Sysdig just published telemetry confirming active probing of CVE-2026-20896 (Gitea Docker auth bypass) 13 days after disclosure. First observed attempt came from ProtonVPN egress 159.26.98\[.\]241. Detection for the X-WEBAUTH-USER header injection was already live in my repo before that dropped.
Since my last post, bikini pushed five new exploitarium entries and I’ve added coverage for all of them:
\-curl SMTP CRLF injection \-NodeBB ActivityPub UID spoofing \-Next.js unstable\\\cache object argument collision \-libarchive ZIP debuginfod size boundary bypass \-Pillow ImageCms OOB write
Repo is now 55 KQL rules across 23 product folders. All written for Sentinel / Defender XDR. Language translation on detections.ai handles other stacks.
Intel report: https://systemtwosecurity.com/share/inspiration/VNJMKFVM
GitHub: https://github.com/Ethan-Andrews/Exploitarium-Detections
The Gitea finding is being actively probed. If you’re running any default Gitea Docker deployments that haven’t patched to 1.26.3 yet, that’s the one to prioritize.
Happy to discuss detection logic or the specific technique in the comments.