[SecurityIntel] 22 Aug | GitLab CVE-2026-19478 Under Active Exploitation
SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Saturday, August 22, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY GitLab CVE-2026-19478 Under Active Exploitation CRITICAL 5 C2 IPs 78 OTX IOCs 31 ARTICLES ■ ANALYST TLDR Active exploitation of GitLab's CVE-2026-19478 and a maximum-severity Entra ID vulnerability highlight a critical week for identity and code repository security. Meanwhile, supply chain attacks targeting Rust (`arrayref`) and npm packages (RedC2 4.0) demonstrate persistent threat actor focus on developer environments. Organizations must also address newly discovered evasion vectors, including Microsoft Defender driver abuse and AI safety guardrail bypasses. ■ CRITICAL STORIES HIGH #1 GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure Attackers are actively exploiting this CVSS 9.4 code injection vulnerability to execute unauthorized code, emphasizing the rapid weaponization cycle of SDLC vulnerabilities. CRITICAL #2 Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution A maximum-severity vulnerability in Microsoft's primary identity platform could allow attackers to execute arbitrary code, requiring immediate verification of patch status. HIGH #3 Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Researchers demonstrated a BYOVD-style technique using Defender's signed boot-time remediation driver to perform arbitrary kernel-level operations, bypassing traditional security controls. HIGH #4 Rust Supply Chain Attack Linked to North Korean Hackers State- actors poisoned the `arrayref` package to fetch malicious payloads, showcasing the ongoing threat to software supply chains and CI/CD pipelines. ■ CVEs IDENTIFIED CVE-2026-19478 GitLab — Code injection leading to remote code execution Critical [CVE-TBD] Microsoft Entra ID — Remote code execution (CVSS 10.0) Critical [CVE-TBD] TrueConf Server — Actively exploited remote code execution and privilege escalation Critical [CVE-TBD] Cisco Crosswork and Secure Workload — Multiple vulnerabilities including five CVSS 10.0 flaws allowing remote compromise Critical ■ THREAT ACTORS North Korean Hackers APT Poisoned the `arrayref` Rust package to deliver malicious payloads Black Spark Hacktivist Compromised Russian network monitoring firm Microolap and accessed EtherSensor [Unknown Threat Actor] Cybercrime Distributed RedC2 4.0 Linux backdoor via trojanized npm packages ■ ATT&CK TTPs T1195.002 Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Seen in trojanized npm packages and poisoned Rust arrayref package T1562.001 Impair Defenses: Disable or Modify Tools | Seen in weaponization of Microsoft Defender's boot-time driver to delete security software T1566.002 Phishing: Spearphishing Link | Seen in Microsoft Teams phishing campaigns delivering SynkLoader T1098 Account Manipulation | Seen in iAuthFlow V2 registering malicious passkeys for persistence T1552 Unsecured Credentials | Seen in 9,300+ leaked AWS access keys left active T1204.002 User Execution: Malicious File | Seen in trojanized calendar and streak npm utilities ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h GitLab — CVE-2026-19478 code injection vulnerability under active exploitation — THN [P1 PATCH NOW] ≤24h Microsoft — Entra ID CVSS 10.0 Remote Code Execution vulnerability — BC [P1 PATCH NOW] ≤24h Cisco — Crosswork and Secure Workload CVSS 10.0 vulnerabilities — THN [P1 PATCH NOW] ≤24h TrueConf — TrueConf Server actively exploited vulnerabilities — BC ■ RECOMMENDED ACTIONS TODAY 1 [P1] Patch GitLab immediately to address CVE-2026-19478 to prevent active exploitation of the code injection vulnerability. 2 [P1] Apply Microsoft's August 2026 security updates to remediate the CVSS 10.0 remote code execution vulnerability in Entra ID. 3 [P1] Prioritize patching TrueConf Server installations to remediate the actively exploited vulnerabilities highlighted by CISA. 4 [P1] Apply security updates for Cisco Crosswork and Secure Workload platforms to mitigate the five CVSS 10.0 vulnerabilities. 5 [P2] Audit and rotate all active AWS access keys, specifically targeting the 9,300+ leaked keys identified as still active. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
SECURITYINTEL DAILY BRIEF
Saturday, August 22, 2026
INTEL CONFIDENCE 100%
GitLab CVE-2026-19478 Under Active Exploitation
Active exploitation of GitLab's CVE-2026-19478 and a maximum-severity Entra ID vulnerability highlight a critical week for identity and code repository security. Meanwhile, supply chain attacks targeting Rust (`arrayref`) and npm packages (RedC2 4.0) demonstrate persistent threat actor focus on developer environments. Organizations must also address newly discovered evasion vectors, including Microsoft Defender driver abuse and AI safety guardrail bypasses.
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
Attackers are actively exploiting this CVSS 9.4 code injection vulnerability to execute unauthorized code, emphasizing the rapid weaponization cycle of SDLC vulnerabilities.
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
A maximum-severity vulnerability in Microsoft's primary identity platform could allow attackers to execute arbitrary code, requiring immediate verification of patch status.
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Researchers demonstrated a BYOVD-style technique using Defender's signed boot-time remediation driver to perform arbitrary kernel-level operations, bypassing traditional security controls.
Rust Supply Chain Attack Linked to North Korean Hackers
State- actors poisoned the `arrayref` package to fetch malicious payloads, showcasing the ongoing threat to software supply chains and CI/CD pipelines.
GitLab — Code injection leading to remote code execution
Microsoft Entra ID — Remote code execution (CVSS 10.0)
TrueConf Server — Actively exploited remote code execution and privilege escalation
Cisco Crosswork and Secure Workload — Multiple vulnerabilities including five CVSS 10.0 flaws allowing remote compromise
Poisoned the `arrayref` Rust package to deliver malicious payloads
Compromised Russian network monitoring firm Microolap and accessed EtherSensor
[Unknown Threat Actor]
Distributed RedC2 4.0 Linux backdoor via trojanized npm packages
GitLab — CVE-2026-19478 code injection vulnerability under active exploitation — THN
Microsoft — Entra ID CVSS 10.0 Remote Code Execution vulnerability — BC
Cisco — Crosswork and Secure Workload CVSS 10.0 vulnerabilities — THN
TrueConf — TrueConf Server actively exploited vulnerabilities — BC
■ RECOMMENDED ACTIONS TODAY
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5
FULL IOC EXPORT — GOOGLE SHEET
All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
