Skip to main content

Share story

Security

GitLab flaw sees exploitation attempts days after patch

GitLab flaw sees exploitation attempts days after patch Image: Primary
Threat actors began attempting to exploit a critical GitLab code-injection flaw roughly two days after its public disclosure, according to WatchTowr's honeypot network. GitLab patched CVE-2026-19478, rated 9.4, on August 17 in specified Community and Enterprise Edition releases. The company said the defect could, under certain conditions, let an unauthenticated remote user modify or delete public projects and user data through a GraphQL directive. WatchTowr advised self-managed users to update and inspect web logs for requests containing "@gl_introduced."
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Policy
Products Policy

Boeing awarded US$20-billion Navy fighter development contract

Boeing has been awarded a US$20-billion US Navy contract to develop the F/A-XX sixth-generation fighter, New Atlas reports. Boeing beat rival Northrop Grumman for the contract. The Navy needs a multirole aircraft that can operate...

Products
Products

Valley National agrees to buy Bluevine for $340M

Valley National Bancorp has agreed to acquire New Jersey-based Bluevine for $340M, CTech reports. Bluevine provides digital banking and payments services to 175K small and medium-sized businesses in the US. The acquisition would ...

Security AI
Security AI

Proofpoint links TA419 phishing campaigns to US AI policy targets

Proofpoint has attributed credential phishing campaigns against U.S. AI experts at think tanks, universities and legal organizations to TA419, a group it describes as China-aligned and motivated by espionage. Its analysis describe...