My Homelab Got Hacked - A Postmortem
Summary
An in-depth postmortem of a homelab compromise involving CVE-2026-60004 in Forgejo/Gitea, which exploited the diffpatch endpoint to deploy a crypto-miner. The article details attacker behavior, observed indicators in logs, the payload characteristics, and remediation steps including backups, updating Forgejo to v16, and tightening outbound access. It offers practical lessons for SMBs running containerized apps.