Floating servers illustrating cybersecurity vulnerabilities, AI, and botnets.

Daily Cybersecurity News - May 28, 2026

Gogs Zero Day Grants Remote Code Execution

Gogs self-hosted Git service has an unpatched zero day that hands attackers remote code execution on exposed instances.

The flaw requires a basic user account, but default open registration can make exploitation easy. No CVE assigned yet. It affects internet-facing deployments running the latest versions.

Anyone running Gogs directly reachable from the internet needs to isolate or take it offline until a fix ships.

Public technical details are available.

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

Fortinet's FortiClient EMS has a critical flaw that attackers are already using in new campaigns.

CVE-2026-35616 lets unauthenticated remote users run code through FortiClient EMS. CVSS 9.1 and actively exploited.

Affects FortiClient EMS 7.4.5 and 7.4.6.

Hotfixes released in April after initial zero-day sightings.

Source: SecurityWeek

CrowdStrike and Google Shut Down Glassworm Botnet

Cybercriminals ran the Glassworm botnet to infect open source projects with malware, then hit the developers and companies using those packages.

They compromised build pipelines and injected malicious code into popular repositories, turning supply chain trust into a weapon. The botnet relied on automated scanning and credential theft to expand.

This is standard supply chain tradecraft with little novelty, just better scale from the botnet layer. CrowdStrike, Google, and Shadowserver teamed up for the disruption.

The operation cut off four C2 channels and disrupted malware delivery.

Source: TechCrunch

AI Assisted Exploit Development Outpaces Scanner Detection

Attackers now use AI to build working exploits for new CVEs much faster than scanners can detect them.

The research found exploit development time dropped sharply with AI assistance. Traditional scanners still lag behind these automated variants in coverage.

Dark Reading reports on the trend but provides no independent verification or prior-year benchmarks in the piece. Vendor influence on the underlying research remains unclear.

The study analyzed tens of thousands of CVEs, but the findings still come from vendor research.

Source: Dark Reading