Exposed GitLab project email addresses let attackers push code
2026-09-24T19:23:22Z•5c31362084613b8ee796cc0cc7df225e0036f6fc08ab7870ee3bc6454b191404
CVE-2026-85102CVE-2026-87902Android malwareCheck Point Security GatewayClickFixFedRAMPGitLabGoogle CloudJetBrains TeamCityKubernetesPowerShellRoundcubeVPN securityVeloCloud OrchestratorWordPressactive exploitationbanking trojannetwork management systemspayment card theftprivilege escalationransomwareremote code executionvulnerability managementweb application securityweb skimmingzero-day
What happened
The feed reports multiple active or emerging cybersecurity threats, including exploitation of critical vulnerabilities in Roundcube, JetBrains TeamCity, Check Point Security Gateway (CVE-2026-85102), WordPress (CVE-2026-87902), and VeloCloud Orchestrator. It also covers ransomware activity, supply-chain and exposed GitLab project email risks, ClickFix PowerShell attacks, Android banking malware, large-scale payment-card skimming, cloud privilege escalation through Kubernetes Config Connector, and attacks against network management systems. Several items describe active exploitation and high-pב
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 5c31362084613b8ee796cc0cc7df225e0036f6fc08ab7870ee3bc6454b191404
- Enrichment time
- 2026-09-24T19:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.