Back Defendwork Critical RCEs in GitLab, Dell CSM, SharePoint; Warlock ransomware escalates
GitLab and Dell released critical patches today for remote code execution vulnerabilities affecting AI Gateway and Container Storage Modules. Warlock ransomware is actively exploiting SharePoint flaws against water utilities, telecom operators, and government bodies. Organizations must apply patches immediately and audit SharePoint for unauthorized access.
GitLab released patches for critical AI Gateway vulnerabilities allowing arbitrary command execution on self-hosted instances.
Dell disclosed CVSS 10.0 authentication bypass flaws in Container Storage Modules enabling unauthenticated root access on Kubernetes nodes.
Warlock ransomware group is actively exploiting SharePoint vulnerabilities to target water utilities, telecom operators, regional government bodies, and universities across multiple countries.
A China-nexus threat actor deployed the Antino backdoor using Outlook and OneDrive for command and control in a campaign targeting government and policy organizations across Asia.
Frontline Education disclosed a data breach affecting school district employees after attackers exploited third-party software vulnerabilities.
1. GitLab AI Gateway Remote Code Execution
Severity: CRITICAL Affected: Technology
GitLab has released patches for critical vulnerabilities in its AI Gateway service that could allow authenticated users with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway instances [1] [2] . The AI Gateway is the service connecting GitLab instances to AI models, and the vulnerability affects only organizations hosting their own infrastructure [1] . CVE-2026-90970 and CVE-2026-85706 have been identified, and GitLab has urged customers to patch immediately [2] . Sources: [1] The Hacker News [2] BleepingComputer
Identify all self-hosted GitLab AI Gateway deployments in your environment
Apply latest GitLab patches to all affected instances immediately
Review access logs for Duo Agent Platform users during the vulnerability window
Restrict AI Gateway access to trusted networks pending patch deployment
2. Dell Container Storage Modules Authentication Bypass
Severity: CRITICAL Affected: Technology
Dell has released security updates addressing multiple critical flaws in Dell Container Storage Modules (CSM) that could enable unauthenticated attackers to take over Kubernetes nodes [1] . a reported vulnerability (identifier could not be verified against NVD and has been withdrawn) carries a CVSS score of 10.0 and involves missing authentication for critical functions, allowing bad actors to gain admin-level access and root privileges on vulnerable systems [1] . Sources: [1] The Hacker News
Prioritize patching of all Dell CSM deployments immediately
Audit Kubernetes clusters for signs of unauthorized access or privilege escalation
Implement network segmentation to restrict CSM access from untrusted sources
Monitor container logs for suspicious authentication bypass attempts
3. Warlock Ransomware Expanding SharePoint Exploitation Campaign
Severity: HIGH Affected: Energy Telecom Government Education
The China-linked Warlock ransomware group has been actively exploiting SharePoint vulnerabilities since July 2025 to target critical infrastructure organizations ⚠ including water utilities, telecom providers, regional government bodies, and universities [1] [2] [3] . The group exploits a variety of SharePoint flaws to gain initial access, and attacks have been documented across Portuguese and Spanish-speaking countries as well as additional regions [2] [3] . Warlock uses these vulnerabilities to establish persistence and deploy ransomware payloads against high-value targets [1] . Sources: [1] BleepingComputer [2] The Record [3] SecurityWeek
Apply all available Microsoft SharePoint security patches without delay
Conduct immediate audit of SharePoint access logs for indicators of compromise
Implement multi-factor authentication on all SharePoint administrative accounts
Segment SharePoint infrastructure from critical operational technology networks
Enable enhanced monitoring and alerting for unusual file access or sharing activity
4. Antino Backdoor Campaign Targeting Asian Government Entities
Severity: HIGH Affected: Government
A China-nexus threat actor has launched a campaign deploying the Antino backdoor to target government and policy organizations across Asia, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar [1] . The backdoor uses Outlook and OneDrive for command-and-control communications, leveraging legitimate Microsoft services to evade detection [1] . Sources: [1] The Hacker News
Monitor for abnormal Outlook and OneDrive API activity, particularly external data exfiltration
Audit Microsoft 365 account permissions and remove unnecessary delegated access
Implement conditional access policies to restrict login from unusual geographic locations
Review email forwarding rules for unauthorized redirection of sensitive communications
5. Frontline Education Data Breach Affecting School Districts
Severity: HIGH Affected: Education
Frontline Education is notifying school districts of a data breach in which attackers exploited a vulnerability in third-party software to gain unauthorized access to systems and steal employee information, including Social Security numbers [1] . Sources: [1] BleepingComputer
Notify affected employees and provide credit monitoring services
Inventory all third-party software integrations with Frontline Education systems
Patch the vulnerable third-party software component immediately
Review logs to determine the extent of data accessed during the compromise window
Microsoft released patches for nearly 1,000 security holes in its Windows operating systems and other software; see earlier coverage for Fortinet FortiMail and related CVEs. Dutch police arrested a 23-year-old convicted cybercriminal suspected of aiding ShinyHunters data theft group. A U.S. Army soldier was sentenced to 70 months in prison for hacking AT&T and Verizon networks and stealing call and text metadata for over 100 million customers. ⚠ An Iranian national alleged to have participated in dozens of university breaches was extradited from Montenegro to face U.S. charges. The FBI is investigating a dark web service offering digital scans of over 153 million U.S. and Canadian drivers licenses.
Today’s Action Checklist
☐ URGENT: Patch GitLab AI Gateway instances with latest security releases
☐ URGENT: Apply Dell CSM patches to all Kubernetes environments
☐ URGENT: Deploy all available Microsoft SharePoint patches and audit for Warlock indicators
☐ HIGH: Review SharePoint and Outlook access logs for anomalies
☐ HIGH: Audit third-party software integrations in critical business applications
☐ MEDIUM: Update incident response plans to reflect expanded Warlock targeting of critical infrastructure sectors
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
