A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
CSO Online 15.09.2026 00:52
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity.
CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single HTTP request. The path traversal flaw results from improper confinement and lack of authentication enforcement in GitLab’s repository commits API, the company reported.
Microsoft’s Patching
Schneier on Security 14.09.2026 11:03
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an …
Hackers Exploit Maximum Severity Flaw in GitLab
Infosecurity Magazine 14.09.2026 10:00
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
OpenAI Agent Swarm Hacks RubyGems Package Manager
Infosecurity Magazine 14.09.2026 08:50
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
Cyber-Attacken auf GitLab, ConnectWise ScreenConnect und JFrog Artifactory
Heise Security 14.09.2026 07:11
Die IT-Sicherheitsbehörde CISA warnt vor beobachteten Angriffen auf GitLab, ConnectWise ScreenConnect und JFrog Artifactory.
Sicherheitslücke in Klimaanlage: Midea Portasplit bekommt ein wichtiges Update
Golem 14.09.2026 06:23
Angreifer können die Klimaanlage Midea Portasplit ohne Anmeldung per Bluetooth steuern. Ein neues Firmware-Update korrigiert das. (Sicherheitslücke, Bluetooth)