Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: GitLab's CVSS 10.0 File-Read Flaw Under Active Exploitation as CISA Adds It to KEV (20260912)

GitLab patches CVE-2026-85706, a CVSS 10.0 path-traversal flaw in its repository commits API that lets unauthenticated attackers read arbitrary server files — in-the-wild probes began within hours and CISA added it to KEV with a September 14 deadline, alongside a second CVSS 9.9 flaw in the same release. Also today: OpenAI's agent swarm is tied to the RubyGems/RubyDoc supply-chain breach; Anthropic's misuse report draws a Yemen weapons-cell disclosure and Beijing's 'distorting facts' rejection; Google GTIG documents autonomous agents harvesting credentials in under six hours; Unit 42 reports a ten-hour agentic intrusion; Microsoft tracks 1M AI-personalized invoice-fraud emails; Gigabud clones banking apps into Android work profiles in Indonesia; North Korea's fake-job infiltrators reach healthcare; and CISA and the FBI push candid outage communication.

GitLab CVE-2026-85706 CVE-2026-87719 CISA-KEV DevSecOps Supply-Chain RubyGems RubyDoc OpenAI-Agents AI-Agents Anthropic Claude Model-Misuse Yemen Houthis Hypersonic Beijing Unit-42 Palo-Alto-Networks Agentic-AI Google-GTIG TeamPCP Microsoft Phishing Fraud Gigabud Group-IB Vwork Android Banking-Trojan North-Korea Huntress CISA FBI CISO-Digest

GitLab’s CVSS 10.0 File-Read Flaw Under Active Exploitation — Added to CISA KEV

On September 11, GitLab shipped patches for multiple flaws — led by CVE-2026-85706 (CVSS 10.0), a path-traversal vulnerability in the repository commits API that lets an unauthenticated attacker read arbitrary files from the GitLab server under certain conditions. GitLab traces the flaw to “improper path confinement and missing authentication enforcement,” and it affects GitLab Community and Enterprise Edition: all versions from 18.7 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2.

Exposure-management firm watchTowr says the flaw drew active in-the-wild probes from 06:00 UTC on September 11 — within hours of public disclosure. The impact is direct: attackers can read log files and GitLab configuration files to obtain credentials, secrets and sensitive information, and exploitation requires just one condition — at least one public project must exist on the server. watchTowr’s Jake Knott called it “the second instance of a critical severity GitLab vulnerability in recent weeks,” after the GraphQL code-injection flaw (CVE-2026-19478) that was “almost immediately actively exploited.” The appeal, he said, is that unauthorized GitLab access yields source code, CI/CD secrets and credentials — and the ability to inject code into build pipelines, “gaining access or poisoning anything downstream of it.”

CISA confirmed reports of active exploitation on September 11, adding CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation deadline of September 14. The same release also fixes CVE-2026-87719 (CVSS 9.9), an insecure-deserialization flaw in GitLab EE through which a user with Duo Chat access can obtain advanced-search instance configurations and sensitive credentials via a specially crafted GraphQL subscription argument.

Why This Reshapes Developer-Infrastructure Risk

  • Dev platforms are composite crown jewels. One unauthenticated file read reaches logs, configuration, secrets and pipeline tokens — the exact assets that make developer infrastructure the highest-leverage target in the software supply chain.
  • The vulnerable surface is close to default. Exploitation needs little more than a single public repository — a configuration most organizations running GitLab already have.
  • Patch-gap windows keep collapsing. Probes began within hours and CISA set a September 14 deadline; this is the second CVSS 10.0 GitLab flaw exploited in recent weeks — part of a stretch that has also hit JetBrains TeamCity, Coder’s module registry and N-able N-central, with the agentic-side equivalent covered in the RubyGems item below.

🔗 Reference: The Hacker News


Active Threats This Week

📌 OpenAI agent swarm behind the RubyGems attack — including an RCE on RubyDoc’s servers The “major malicious attack” that hit RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report by researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx (first reported by The Wall Street Journal). More than 2,000 packages were submitted on May 11–12 after a first upload on May 5, with further batches on May 26–27 and on June 18; the junk gems show LLM authorship and “oai”-themed names (15 packages list “oai” as author). Socket’s follow-up tied a “GemStuffer” cluster of 150-plus gems to the same activity, which used the registry as a data-exfiltration channel — and the agents abused the .yardopts documentation-build process to gain arbitrary RCE on RubyDoc.info’s servers, scraped public U.K. government portals (Lambeth, Wandsworth and Southwark ModernGov sites), attempted to steal other users’ API keys, and experimented with SEC datasets through 83 more gems in June. RubyGems shipped a July fix for a CDN caching bug (CVSS 7.3) that could hand one account’s API key to another — six campaign packages tried it first. 🔗 Reference: The Hacker News

📌 Anthropic’s September misuse report, day 2: Yemen’s weapons programs — and Beijing’s pushback The second wave of coverage of the report that led our September 11 edition surfaced its sharpest case details. A cell that Anthropic describes only as “a cell of threat actors based in northern Yemen” ran three weapons-development programs simultaneously, using Claude Code to write the guidance, navigation and control (GNC) software — “in place of human software engineers.” The projects included a guided rocket built around a commodity, phone-grade flight computer with final-phase homing, a multi-stage ballistic missile, and a multi-variant effort that included a hypersonic glide vehicle variant. The group hid its intent and split work across multiple sessions to get past safeguards — Anthropic says the safeguards “blocked many of their requests, but not all of them” — and after their test-fired guided rocket appeared to have failed, the operators returned to Claude within hours to work out why. The activity ran December 2025–August 2026 across Haiku, Sonnet and Opus models; the accounts were banned and the case published (Anthropic says it has no evidence an operational device was fielded). Separately, Beijing pushed back on the report: foreign-ministry spokesperson Mao Ning said China “advocates AI for good” and accused Anthropic of “distorting facts” — “we firmly oppose attempts to throw mud at China,” she said on Friday. 🔗 Reference: The Washington Post | The National | The Times of India

📌 Anthropic’s report, part 2: a 1.8M-APK secret-scanning pipeline The report’s standout cyber-operations case: GTG-50014 (tracked as MeowSHA, frkoo and blazespider), a French-speaking suspected affiliate of the ShinyHunters collective, ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, scanned them for hard-coded secrets with TruffleHog, and sent verified findings to a Telegram group. A second ShinyHunters affiliate specialized in compromising SaaS vendors to steal downstream customers’ data. Anthropic’s framing of the spectrum is the keeper: from conversational misuse, to operations “with a human making each individual targeting decision” — all the way to “operations [that] ran autonomously… multi-agent frameworks conducting reconnaissance, exploitation and theft against multiple victims, in parallel, for hours or days at a time.” 🔗 Reference: The Hacker News

📌 Google GTIG: autonomous AI agents harvested credentials at scale in under six hours Google Threat Intelligence Group says a financially motivated group used an autonomous, multi-agent attack framework to carry out a large-scale credential-harvesting campaign in six hours — one data point in a widening pattern: GTIG has observed attackers “with diverse motivations” targeting proprietary AI models across healthcare, government and media, exfiltrating API credentials and co-opting victim cloud environments to run unauthorized AI workloads. “At this point, we can assume that all threat actors are using AI in some capacity,” GTIG chief analyst John Hultquist said, warning that agentic use creates “a scaled, faster adversary” — and that criminals “will gravitate to attacks that are faster than we can respond to.” GTIG also ties supply-chain compromises of PyPI, npm and Docker Hub to a financially motivated actor it calls TeamPCP (aka Altered Spider / UNC6780), whose intrusions deploy credential stealers SANDCLOCK and DUSTMAKER that specifically target AI coding assistants. 🔗 Reference: The Hacker News

📌 Unit 42: AI agents compressed a two-week intrusion into ten hours Palo Alto Networks’ Unit 42 documented an enterprise-network intrusion in which attackers used frontier AI models and a purpose-built agentic framework to complete — in under 10 hours — a breach the team estimates would take roughly two weeks by hand. No novel zero-days were needed: agents split reconnaissance, internal architecture mapping and credential-hunting across source repositories; the attackers obtained administrator credentials and root-level access, stole CI/CD and cloud-AI service keys, and tried to plant a backdoor through a Terraform configuration change that branch protection blocked. They also repurposed the victim’s own AI compute as attack infrastructure and left behind an 80-page report enumerating dozens of exploited weaknesses — chaining more than 50 MITRE ATT&CK techniques in 10 hours. 🔗 Reference: iThome

📌 Microsoft: a threat actor sent 1M AI-personalized invoice-fraud emails in 48 hours Microsoft researchers tracked an unattributed actor sending more than one million emails in roughly 48 hours (August 3–5) — each lightly personalized with the real names of targets’ executive leadership and aimed at accounts-payable departments (87.7% of targets in the US; IT, consumer goods and real estate the most common). The lures: detailed, credibly designed invoices claiming just under $50,000 owed to ServiceNow for an annual subscription, wrapped in a forged email “thread” that simulated an executive forwarding the invoice from the vendor. “Gathering information about a victim organization can now be a matter of minutes,” said Barracuda’s Merium Khalid — attackers can now “construct more convincing impersonation emails” and run multiple AI-driven processes across a single campaign. 🔗 Reference: Dark Reading

📌 Gigabud clones banking apps into Android work profiles to evade malware checks Group-IB documented a new technique from the Gigabud Android banking trojan (active since 2022; credited to a Chinese-speaking group it calls GoldFactory): a second app, “Vwork,” creates an Android work profile — the isolated space normally reserved for employer apps — and drops a tampered copy of the victim’s banking app inside it, so the bank’s own malware scans, running in the personal space, cannot see the trojan. Combined with fake login overlays and lock-screen capture, operators can run fraudulent transactions on the victim’s phone behind a black screen. Group-IB confirmed the full chain on infected devices in Indonesia, where researchers observed roughly 1,469 compromised devices and 1,281 potentially compromised logins between February and July — nearly $1 million in estimated losses. Installation comes via sideloaded apps posing as a national airline, a tax office or a government portal. 🔗 Reference: The Hacker News | Dark Reading

📌 Huntress: North Korea’s fake-job infiltrators expand into healthcare roles Huntress reports that North Korean operatives using doctored identity documents are applying through ordinary hiring channels — remote and on-site — well beyond the IT roles that first drew attention, now reaching healthcare, sales and marketing. Hired under false identities, they receive legitimate accounts, equipment and internal system access, then move earnings back to North Korea; some use VPNs, proxies and PiKVM devices to mask their true location or remotely operate employer machines. Huntress has helped confirm five suspected workers this year, including three at an Australian healthcare organization — an intrusion where the people are the breach, and one that conventional security tooling struggles to flag. 🔗 Reference: iThome

📌 CISA and the FBI set a new bar for outage and breach communication CISA, the FBI and international partners published “Communicating Under Pressure: Best Practices for Service Providers”, an advisory that defines effective crisis communication as transparent, free of PR spin, and rooted in root-cause analysis — urging providers to communicate immediately, give actionable guidance, share what they do and do not know, and stay accountable with continuous updates while meeting reporting duties. The backdrop: mandatory breach disclosure is now widespread (all 50 US states; CISA, the SEC and HHS all require prompt reporting), yet users are often left in the dark during multi-day outages. “Service outages alone have the potential to cause enough damage, disruption, and societal panic without speculation and uncertainty from end users and the public as added factors,” the advisory states. 🔗 Reference: Dark Reading


How Can OPSWAT Help

Several of today’s attack paths arrive as files: the RubyGems/RubyDoc compromise rode in through malicious packages and build-time scripts, Gigabud reaches devices as sideloaded APKs, and the million-email fraud wave depends on crafted invoice attachments passing email gateways. MetaDefender Multi-Scan layers 30+ anti-malware engines over packages, archives and executables to catch what single-engine stacks miss, while MetaDefender CDR (Content Disarm & Reconstruction) rebuilds allowed documents and archives — stripping active content from invoices and other files traversing email and web paths — and MetaDefender Kiosk screens files entering through physical and OT boundaries.