GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user data. “GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.” reads the advisory. GitLab issued an emergency patch on August 17, five days after its regular update. The vulnerability impacts only self-managed installations, users should upgrade to versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. There’s a gap worth flagging for anyone still sitting on an older release. The available patches don’t cover the 18.2 through 18.10 branches, even though those versions technically fall inside the affected range. If you’re running anything in that window, staying put isn’t really an option; you’ll need to upgrade to a patched branch entirely rather than waiting for a fix that isn’t coming for your current one. hiimguardian reported the flaw through the company HackerOne bug bounty program. A second, less severe issue shipped in the same release. CVE-2026-19650 (CVSS score of 7.1), involves a cross-site request forgery weakness in how GitLab’s GraphQL handles multiplex queries, letting an unauthenticated attacker trigger mutations through GET requests due to improper validation. Unlike the critical flaw, this one needs a victim to actually interact with something, so it’s a real risk but a considerably narrower one. There’s no evidence either bug has been exploited in the wild yet, and no public proof-of-concept code has surfaced as of publication. That’s the good news. The less comforting part is GitLab’s own disclosure policy: full technical details typically go public on the company’s issue tracker 90 days after the patching release, which puts a working understanding of exactly how this bug functions squarely in mid-November, plenty of time for someone motivated enough to reverse-engineer the patch diff themselves before then. This is not the first serious GitLab issue in recent months. Last month, researchers released working exploit code for another remote-code-execution flaw affecting self-managed servers. Organizations running GitLab on their own infrastructure should therefore treat this patch as a priority, especially given the critical severity and the fact that the vulnerability requires no authentication or user interaction. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, GitLab)
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026, including names, addresses, email addresses, phone numbers and order details. “Recently, the team identified an authorization flaw in the order-tracking function for a plug-in associated with customer order information. Under certain conditions, the flaw allowed unauthorized access to another customer’s order information.” reads the notice published by the company. “We are extremely sorry to inform the community that order information for customers who placed orders between March 2, 2025 and April 11, 2026. Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw. The affected data involves approximately 39,798 customers.” SafePal is a Singapore-based company focused on cryptocurrency security. It develops hardware and software wallets that let users securely store and manage digital assets. Its products include hardware wallets, a mobile app and browser-based tools supporting multiple blockchains and cryptocurrencies. The disclosure came as a threat actor began advertising the stolen data on a cybercrime forum, claiming the same number of affected customers. SafePal confirmed the security breach incident, while warning users about the exposure of their personal and order-related information. The company said all affected customers were notified individually by email on August 16 and urged them to check their status. The exposed order data could enable more convincing phishing attempts, including fake support calls, emails, refund offers, firmware updates or malicious websites designed to steal additional information. SafePal stressed that seed phrases, private keys and wallet passwords were not exposed, so customers do not need to move their assets solely because of the breach. However, anyone who has shared a seed phrase or private key with an attacker should consider the wallet compromised, create a new one using a trusted device or official app, and immediately transfer the remaining funds. The crypto firm said the breach did not expose seed phrases, private keys, wallet passwords or other wallet credentials. Bank details, payment card numbers and government IDs were also not involved. The company pointed out it does not collect or store such information and found no evidence that the incident compromised access to customer wallets or funds. “However, if you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised.” continyes the notice. “Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately. Lastly, contact SafePal through our official support channel.” SafePal said it has fixed the vulnerability and added further security measures, with an independent security firm reviewing the fix and order-processing systems. The company also reduced data retention to 90 days, contacted affected customers and logistics partners, and opened a dedicated support channel. The firm identified more than 30 fraudulent websites and phishing links and removed them. It will continue monitoring scams, investigating potential risks and sharing updates through its official channels. SafePal urges customers who suffered financial losses linked to the breach to contact the company, which is working with specialists to trace stolen on-chain assets. “For more FAQs and details, we will keep updating the dedicated webpage for this incident.” concludes the notice. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, SafePal)
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. The incident began on August 16, 2026, at around 21:58 UTC, and is affecting Claude.ai, Claude Code, and Claude Cowork. According to Anthropic’s status page, the company first said it was investigating an issue preventing some users from authenticating to Claude.ai, Claude Code, and Claude Cowork. A few minutes later, Anthropic reported a broader service disruption involving degraded performance on Claude.ai and platform.claude.com. For users, the outage can result in problems signing in, Claude failing to load, requests not completing, or other errors when using the affected services. Anthropic’s status page currently classifies Claude.ai, Claude Code, and Claude Cowork as experiencing a major outage. Claude Console and the Claude API are currently listed as operational.
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes that an operator already has code execution on the Windows host and does not involve
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control
Confirm this action.
Leaving now will discard your changes.