GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has patched a maximum-severity path traversal vulnerability that can allow unauthenticated attackers to read arbitrary files from vulnerable GitLab servers.
Every report filed under this tag.
GitLab has patched a maximum-severity path traversal vulnerability that can allow unauthenticated attackers to read arbitrary files from vulnerable GitLab servers.
Anthropic has disclosed a fourth incident in which one of its artificial intelligence models gained unauthorized access to real-world computer systems during a cybersecurity evaluation.
cPanel has patched a security vulnerability that could allow an authenticated hosting account with mail-related privileges to take complete control of the underlying server.
Security researchers have uncovered a sophisticated malware implant targeting F5 BIG-IP Access Policy Manager (APM) appliances that can conceal a PHP web shell entirely within Apache process memory, allowing attackers to maintain server-side code execution while leaving the targeted PHP files on disk unchanged.
A sophisticated malware strain known as JSCeal is using stolen browser session cookies to potentially bypass Google authentication and gain unauthorized access to accounts without requiring the victim’s password or a fresh authentication challenge.
One brief each morning: the advisories that matter, the noise removed.
Double opt-in. One-click unsubscribe in every email. We never sell addresses.