GraphQL — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
January 12, 2026
Last Seen
August 18, 2026

Related Threat Clusters

  • Critical GitLab Vulnerability Allows Unauthenticated Data Deletion

    GitLab released an emergency patch on August 17, 2026, for a critical vulnerability tracked as CVE-2026-19478. This flaw allows unauthenticated attackers to remotely modify or delete public projects and user data…

    30 articles · Updated August 18, 2026
  • Malicious LLM Proxy Routers Compromise AI Security

    A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…

    2 articles · Updated April 15, 2026
  • GhostJacking: New Attack Exploits AI Agents to Bypass Security Controls

    Researchers from Tenet Security revealed a new attack method named 'GhostJacking' at DEF CON 34, which exploits AI agents' trusted access to manipulate infrastructure. This attack can reroute web and email traffic,…

    5 articles · Updated August 11, 2026
  • Mandiant Releases AuraInspector Tool for Salesforce Access Control Auditing

    Mandiant has launched AuraInspector, an open-source command line tool aimed at identifying access control misconfigurations in Salesforce environments. The tool automates the detection of configuration errors that have…

    2 articles · Updated January 13, 2026
  • UStrive Fixes Data Vulnerability Exposing User Information

    UStrive, an online mentoring platform, has addressed a security vulnerability that exposed personal information of its users, including minors. The compromised data included full names, email addresses, phone numbers,…

    2 articles · Updated January 20, 2026
  • Moltbook's Security Flaw Exposes AI-Only Social Network Risks

    Moltbook, an AI-driven social network launched in late January 2026, allows AI agents to interact without human oversight. Shortly after its debut, security researchers identified a critical vulnerability that…

    16 articles · Updated February 1, 2026

Recent Intelligence Reports

  • Critical code injection vulnerability in GitLab CE/EE with available proof-of-concept, Patch ... — Ccb.Belgium.Be · August 18, 2026
  • Critical GitLab Zero — Darkreading · August 18, 2026
  • Critical GitLab flaw allows attackers to delete and modify public repos — Csoonline · August 18, 2026
  • GitLab Emergency Patch: Third GraphQL Flaw of 2026 Lets Unauthenticated Attackers ... — Techtimes · August 18, 2026
  • GitLab Official Patch Release Notes — docs.gitlab.com · August 18, 2026
  • GitLab Patches Multiple Security Flaws in CE and EE With 19.2.4 Update — Gbhackers · August 18, 2026
  • 'GhostJacking' attack turns error logs into indirect prompt injections | news — Scworld · August 11, 2026
  • How We Hacked Bains Competitive Intelligence Platform — codewall.ai · April 15, 2026

CVSS v3.1 Breakdown