Start your day with intelligence. Get The OODA Daily Pulse.
GitLab flaw exploited within days of disclosure.
A critical GitLab code injection bug began seeing exploitation roughly two days after it was disclosed, allowing unauthenticated attackers to modify or delete public projects through a GraphQL directive. GitLab patched the issue on August 17 across multiple CE and EE versions, and WatchTowr confirmed both easy reproducibility and early in‑the‑wild probing via its honeypots. The vulnerability enables attackers to rewrite repository state, forge merge records, or ban maintainers with a single request, creating significant supply chain risks. Researchers warn that AI‑assisted exploit development is shrinking patch windows and making rapid updates essential.
Read more:
https://www.securityweek.com/critical-gitlab-flaw-exploited-shortly-after-disclosure/