Cisco Talos says a Chinese-speaking crew paired PentestGPT and DeepAudit with Metasploit and a 170,000-URL target list to compromise web servers at scale. Every entry flaw named is years old.
Reality
- Evidence62
- Adoption20
- Hype gap+30
- Incentives65
- Confidence62
Rapid7 scored it 9.9 and Gogs shipped 0.14.3 on June 7, 2026. The reason it rates that high is configuration: open registration and unlimited repository creation let a stranger own the repo they attack from.
Publishers:rapid7.com · runzero.com
Reality
- Evidence86
- Adoption50
- Hype gap+8
- Incentives72
- Confidence70
Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+8
- Incentives38
- Confidence60
Rapid7 published a Metasploit module for CVE-2026-85706, an unauthenticated file read it says is already exploited against self-hosted GitLab. Every CE and EE build from 18.7 stays exposed until 19.1.8, 19.2.6 or 19.3.2.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence55
Accenture's majority stake closed first, then Dragos completed both acquisitions on Monday. One supplier now holds network discovery, firmware inventory and OT threat detection. Neither price was disclosed.
Reality
- Evidence48
- Adoption25
- Hype gap+25
- Incentives70
- Confidence60
Cisco Talos says UAT-10147, a Chinese-speaking group doing SEO fraud and data theft, wired AI tooling into exploitation, validation and persistence. An open directory gave the operation away.
Reality
- Evidence62
- Adoption52
- Hype gap+22
- Incentives60
- Confidence58