Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let’s dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I’m implementing myself:

  • Miner detection. I’ve updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I’m doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that’s next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so “could I actually reconstruct what happened” is a command I run instead of a thing I assume.
  • tofu
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 hours ago

    Good write up! Since you’re using Komodo already, are your compose stacks in git? Because if they are, check the renovate bot. It will read your files with their pinned image tags, check upstream for newer tags, and creates MRs (can also be set to auto merge) to update. Can be configured per stack.

    • ExperimentalGuy@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 hour ago

      What’s komodo? I’m thinking of starting a home server so learning how to harden/automate updates (which is what it sounds like you’re saying) is what I want to learn.