Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let’s dive in!
As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I’m implementing myself:
- Miner detection. I’ve updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I’m doing simple up / down monitoring. Fixed.
- Access logging. I turned on access logging for my homelab Caddy instances.
- Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
- Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that’s next.
- Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
- Built a tool.
log-inventory.sh, so “could I actually reconstruct what happened” is a command I run instead of a thing I assume.



Don’t let this discourage you.
You can self host on your local network just fine and never portforward which is what exposes it to the outside.
I don’t need to watch tv or upload pictures to my server outside of my home. Its perfectly useable.
When you are ready and feel more confident you can setup your own wireguard vpn and only expose that.
Then Your device can connected to that vpn tunnels inside and can acces everything like home.
Currently without vpn your device is at risk every time it connects to a network you don’t own. A third party vpn is not a guarantee your data is safe either. Your home vpn though means all your outside the home networking is fully encrypted and outsiders cant even detect your home adresses is running a vpn to hack. (No ping unless you have the key)
This! Good advice! I went this path last year so i can give some extra advice for everyone who wants to start:
Before doing anything, buy a new router and put your iot devices and phones in a isolated guest network. Maintain the router updated. After that, you can work, learn and test without fear. Everything stays in your home.
Then like @webghost0101@sopuli.xyz already said, once you get confident, you can run a vpn tunnel to access your lan. This setup is pretty robust, hard to fuck up, and doable even for newbies. (If i can do it, everyone can, i assure you). Lots of guides out there.
Last advice, which you should already be doing, but setup a backup.