Visitor
•
1 Message
Site review request
Advanced Security is blocking a host I own and operate:
Hostname: [Edited: Personal Information]
The block is hostname-based. Connections to that name on ports 80 and 443 are intercepted and answered with a redirect to safebrowse.io/warn.html. Connecting to the same IP address with any other hostname is not blocked, and SSH to the same IP is unaffected, so the listing is against the name, not the address.
The server was previously compromised; it ran Gitea 1.22.6 and was exploited via CVE-2026-60004 in August 2026. I believe this is the reason for the listing.
It has since been fully remediated (2026-09-03):
Gitea upgraded 1.22.6 -> 1.27.3 (the fixed release), verified by SHA256 and GPG signature
Public registration disabled, sign-in required, git hooks disabled
123 attacker-created accounts removed; all secrets rotated
The service account's shell set to /sbin/nologin
Known C2 addresses null-routed at the firewall
Password SSH authentication disabled; key-only access verified
Continuous behavioural monitoring added (fileless/memfd execution, execution from temp directories, unexpected listeners, mining-pool ports) alongside weekly full-filesystem antivirus scans
The host has been clean since. It serves only my own private API endpoint and a personal Git forge, both requiring authentication, with no public registration and no user-generated content reachable without sign-in.
I would be grateful if you could re-scan the hostname and remove the listing if it is now clear. If anything is still being detected, I would very much like to know what, so I can address it.
Thank you.


XfinityJanelle
Official Employee
•
2.4K Messages
9 days ago
Hey @user_b01102, Thank you for visiting our official Xfinity Forums Community support page. We greatly appreciate you taking the time to share your experience regarding advanced security blocks. We would recommend having this review by visiting https://spa.xfinity.com/help/advanced-security?faq=advanced-security with the customer security assurance team. There is a place to report the issue for review.
(edited)
0
0