A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

2026-09-23T19:24:00Z•4a26f9d6ea83fc66b2021515d2ddccce1d0f8a345e4d18c3056501417a8ed7f3
CVE-2026-65660CVE-2026-67279CVE-2026-80521CVE-2026-85046CVE-2026-85880CVE-2026-86060CVE-2026-87491CVE-2026-89775CVE-2026-90898CVE-2026-93616CVE-2026-93952CVE-2026-94127AI-securityChromeF5-BIG-IPLinuxMikroTikNext.jsPyPISharePointWindowsWordPressactive-exploitationcontainer-escapecredential-stealermalwarenpmphishingprivilege-escalationransomwareremote-code-executionsupply-chain-securityvirtualization-escapevulnerabilityzero-day

What happened

Security news feed covering multiple high-impact vulnerabilities, active exploitation campaigns, malware and malicious package supply-chain incidents. Notable threats include unauthenticated remote code execution in F5 BIG-IP APM, Bifrost, Check Point, WordPress and Next.js; router, virtualization and container escapes; Chrome-Windows zero-day exploitation; credential-stealing packages and malware; phishing services; and compromise claims involving the FBI.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4a26f9d6ea83fc66b2021515d2ddccce1d0f8a345e4d18c3056501417a8ed7f3
Enrichment time
2026-09-23T19:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You · Baitaphish