspicious repositories on exposed **** Git servers, we uncovered signs of active exploitation: commands hidden inside repository configurations, payloads fetching remote shells, and infrastructure linked to a custom-packed Supershell C2. What at first looked like an opportunistic abuse of a known bug turned out to be something more: an unpatched zero-day vulnerability, already being leveraged in the wild. While an older RCE was known, the affected systems matched a yet-unknown exploit chain. This mismatch was the first clue that attackers were using a new vulnerability, rather than simply reusing a patched one. In this talk, we will retrace that investigation. Starting from live exploitation artifacts, we will show how we correlated repositories across multiple tenants, fingerprinted vulnerable internet-facing servers, and pieced together the attack chain. Our scans revealed over 700 compromised **** instances worldwide, with dozens already updated yet still showing signs of compromise. The evidence demonstrated that attackers had a working exploit before disclosure. We will close with lessons learned for defenders. These include how to detect malicious repository abuse in developer platforms, techniques for hunting zero-days from threat intelligence leads, and what this case study means for the broader risk landscape of self-hosted developer tools. By: Gili Tikochinski | Malware Researcher, Wiz Yaara Shriki | Threat Researcher, Wiz https://blackhat.com/eu-25/briefings/...
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

Black Hat Europe 2025 | The Post-NVD Era: A Call for Global CVE Decentralization

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

How to Detect a Fake Cell Tower Spying on Your Phone (Stingray)

Attacking AI - Jason Haddix - NDC Security 2026

Kernel-Hack-Drill Masterclass // Alexander Popov // #PHTalks KL

DEF CON 33 - Turning Camera Surveillance on its Axis - Noam Moshe

researcher accidentally finds 0-day affecting his entire internet service provider

Black Hat Europe 2025 | Unveiling System Management Mode Memory Corruption Vulnerability Via Fuzzing

AI Will End Every Disease In The Next Decade (Demis Hassabis Interview)

Exposing The Solid State Donut Battery. It's Over.

SecTor 2025 | Rethinking Phishing Detection in the Age of AI and Disinformation

The Biggest Hacking Mystery of Our Time: Shadow Brokers

Something is jamming GPS over Europe. Here's what we found

Black Hat Europe 2025 | You Win Some, You CheckSum: A Kerberos Delegation Vulnerability

I Hacked This Temu Router. What I Found Should Be Illegal.

Black Hat Europe 2025 | A crash course in revealing insecure blind spots for DoS & DDoS

Ex-Google Officer: You Only Have 3 Years Left Before It Hits! - Mo Gawdat

Fable JUST made EVERYONE MAD...

