Skip to content
Critical RCEs in GitLab, Dell CSM, SharePoint; Warlock ransomware escalates

Critical RCEs in GitLab, Dell CSM, SharePoint; Warlock ransomware escalates

Defendwork •defend.network • October 3, 2026

GitLab and Dell released critical patches today for remote code execution vulnerabilities affecting AI Gateway and Container Storage Modules. Warlock ransomware is actively exploiting SharePoint flaws against water utilities, telecom operators, and government bodies. Organizations must apply patches immediately and audit SharePoint for unauthorized access.

GitLab released patches for critical AI Gateway vulnerabilities allowing arbitrary command execution on self-hosted instances.

Dell disclosed CVSS 10.0 authentication bypass flaws in Container Storage Modules enabling unauthenticated root access on Kubernetes nodes.

Warlock ransomware group is actively exploiting SharePoint vulnerabilities to target water utilities, telecom operators, regional government bodies, and universities across multiple countries.

A China-nexus threat actor deployed the Antino backdoor using Outlook and OneDrive for command and control in a campaign targeting government and policy organizations across Asia.

Frontline Education disclosed a data breach affecting school district employees after attackers exploited third-party software vulnerabilities.

1. GitLab AI Gateway Remote Code Execution

Severity: CRITICAL Affected: Technology

GitLab has released patches for critical vulnerabilities in its AI Gateway service that could allow authenticated users with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway instances [1] [2] . The AI Gateway is the service connecting GitLab instances to AI models, and the vulnerability affects only organizations hosting their own infrastructure [1] . CVE-2026-90970 and CVE-2026-85706 have been identified, and GitLab has urged customers to patch immediately [2] . Sources: [1] The Hacker News [2] BleepingComputer

Identify all self-hosted GitLab AI Gateway deployments in your environment

Apply latest GitLab patches to all affected instances immediately

Review access logs for Duo Agent Platform users during the vulnerability window

Restrict AI Gateway access to trusted networks pending patch deployment

2. Dell Container Storage Modules Authentication Bypass

Severity: CRITICAL Affected: Technology

Dell has released security updates addressing multiple critical flaws in Dell Container Storage Modules (CSM) that could enable unauthenticated attackers to take over Kubernetes nodes [1] . a reported vulnerability (identifier could not be verified against NVD and has been withdrawn) carries a CVSS score of 10.0 and involves missing authentication for critical functions, allowing bad actors to gain admin-level access and root privileges on vulnerable systems [1] . Sources: [1] The Hacker News

Prioritize patching of all Dell CSM deployments immediately

Audit Kubernetes clusters for signs of unauthorized access or privilege escalation

Implement network segmentation to restrict CSM access from untrusted sources

Monitor container logs for suspicious authentication bypass attempts

3. Warlock Ransomware Expanding SharePoint Exploitation Campaign

Severity: HIGH Affected: Energy Telecom Government Education

The China-linked Warlock ransomware group has been actively exploiting SharePoint vulnerabilities since July 2025 to target critical infrastructure organizations ⚠ including water utilities, telecom providers, regional government bodies, and universities [1] [2] [3] . The group exploits a variety of SharePoint flaws to gain initial access, and attacks have been documented across Portuguese and Spanish-speaking countries as well as additional regions [2] [3] . Warlock uses these vulnerabilities to establish persistence and deploy ransomware payloads against high-value targets [1] . Sources: [1] BleepingComputer [2] The Record [3] SecurityWeek

Apply all available Microsoft SharePoint security patches without delay

Conduct immediate audit of SharePoint access logs for indicators of compromise

Implement multi-factor authentication on all SharePoint administrative accounts

Segment SharePoint infrastructure from critical operational technology networks

Enable enhanced monitoring and alerting for unusual file access or sharing activity

4. Antino Backdoor Campaign Targeting Asian Government Entities

Severity: HIGH Affected: Government

A China-nexus threat actor has launched a campaign deploying the Antino backdoor to target government and policy organizations across Asia, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar [1] . The backdoor uses Outlook and OneDrive for command-and-control communications, leveraging legitimate Microsoft services to evade detection [1] . Sources: [1] The Hacker News

Monitor for abnormal Outlook and OneDrive API activity, particularly external data exfiltration

Audit Microsoft 365 account permissions and remove unnecessary delegated access

Implement conditional access policies to restrict login from unusual geographic locations

Review email forwarding rules for unauthorized redirection of sensitive communications

5. Frontline Education Data Breach Affecting School Districts

Severity: HIGH Affected: Education

Frontline Education is notifying school districts of a data breach in which attackers exploited a vulnerability in third-party software to gain unauthorized access to systems and steal employee information, including Social Security numbers [1] . Sources: [1] BleepingComputer

Notify affected employees and provide credit monitoring services

Inventory all third-party software integrations with Frontline Education systems

Patch the vulnerable third-party software component immediately

Review logs to determine the extent of data accessed during the compromise window

Microsoft released patches for nearly 1,000 security holes in its Windows operating systems and other software; see earlier coverage for Fortinet FortiMail and related CVEs. Dutch police arrested a 23-year-old convicted cybercriminal suspected of aiding ShinyHunters data theft group. A U.S. Army soldier was sentenced to 70 months in prison for hacking AT&T and Verizon networks and stealing call and text metadata for over 100 million customers. ⚠ An Iranian national alleged to have participated in dozens of university breaches was extradited from Montenegro to face U.S. charges. The FBI is investigating a dark web service offering digital scans of over 153 million U.S. and Canadian drivers licenses.

Today’s Action Checklist

☐ URGENT: Patch GitLab AI Gateway instances with latest security releases

☐ URGENT: Apply Dell CSM patches to all Kubernetes environments

☐ URGENT: Deploy all available Microsoft SharePoint patches and audit for Warlock indicators

☐ HIGH: Review SharePoint and Outlook access logs for anomalies

☐ HIGH: Audit third-party software integrations in critical business applications

☐ MEDIUM: Update incident response plans to reflect expanded Warlock targeting of critical infrastructure sectors