Daily Security Intel

Archives
Log in
Subscribe
August 22, 2026

[SecurityIntel] 22 Aug | GitLab CVE-2026-19478 Under Active Exploitation

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, August 22, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

GitLab CVE-2026-19478 Under Active Exploitation

CRITICAL

5

C2 IPs

78

OTX IOCs

31

ARTICLES

■ ANALYST TLDR

Active exploitation of GitLab's CVE-2026-19478 and a maximum-severity Entra ID vulnerability highlight a critical week for identity and code repository security. Meanwhile, supply chain attacks targeting Rust (`arrayref`) and npm packages (RedC2 4.0) demonstrate persistent threat actor focus on developer environments. Organizations must also address newly discovered evasion vectors, including Microsoft Defender driver abuse and AI safety guardrail bypasses.

■ CRITICAL STORIES

HIGH#1

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

Attackers are actively exploiting this CVSS 9.4 code injection vulnerability to execute unauthorized code, emphasizing the rapid weaponization cycle of SDLC vulnerabilities.

CRITICAL#2

Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

A maximum-severity vulnerability in Microsoft's primary identity platform could allow attackers to execute arbitrary code, requiring immediate verification of patch status.

HIGH#3

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Researchers demonstrated a BYOVD-style technique using Defender's signed boot-time remediation driver to perform arbitrary kernel-level operations, bypassing traditional security controls.

HIGH#4

Rust Supply Chain Attack Linked to North Korean Hackers

State-sponsored actors poisoned the `arrayref` package to fetch malicious payloads, showcasing the ongoing threat to software supply chains and CI/CD pipelines.

■ CVEs IDENTIFIED

CVE-2026-19478

GitLab — Code injection leading to remote code execution

Critical

[CVE-TBD]

Microsoft Entra ID — Remote code execution (CVSS 10.0)

Critical

[CVE-TBD]

TrueConf Server — Actively exploited remote code execution and privilege escalation

Critical

[CVE-TBD]

Cisco Crosswork and Secure Workload — Multiple vulnerabilities including five CVSS 10.0 flaws allowing remote compromise

Critical

■ THREAT ACTORS

North Korean Hackers

APT

Poisoned the `arrayref` Rust package to deliver malicious payloads

Black Spark

Hacktivist

Compromised Russian network monitoring firm Microolap and accessed EtherSensor

[Unknown Threat Actor]

Cybercrime

Distributed RedC2 4.0 Linux backdoor via trojanized npm packages

■ ATT&CK TTPs

T1195.002
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Seen in trojanized npm packages and poisoned Rust arrayref package
T1562.001
Impair Defenses: Disable or Modify Tools | Seen in weaponization of Microsoft Defender's boot-time driver to delete security software
T1566.002
Phishing: Spearphishing Link | Seen in Microsoft Teams phishing campaigns delivering SynkLoader
T1098
Account Manipulation | Seen in iAuthFlow V2 registering malicious passkeys for persistence
T1552
Unsecured Credentials | Seen in 9,300+ leaked AWS access keys left active
T1204.002
User Execution: Malicious File | Seen in trojanized calendar and streak npm utilities

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

GitLab — CVE-2026-19478 code injection vulnerability under active exploitation — THN

[P1 PATCH NOW]≤24h

Microsoft — Entra ID CVSS 10.0 Remote Code Execution vulnerability — BC

[P1 PATCH NOW]≤24h

Cisco — Crosswork and Secure Workload CVSS 10.0 vulnerabilities — THN

[P1 PATCH NOW]≤24h

TrueConf — TrueConf Server actively exploited vulnerabilities — BC

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch GitLab immediately to address CVE-2026-19478 to prevent active exploitation of the code injection vulnerability.
2[P1] Apply Microsoft's August 2026 security updates to remediate the CVSS 10.0 remote code execution vulnerability in Entra ID.
3[P1] Prioritize patching TrueConf Server installations to remediate the actively exploited vulnerabilities highlighted by CISA.
4[P1] Apply security updates for Cisco Crosswork and Secure Workload platforms to mitigate the five CVSS 10.0 vulnerabilities.
5[P2] Audit and rotate all active AWS access keys, specifically targeting the 9,300+ leaked keys identified as still active.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 21 Aug | Active Exploitation of Zimbra CVE-2026-73570 RCE Vulnerability
Powered by Buttondown, the easiest way to start and grow your newsletter.