Attackers Exploit GitLab Flaw to Read Server Files Without a Login
An exploited GitLab flaw exposes arbitrary server files through the commits API. Self-managed operators should install 19.1.8, 19.2.6, or 19.3.2 immediately.
Read article →Reader view
Choose the default article length.
Cloud platforms, SaaS, containers, and infrastructure.
An exploited GitLab flaw exposes arbitrary server files through the commits API. Self-managed operators should install 19.1.8, 19.2.6, or 19.3.2 immediately.
Read article →Kestra OSS versions through 1.3.20 let unauthenticated requests create workflows and run commands as root inside workers. CISA confirms exploitation.
Read article →Attackers made Coder's trusted registry serve malicious Terraform modules. Operators have a 14-hour exposure window, concrete indicators, and urgent credential work.
Read article →Google observed attackers move from cloud compromise to agent-enabled mass credential harvesting in under six hours, shrinking the time defenders have to respond.
Read article →JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Read article →Unit 42 traced an AI-assisted ransom intrusion across web, repository, secrets, CI/CD and cloud systems in less than 10 hours. These behaviors can reveal the loop.
Read article →Recovered tooling shows how forged WebDAV requests exposed nuclear records and credentials, with specific version, request-pattern, and signing-key checks for defenders.
Read article →Fortinet traced one stolen AWS administrator key through a new IAM user, Marketplace agreements, and billable Bedrock model calls.
Read article →A fail-open agent dashboard exposed one public-model key for three weeks, while noisy usage signals and absent spend limits delayed recognition.
Read article →Mandiant traced BREEZE COMET from vishing, rogue branch hardware and stolen cloud credentials to payment APIs used for hundreds of fraudulent transfers.
Read article →CISA says attackers are exploiting a Linux IPv6 kernel flaw that can give a local user root and, on affected RHEL 10 systems, escape a container.
Read article →Next.js fixed two unauthenticated code-execution paths involving AVIF processing and Windows servers. Self-hosted operators need 15.5.24 or 16.3.3.
Read article →CareCloud says forensic review confirmed patient data exfiltration. HHS reports 3.76 million affected people, while public records do not map specific fields to each person.
Read article →