2 hours ago · 11 min read2136 words · Tech · hide · 0 comments

As with my previous incident report, this is not my usual blogging style. When something goes wrong, the professional practice is to write up what happened, what was done about it, and what should change. This is the postmortem for a security incident on my self-hosted git server. A note on AI use: My AI statement declares that unless stated otherwise, content on this site was written by me. For this post, I am stating otherwise. I used an LLM (Claude) heavily throughout this incident, to assist with the analysis and recovery. I also used it in preparing the draft of this post. Incident Summary Severity: critical Started: Tues, 4 Aug 2026 (first attacker activity) Detected: Thu, 3 Sep 2026 Concluded: Fri, 4 Sep 2026 Impact: remote code execution on the git server as the service account 94 attacker accounts created, each with one repository cryptominer installed and running, saturating three CPU cores application secrets and service credentials exfiltrated no repository content…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.