Defendwork Critical RCE Vulnerabilities in GitLab and Dell; Warlock Ransomware Targets SharePoint
Article Content
- •GitLab and Dell released critical patches for RCE vulnerabilities on October 3, 2026.
- •Warlock ransomware is exploiting SharePoint vulnerabilities against critical infrastructure.
- •Immediate patching is essential to prevent unauthorized access and exploitation.
GitLab and Dell released critical patches for remote code execution vulnerabilities on October 3, 2026. GitLab's AI Gateway vulnerability (CVE-2026-90970) allows arbitrary command execution on self-hosted instances, with a CVSS score of 9.9. Dell's Container Storage Modules have critical flaws (CVSS 10.0) enabling unauthenticated root access on Kubernetes nodes. Both companies urge immediate patching to prevent exploitation. Additionally, the Warlock ransomware group is actively exploiting SharePoint vulnerabilities to target water utilities, telecom operators, and government bodies. A China-linked threat actor has deployed the Antino backdoor via Outlook and OneDrive against government organizations in Asia. Organizations are advised to audit their systems for unauthorized access and apply the latest patches promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Warlock, Antino and Dell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected by the GitLab vulnerability?
What is the CVSS score for the Dell vulnerabilities?
How can organizations protect themselves?
Continue Reading
Warlock Ransomware Targets Critical Infrastructure in Spanish and Portuguese Regions The Warlock ransomware group, tracked as Longlegs or Storm-2603, has targeted critical infrastructure in Portuguese- and Spanish-speaking countries, including a water utility, a telecommunications provider, a regional government body, and an university. Recent attacks exploited vulnerabilities in Microsoft SharePoint…
Warlock Ransomware Exploits SharePoint Vulnerabilities Warlock ransomware has been reported to exploit vulnerabilities in Microsoft SharePoint to breach networks. The ransomware targets organizations using SharePoint, leveraging flaws to gain unauthorized access. Specific CVEs related to these vulnerabilities have not been disclosed in the articles. The scope of the…