SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, August 22, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY GitLab CVE-2026-19478 Under Active Exploitation | CRITICAL |
|
5 C2 IPs | 78 OTX IOCs | 31 ARTICLES |
|
■ ANALYST TLDR Active exploitation of GitLab's CVE-2026-19478 and a maximum-severity Entra ID vulnerability highlight a critical week for identity and code repository security. Meanwhile, supply chain attacks targeting Rust (`arrayref`) and npm packages (RedC2 4.0) demonstrate persistent threat actor focus on developer environments. Organizations must also address newly discovered evasion vectors, including Microsoft Defender driver abuse and AI safety guardrail bypasses. |
|
■ CRITICAL STORIES GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure Attackers are actively exploiting this CVSS 9.4 code injection vulnerability to execute unauthorized code, emphasizing the rapid weaponization cycle of SDLC vulnerabilities. |
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution A maximum-severity vulnerability in Microsoft's primary identity platform could allow attackers to execute arbitrary code, requiring immediate verification of patch status. |
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Researchers demonstrated a BYOVD-style technique using Defender's signed boot-time remediation driver to perform arbitrary kernel-level operations, bypassing traditional security controls. |
Rust Supply Chain Attack Linked to North Korean Hackers State-sponsored actors poisoned the `arrayref` package to fetch malicious payloads, showcasing the ongoing threat to software supply chains and CI/CD pipelines. |
|
■ CVEs IDENTIFIED CVE-2026-19478 GitLab — Code injection leading to remote code execution |
[CVE-TBD] Microsoft Entra ID — Remote code execution (CVSS 10.0) |
[CVE-TBD] TrueConf Server — Actively exploited remote code execution and privilege escalation |
[CVE-TBD] Cisco Crosswork and Secure Workload — Multiple vulnerabilities including five CVSS 10.0 flaws allowing remote compromise |
|
■ THREAT ACTORS Poisoned the `arrayref` Rust package to deliver malicious payloads |
Compromised Russian network monitoring firm Microolap and accessed EtherSensor |
[Unknown Threat Actor] | Cybercrime |
Distributed RedC2 4.0 Linux backdoor via trojanized npm packages |
|
|
|
■ ATT&CK TTPs | T1195.002 | | Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Seen in trojanized npm packages and poisoned Rust arrayref package |
| T1562.001 | | Impair Defenses: Disable or Modify Tools | Seen in weaponization of Microsoft Defender's boot-time driver to delete security software |
| T1566.002 | | Phishing: Spearphishing Link | Seen in Microsoft Teams phishing campaigns delivering SynkLoader |
| T1098 | | Account Manipulation | Seen in iAuthFlow V2 registering malicious passkeys for persistence |
| T1552 | | Unsecured Credentials | Seen in 9,300+ leaked AWS access keys left active |
| T1204.002 | | User Execution: Malicious File | Seen in trojanized calendar and streak npm utilities |
|
■ PATCH PRIORITY GitLab — CVE-2026-19478 code injection vulnerability under active exploitation — THN |
Microsoft — Entra ID CVSS 10.0 Remote Code Execution vulnerability — BC |
Cisco — Crosswork and Secure Workload CVSS 10.0 vulnerabilities — THN |
TrueConf — TrueConf Server actively exploited vulnerabilities — BC |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch GitLab immediately to address CVE-2026-19478 to prevent active exploitation of the code injection vulnerability. |
| 2 | [P1] Apply Microsoft's August 2026 security updates to remediate the CVSS 10.0 remote code execution vulnerability in Entra ID. |
| 3 | [P1] Prioritize patching TrueConf Server installations to remediate the actively exploited vulnerabilities highlighted by CISA. |
| 4 | [P1] Apply security updates for Cisco Crosswork and Secure Workload platforms to mitigate the five CVSS 10.0 vulnerabilities. |
| 5 | [P2] Audit and rotate all active AWS access keys, specifically targeting the 9,300+ leaked keys identified as still active. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |