Related Threat Clusters
-
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this…
2 articles · Updated August 22, 2026 -
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
12 articles · Updated June 16, 2026 -
GitLab Issues Emergency Patches for Multiple Security Vulnerabilities
GitLab has released urgent security patches for versions 19.0.1, 18.11.4, and 18.10.7 to address seven vulnerabilities affecting both Community Edition (CE) and Enterprise Edition (EE). The flaws include access control…
2 articles · Updated May 30, 2026 -
Critical Vulnerabilities Discovered in GitLab Products
Multiple high-severity vulnerabilities have been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) products, affecting versions 12.10.0 to 19.0.1. The vulnerabilities, including CVE-2026-6552,…
25 articles · Updated June 16, 2026 -
Critical Gitea Vulnerability CVE-2026-60004 Actively Exploited
A critical vulnerability in Gitea, tracked as CVE-2026-60004, is being actively exploited by attackers, allowing unauthorized users to execute arbitrary shell commands on vulnerable servers. This flaw affects…
18 articles · Updated August 26, 2026 -
Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
227 articles · Updated April 30, 2026 -
Critical GitLab Gateway Flaw CVE-2026-1868 Allows RCE
GitLab has patched a critical vulnerability identified as CVE-2026-1868, which has a CVSS score of 9.9. This flaw affects the self-hosted AI Gateway, allowing remote code execution (RCE) through insecure templates.…
4 articles · Updated February 8, 2026
Recent Intelligence Reports
- Jetbrains Told Everyone To Patch It Didnt Patch Itself — thenewstack.io · September 6, 2026
- AI-powered ransomware has arrived: Cybercriminals can now launch attacks for less than ... — Digitaljournal · September 3, 2026
- Contagious Interview: Malware delivered through fake developer job interviews — www.microsoft.com · September 3, 2026
- Version Control DFIR: GitHub, GitLab, Bitbucket, and Azure DevOps Detection & Incident ... — Securityarsenal · August 28, 2026
- 2026 04 02 Incident Report Litellm Telnyx Supply Chain Attack — blog.pypi.org · August 28, 2026
- Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps — Wiz · August 27, 2026
- Hackers now exploit critical Gitea flaw in code injection attacks — Bleepingcomputer · August 26, 2026
- Hackers now exploit critical Gitea flaw in code injection attacks — Bleepingcomputer · August 26, 2026