Skip to content
CVE-2026-85706: GitLab Unauthenticated Arbitrary File Read via the Repository Commits API

CVE-2026-85706: GitLab Unauthenticated Arbitrary File Read via the Repository Commits API

Offensive-Security •OffSec Team • September 28, 2026

Ten lessons from Black Hat and DEF CON on AI agents, cheaper attacks, supply chain risk, security fundamentals and cyber skills.

Are Security Teams Keeping Pace With AI-Accelerated Threats?

The strongest response to AI-driven change is a workforce that can use faster tools without surrendering the judgment behind the work.

What If Your Idea Became the OffSec Lab?

Learn all OffSec’s new Creator Platform – create labs, earn rewards and help the security community skill up.

CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability

Who Secures AI When It Touches Every Security Team?

Learn how organizations can develop relevant offensive knowledge across every security function responsible for AI systems.

Introducing the AI Red Teaming Upskill Program

Introducing AI Red Teaming Upskill Program. New way to build AI security capabilities across teams with different roles and levels of experience.

What the Recent Water Systems Cyber Attacks Reveal Critical Infrastructure Security

The recent water system attacks are a reminder that familiar techniques can have serious consequences when they reach critical infrastructure. Preparing teams before the incident is just as important as responding to the last one.

How Federal Agencies Can Turn Year-End Funding Into Long-Term Cyber Capability

If your agency is planning how to use remaining Fiscal Year funding, now is the time to build a stronger cybersecurity workforce.

The EU AI Act Deadline Is Approaching. Is Your Workforce Ready?

The EU AI Act deadline is approaching but the attack surface is already here. Is your workforce ready to secure it?

What Security Leaders Discover When They Train Their Team in the Same Room

Learn how live cybersecurity training helps teams strengthen technical judgment before it matters most.

AI vs Traditional Penetration Testing: Which Approach Is Right for Your Organization?

When does your organization need traditional penetration testing, when does it need AI security testing, and when does it need both?

Cybersecurity Training in the Age of AI

How AI is changing cybersecurity training, why live learning matters, and how AI-300 helps professionals secure evolving AI systems.

AI vs Traditional Penetration Testing: Tooling and Outcomes

Second part of the AI vs Traditional Pentesting series, focusing this time on tools and outcomes of both approaches.

Showing 1 - 12 of 483 entries

Join the OffSec community

Our community members connect, communicate, and collaborate on all things cybersecurity

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)