Black Hat Europe 2025 | From Live Exploitation to Zero-Day Discovery: Investigating Attacks on Gogs

A single infected server led us into a much larger story. While investigating suspicious repositories on exposed **** Git servers, we uncovered signs of active exploitation: commands hidden inside repository configurations, payloads fetching remote shells, and infrastructure linked to a custom-packed Supershell C2. What at first looked like an opportunistic abuse of a known bug turned out to be something more: an unpatched zero-day vulnerability, already being leveraged in the wild. While an older RCE was known, the affected systems matched a yet-unknown exploit chain. This mismatch was the first clue that attackers were using a new vulnerability, rather than simply reusing a patched one. In this talk, we will retrace that investigation. Starting from live exploitation artifacts, we will show how we correlated repositories across multiple tenants, fingerprinted vulnerable internet-facing servers, and pieced together the attack chain. Our scans revealed over 700 compromised **** instances worldwide, with dozens already updated yet still showing signs of compromise. The evidence demonstrated that attackers had a working exploit before disclosure. We will close with lessons learned for defenders. These include how to detect malicious repository abuse in developer platforms, techniques for hunting zero-days from threat intelligence leads, and what this case study means for the broader risk landscape of self-hosted developer tools. By: Gili Tikochinski | Malware Researcher, Wiz Yaara Shriki | Threat Researcher, Wiz https://blackhat.com/eu-25/briefings/...

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
▶︎

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

Black Hat Europe 2025 | The Post-NVD Era: A Call for Global CVE Decentralization
▶︎

Black Hat Europe 2025 | The Post-NVD Era: A Call for Global CVE Decentralization

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains
▶︎

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

How to Detect a Fake Cell Tower Spying on Your Phone (Stingray)
▶︎

How to Detect a Fake Cell Tower Spying on Your Phone (Stingray)

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

Kernel-Hack-Drill Masterclass // Alexander Popov // #PHTalks KL
▶︎

Kernel-Hack-Drill Masterclass // Alexander Popov // #PHTalks KL

DEF CON 33 - Turning Camera Surveillance on its Axis - Noam Moshe
▶︎

DEF CON 33 - Turning Camera Surveillance on its Axis - Noam Moshe

researcher accidentally finds 0-day affecting his entire internet service provider
▶︎

researcher accidentally finds 0-day affecting his entire internet service provider

Black Hat Europe 2025 | Unveiling System Management Mode Memory Corruption Vulnerability Via Fuzzing
▶︎

Black Hat Europe 2025 | Unveiling System Management Mode Memory Corruption Vulnerability Via Fuzzing

AI Will End Every Disease In The Next Decade (Demis Hassabis Interview)
▶︎

AI Will End Every Disease In The Next Decade (Demis Hassabis Interview)

Exposing The Solid State Donut Battery. It's Over.
▶︎

Exposing The Solid State Donut Battery. It's Over.

SecTor 2025 | Rethinking Phishing Detection in the Age of AI and Disinformation
▶︎

SecTor 2025 | Rethinking Phishing Detection in the Age of AI and Disinformation

The Biggest Hacking Mystery of Our Time: Shadow Brokers
▶︎

The Biggest Hacking Mystery of Our Time: Shadow Brokers

Something is jamming GPS over Europe. Here's what we found
▶︎

Something is jamming GPS over Europe. Here's what we found

Black Hat Europe 2025 | You Win Some, You CheckSum: A Kerberos Delegation Vulnerability
▶︎

Black Hat Europe 2025 | You Win Some, You CheckSum: A Kerberos Delegation Vulnerability

I Hacked This Temu Router. What I Found Should Be Illegal.
▶︎

I Hacked This Temu Router. What I Found Should Be Illegal.

Black Hat Europe 2025 | A crash course in revealing insecure blind spots for DoS & DDoS
▶︎

Black Hat Europe 2025 | A crash course in revealing insecure blind spots for DoS & DDoS

Ex-Google Officer: You Only Have 3 Years Left Before It Hits! - Mo Gawdat
▶︎

Ex-Google Officer: You Only Have 3 Years Left Before It Hits! - Mo Gawdat

Fable JUST made EVERYONE MAD...
▶︎

Fable JUST made EVERYONE MAD...

Google PANICS As GrapheneOS EXPLODES And Android Users WALK AWAY
▶︎

Google PANICS As GrapheneOS EXPLODES And Android Users WALK AWAY