Overview
- GitLab
- GitLab
Description
Statistics
- 9 Posts
- 7 Interactions
Fediverse
If you're using on-prem Gitlab then you need to patch for CVE-2026-19478. One of those situations where patching first and testing second is justified.
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
Las últimas 24 horas en seguridad informática revelan una grave falla en GitLab que permitía borrar proyectos públicos sin autenticación, vulnerabilidades críticas en sanitización web con DOMPurify, riesgos internos por accesos activos a exempleados, sofisticados ataques hardware en Windows 11 y soluciones SASE para proteger IA y redes. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:
🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 18/08/26 📆 |====
🔍 INVESTIGACIÓN DE VULNERABILIDADES EN IA
Únete a una comunidad activa en Discord dedicada a la investigación en seguridad aplicada a modelos de lenguaje (LLMs). Aquí se comparten técnicas avanzadas de bug bounty, red teaming y herramientas para escaneo automático, ideales para profesionales que buscan innovar en la protección contra amenazas basadas en inteligencia artificial. Descubre más sobre esta red especializada en seguridad IA 👉 https://djar.co/wxUdaF
⚠️ GRAVE FALLA EN GITLAB GRAPHQL PUEDE PERMITIR BORRADO DE PROYECTOS PÚBLICOS
GitLab ha parcheado la vulnerabilidad CVE-2026-19478, con una puntuación CVSS de 9.4, que exponía a proyectos públicos a modificaciones o eliminaciones sin necesidad de autenticación. Esta falla en su API GraphQL resalta la importancia crítica de mantener actualizadas las plataformas colaborativas para evitar interrupciones y pérdidas de información. Infórmate sobre esta alerta y cómo proteger tus proyectos 👉 https://djar.co/AbJK
🔐 PELIGRO DE CUENTAS ACTIVAS DE EXEMPLEADOS EN SEGURIDAD CORPORATIVA
El mantenimiento de accesos para exempleados representa un riesgo considerable: facilita fraudes, fugas de datos y ataques internos. Este problema común en empresas requiere procesos rigurosos de desactivación y auditoría constante para evitar brechas que comprometan información sensible. Aprende las mejores prácticas para mitigar esta amenaza interna 👉 https://djar.co/NqXQcu
☁️ CLOUD FLARE ONE: LA PLATAFORMA SASE PARA PROTEGER IA Y REDES
Cloudflare One ofrece una solución integral SASE (Secure Access Service Edge) que centraliza la seguridad y conectividad para equipos, agentes de inteligencia artificial e infraestructura. Su arquitectura de confianza cero facilita una adopción segura y eficiente en entornos híbridos y en la nube, clave para organizaciones que integran IA en sus operaciones. Conoce cómo esta plataforma puede fortalecer tu seguridad TI 👉 https://djar.co/0Wizt1
🛡️ VULNERABILIDAD EN DOMPURIFY PERMITE BYPASS EN SAFARI
Una falla en DOMPurify versión 3.2.6 y anteriores habilita un bypass de seguridad en navegadores Safari mediante el uso del elemento animateTransform de SMIL. DOMPurify es esencial para la sanitización de contenido en la web, por lo que esta vulnerabilidad puede abrir puertas a ataques XSS si no se parchea a tiempo. Descubre los detalles técnicos y recomendaciones para proteger tus aplicaciones 👉 https://djar.co/mLCdY
💻 SECUESTRO DE TABLAS IDT EN WINDOWS 11 MEDIANTE DATA ONLY GADGETS
Se ha demostrado que la técnica DOG (Data Only Gadgets) puede atacar la tabla IDT del procesador en Windows 11, una estructura crítica que controla la ejecución de instrucciones del CPU. Este avance en el secuestro de tablas del núcleo, que afecta mecanismos de seguridad como VBS, HVCI y kCET, subraya la constante evolución de las amenazas a nivel hardware y la necesidad de medidas avanzadas en defensa de sistemas operativos modernos. Profundiza en esta investigación y sus implicaciones 👉 https://djar.co/gRJVL
⚠️ CRITICAL: GitLab Patches Critical Code Injection Vulnerability
GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versions…
🤖 AI generated summary
Bluesky
Description
Statistics
- 4 Posts
- 11 Interactions
Fediverse
Apple aktualisiert allerhand 2026-08
Wer jetzt denkt "ja klar, Apples Flickentag (gestern, 17.8.) bringt die Updates", irrt. Zumindest ist das nur die halbe Wahrheit. Apple hat nämlich bereits am 6.8. Updates für die drei noch gepflegten Versionen von macOS veröffentlicht (Sonoma 14.8.9; Sequoia 15.7.9; Tahoe 26.6.1). Diese schließen die Sicherheitslücke CVE-2026-65400 in der Funktion Screen Sharing (Bildschirmfreigabe für Fernzugriff) von macOS. Die ursprünglich mit dem Risiko 7,1 (von 10) bewertete Lücke wurde gerade auf 9,8 hoch gestuft, da inzwischen ein Exploit öffentlich verfügbar ist und die Lücke aktiv für Angriffe ausgenutzt wird. ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/18/apple-aktualisiert-allerhand-2026-08/
#apple #browser #exploits #ios #macos #sicherheit #UnplugApple #UnplugTrump #webkit
Attackers are exploiting CVE-2026-65400, a critical macOS Screen Sharing auth bypass, to gain root access and deploy Monero miners on Macs with exposed port 5900.
⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
Overview
Description
Statistics
- 5 Posts
Fediverse
⚠️ CRITICAL: ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto min…
🤖 AI generated summary
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
🚨 C-SUITE ALERT: CISA has flagged CVE-2025-62593 (Ray-Project) for active exploitation. This critical RCE flaw requires immediate executive oversight. Read our board-ready risk assessment and compliance framework to secure your enterprise. Command the wire. 👇 Link below
https://thecybermind.co/k3rh
#CyberSecurity
Recent alerts include CISA adding a critical RCE flaw in Ray-Project Ray (CVE-2025-62593) to its KEV catalog (Aug 18). Heights Finance also reported a data breach impacting over 1.2 million customers. Globally, ransomware incidents remain high, with AI increasingly used in attacks. Geopolitically, US-Iran talks have stalled, intensifying Middle East tensions and affecting global shipping.
Overview
Description
Statistics
- 3 Posts
- 6 Interactions
Fediverse
Looks like CVE-2026-33824 was added to KEV. Keep in mind that this service isn't just for IPSec VPNs. It's also used with some Windows Firewall policies so check your internal systems for listeners, not just public-facing systems.
An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, which could enable remote code execution.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
🚨 NEW CISA KEV: CVE-2026-33824. Active RCE weaponization targeting Microsoft Internet Key Exchange (IKE) via double-free memory corruption. Unauthenticated access possible. Get the full T-Suite brief & custom CrowdStrike detection queries to secure your Precinct Hybrid architecture.
Link below 👇
https://thecybermind.co/jily
Overview
- wpmudev
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Description
Statistics
- 3 Posts
Fediverse
Critical WordPress Alert: Dissecting CVE-2026-15748 (Forminator RCE) & CVE-2026-15826 (UPB Auth Bypass)
CVE-2026-15748 enables critical Forminator RCE, while CVE-2026-15826 allows User Profile Builder authentication bypass. Learn how to detect and patch bothhttps://thecybersecguru.com/news/cve-2026-15748-forminator-rce-cve-2026-15826-user-profile-builder/
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
CISA added four exploited vulnerabilities to its KEV Catalog, hitting SharePoint, VMware vCenter, macOS, and Windows IKE. Patch by August 21.
Bluesky
Overview
- Microsoft
- Copilot Web
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
“Varonis Threat Labs uncovered another one-click vulnerability in #Microsoft #Copilot Personal dubbed #CoSnitch (critical, CVE-2026-24301), which quietly executes an attack chain that exfiltrates data from enterprises without obvious red flags.
What makes CoSnitch unique is how Copilot surfaced its own vulnerabilities, a method we are calling #MetaHacking. Our researchers didn't have to reverse-engineer the flaw. The #AI exposed the weakness during normal use, highlighting a meaningful shift in how #SecurityFlaws are found, and a preview of what's ahead as AI gets woven deeper into enterprise systems.”
#security / #CVE / #Varonis <https://www.varonis.com/blog/cosnitch> via ElReg <https://www.theregister.com/research/2026/08/18/copilot-tricked-into-telling-reseachers-how-to-hack-itself/5288857>
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
Overview
- Apache Software Foundation
- Apache HttpComponents Client
- org.apache.httpcomponents.client5:httpclient5
Description
Statistics
- 2 Posts