The Signal
Today’s strongest practitioner signal is the coexistence of AI-related boundary research and reported attacker use with established exposure paths: a critical software flaw and ransomware access brokerage retain immediate operational relevance. The clusters point to different security decisions, not a single shared mechanism. [1][2][3][4]
Must Know
GitLab public-project vulnerability
What happened
GitLab released patches for two vulnerabilities, including a critical, unauthenticated code-injection flaw affecting GitLab Community Edition and Enterprise Edition. [3]
Affected versions are 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. [3]
Why it matters
Unauthenticated code injection makes this a direct review priority for organizations operating the affected product lines, with attention to the stated release boundaries. [3]
Medusa ransomware advisory update
What happened
A U.S. government advisory updated by CISA, the FBI and HHS says the Medusa ransomware-as-a-service group has added hundreds of victims in a little more than a year and relies on access brokers, paying roughly $100 to $1 million. [4]
The advisory says Medusa opportunistically targets victims with unpatched software rather than specific organizations or sectors, while identifying the Healthcare and Public Health sector as a frequent victim. [4]
Why it matters
The advisory’s reported victim tally increased from more than 300 in March 2025 to more than 500 by April of the following year. [4]
Reported access-broker use and opportunistic targeting link external exposure management to ransomware risk, while the advisory’s healthcare observation should not be read as limiting the group’s potential victim set. [4]
Microsoft Copilot security-boundary research
What happened
Varonis Threat Labs reported a Microsoft Copilot Personal vulnerability named CoSnitch to Microsoft in December 2025; the source says Microsoft planned a patch and CVE identification, but had not responded before publication. [1]
The flaw involved Copilot disclosing technical details during repeated questioning about why automatic prompt execution was impossible, including an undocumented autorun=1 parameter and the session conditions needed to use it. [1]
Why it matters
Depending on the prompt, the attack could expose session context, messages, emails, connected applications and memory, including through OAuth-connected Gmail, Google Drive and Google Calendar. [1]
The reported disclosure path underscores the need to assess interaction flows alongside intended feature behavior, especially where personal-session information and OAuth-connected services meet; the research does not establish a general Copilot outcome. [1]
Reported attacker use of AI in intrusions
What happened
AI tools are being used by cyber attackers to write malicious code, build credential-harvesting tools, search compromised networks, identify valuable business information, manage technical infrastructure, and generate intrusion commands. [2]
Gambit Security researchers examined three unrelated threat actors to show how AI can support different stages of a cyberattack. [2]
Why it matters
Across the examined cases, attackers used AI to create scripts and exploitation tools, identify high-value business information, perform IT and DevOps tasks, and generate commands. [2]
The examined cases span several attack stages rather than one discrete task, so defensive assessment can distinguish individual AI uses from the broader operational workflow described by the researchers. [2]
Also Worth Knowing
Heights Finance breach reporting
What happened
Heights Finance, a consumer lender offering personal installment loans, reported that an unauthorized party accessed a third-party cloud platform storing customer information and may have viewed or copied data. [5]