Skip to main content

Tag: gitlab

6 articles

Rows of computer servers and workstations in a brightly-lit software development room with blank laptop screens.

GitLab Warns Users to Patch Path Traversal Flaw

GitLab is urging users to upgrade immediately to patch a critical path traversal flaw, CVE-2026-85706, that could expose sensitive files to unauthenticated attackers. This maximum-severity vulnerability requires prompt action to protect self-managed GitLab installations.

Analyst 207
Server rack in a network operations room with rows of computer servers and equipment.

GitLab Flaw Exploited in Wild Days After Disclosure

In a chilling demonstration of the new reality in vulnerability exploitation, attackers began exploiting a newly disclosed GitLab flaw within minutes of its public disclosure, leaving little time for patching. This rapid reproduction and exploitation is a stark reminder that waiting for the next patch cycle may no longer be a viable defense strategy.

Analyst 207
Developers gather around a large screen in a bright, open workspace surrounded by laptops and coding gear.

GitLab Patches Flaw That Exposes Public Projects to Unauthenticated Deletion

GitLab has urgently patched a critical vulnerability that left public projects open to deletion by anyone, with no login required - a flaw that scored a near-perfect 9.4 on the severity scale. The fix addresses a GraphQL weakness that could let unauthenticated users remotely modify or delete public projects and user data.

Analyst 207
Modern data center with rows of servers and networking equipment, and a single out-of-focus computer workstation in the…

TeamPCP Linked to Years-Old Cryptojacking Operation

New research reveals that TeamPCP, a notorious cryptojacking group, has been secretly operating for years, with evidence tracing back to 2020 and a recent connection to a massive supply-chain compromise in March 2026. Their operation, linked to the TA-NATALSTATUS activity, involved a sophisticated deployment framework and shared infrastructure.

Analyst 207
Security researcher inspects a server in a data center.

GitLab RCE Exploit Published, Targets Unpatched Servers

A security researcher has just published a working exploit that can execute commands on unpatched GitLab servers, putting sensitive data and systems at risk. If your GitLab server is unpatched, it's crucial to update now to prevent potential code execution and data breaches.

Analyst 207
Brightly lit coding workspace with laptop showing GitHub/GitLab page surrounded by coding materials and documents.

North Korean Hackers Exploit Coding Lures to Steal Crypto Credentials

In a sneaky move, North Korean hackers sent over 250 emails with innocent-looking coding tasks to nearly 100 US-based organizations, tricking them into handing over cryptocurrency credentials. The clever phishing scam, tracked as UNK_DeadDrop, targeted tech, education, and finance firms, with a special focus on cryptocurrency companies.

Analyst 207