Skip to main content

Share story

Security

GitLab patches critical unauthenticated GraphQL project-deletion flaw

GitLab patches critical unauthenticated GraphQL project-deletion flaw Image: Primary
GitLab released updates for a critical GraphQL vulnerability that could, under certain conditions, let an unauthenticated attacker remotely modify or delete public projects and user data on self-managed installations. GitLab rated CVE-2026-19478 at CVSS 9.4 and issued fixes in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. GitLab.com and GitLab Dedicated were already patched. The advisory does not name the affected directive or disclose the conditions required for exploitation.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News, cybersecuritydive.com, SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Oregon DOJ reviews McMinnville breach notification timeline

The Oregon Department of Justice is reviewing McMinnville's data breach and notification timeline, KPTV reported. The city sent formal notices on September 29 after detecting unusual network activity on or about July 15. Its inves...

Security
Security

Pentagon notifies millions of exposed personal data

The Pentagon's Defense Manpower Data Center is notifying people that unauthorized users accessed files containing unencrypted personal information. The breach affects 2.76 million living individuals and 294,000 deceased individual...

Security
Security

Kiteworks patches flaw allowing remote takeover of email gateway

Kiteworks released updates addressing 126 vulnerabilities, including a maximum-severity flaw that can let unauthenticated remote attackers take over its Email Protection Gateway. Tracked as CVE-2026-54154, the flaw affects every g...

Security
Security

AWS moves GuardDuty runtime monitoring billing into Security Hub

AWS says GuardDuty Runtime Monitoring is now included in the Security Hub Threat Analytics plan. For accounts and regions with Security Hub enabled, runtime monitoring usage moves from separate GuardDuty charges to one Security Hu...