Supershell C2 appears in the context of campaigns exploiting a zero-day in the Gogs self-hosted Git service.
Overview
Supershell C2 appears in the context of campaigns exploiting a zero-day in the Gogs self-hosted Git service. The activity has drawn CISA’s attention, with the zero-day added to the Known Exploited Vulnerabilities list and federal agencies urged to patch or retire Gogs to prevent compromise. This underscores the risk of exposed self-hosted services and the role of C2-like tooling in post-exploitation, marking Supershell C2 as a significant concern for cybersecurity defense, particularly in federal environments.
Related Threat Clusters
-
CISA Directs Agencies to Address Gogs RCE Vulnerability Exploited in Zero-Day Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that government agencies secure their systems against a critical Gogs vulnerability, tracked as CVE-2025-8110. This remote code execution…
6 articles · Updated January 12, 2026
Recent Intelligence Reports
- Fed agencies urged to ditch Gogs as zero-day makes CISA list — Theregister · January 13, 2026
- Federal agencies told to fix or ditch Gogs as exploited zero — Theregister · January 13, 2026