GitLab has pushed an urgent set of security updates after disclosing a critical vulnerability in its AI Gateway that could allow authenticated users to run arbitrary commands on the gateway. Tracked as CVE-2026-90970 and rated CVSS 9.9, the flaw affects self-hosted AI Gateway deployments that support GitLab Duo AI features. While GitLab’s hosted gateways have already been patched, organizations running
Category: Cybersecurity
Zero-Day, APT, Exfiltration, Lateral-Movement, Privilege-Escalation, Botnet, Rootkit, Backdoor, Keylogger, Smishing, Vishing, Spear-Phishing, Social-Engineering, MITM, SQL-Injection, XSS, CSRF, Path-Traversal, Buffer-Overflow, Honeypot, CVE, CVSS, Red-Team, Blue-Team, Threat-Hunting, Malware-Analysis, MITRE-ATT&CK, Insider-Threat, Jailbreak, Shellcode, Exploit-Kit, LFI, RFI, Obfuscation, Payload, security advisory, vulnerability disclosure, CWE, OWASP, cybersecurity news, threat intelligence, SOC, SIEM, cryptotheft, evasion, CVE Security
Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know
Citrix released emergency builds to address two actively exploited zero-day vulnerabilities in NetScaler appliances, but some organizations report that the patched appliances are repeatedly rebooting. What began as a rapid mitigation effort to stop remote command execution and DTLS-related attacks has morphed into an availability problem for some deployments—raising the difficult question defenders must balance: is this an operational outage
Debian Patches 1,313 Kernel Flaws: What Administrators Need to Know
Debian has just released a major kernel security update that aggregates fixes for 1,313 CVE entries, a headline figure that has drawn attention across the Linux community. The update — published as DSA-6528-1 and delivered for the Trixie stable release as Linux source package 6.12.111-1 — addresses a range of vulnerabilities that could, in different contexts, lead to privilege escalation,
Antino: A Stealthy Backdoor That Hides in Outlook and OneDrive
A new espionage campaign tracked by Cisco Talos has exposed a sophisticated Windows backdoor, nicknamed Antino, that uses Microsoft 365 services as its covert communications channel. Targeting government and policy organizations across Asia — including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar — the activity centers on highly tailored spear‑phishing lures and a multi-stage infection chain that culminates
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Microsoft’s SharePoint platform is facing active exploitation following the public release of a proof-of-concept (PoC) for a critical authentication bypass vulnerability tracked as CVE-2026-55040. Patched in July’s Patch Tuesday, the flaw allows unauthenticated actors to impersonate SharePoint users by forging JSON Web Tokens (JWTs). Since the PoC surfaced, security researchers and telemetry providers have observed real-world attempts that underscore the
Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor
Akira’s latest tactics expand the ransomware playbook: instead of relying solely on kernel drivers or signed binaries to disable protections, an affiliate in a recent intrusion rebooted a compromised host into Safe Mode with Networking to silence endpoint defenses while keeping network access for remote control and exfiltration. The operation began with a successful credential-spraying attack against an exposed SonicWall





