GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.

The gateway is the service that connects a GitLab instance to AI mo… Continue reading GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers→

Posted in Uncategorized

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.

The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Paki… Continue reading Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign→

Posted in Uncategorized

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.

The vulnerabilities are listed below –

CVE-2026-63688 (C… Continue reading Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes→

Posted in Uncategorized

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported.

“We have parted ways with three individuals for violating our policies on accessing … Continue reading OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling→

Posted in Uncategorized

Why CISOs Struggle to Answer the Board’s Three Hardest Questions, and How to Fix the Report

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone… Continue reading Why CISOs Struggle to Answer the Board’s Three Hardest Questions, and How to Fix the Report→

Posted in Uncategorized

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android’s accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.

With malicious Android applications abusing the API serv… Continue reading Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools→

Posted in Uncategorized

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerabilit… Continue reading Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes→

Posted in Uncategorized

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid.

The 16-year-old was… Continue reading Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers→

Posted in Uncategorized

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A pub… Continue reading ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories→

Posted in Uncategorized

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again.

The backdoor has been codename… Continue reading WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory→

Posted in Uncategorized