Security
GitLab 10.0 Flaw Exploited as CISA Sets Patch Deadline
A maximum-severity GitLab bug is already being exploited to steal CI/CD secrets, while ShinyHunters dumps 594,701 Florida DMV files.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
GitLab CVE-2026-85706 Exploited After 10.0 Severity Score
Threat actors are exploiting CVE-2026-85706, a maximum-severity GitLab path traversal flaw disclosed and patched Sept. 10 that lets unauthenticated attackers read arbitrary files. GitLab rated it 10 out of 10; the bug stems from improper path confinement and missing authentication checks in the repository commits API. CISA added it to the Known Exploited Vulnerabilities catalog Friday and ordered federal agencies to patch or disable self-managed instances by today. watchTowr saw probes on its honeypots that escalated to full exploitation and exfiltration of config files, secrets and SSH configurations. Exploitation requires at least one public project. Customers should update to 19.3.2, 19.2.6 or 19.1.8, or remove public access. GitLab.com and Dedicated are unaffected.
Maximum Severity GitLab Flaw Puts Supply Chains at Risk →
HBO Max Reddit Account Hijacked for 108 ClickFix Ads
Hackers took over the verified u/hbomax Reddit account and ran 108 malicious advertisements over roughly 48 hours, pushing ClickFix attacks that infected Windows and macOS devices with information stealers. Hudson Rock and ADAMnetworks linked the campaign to an operation they call PasteSwitch, which distributes stealers, loaders, crypto clippers and fake wallet apps. Ads impersonated HBO Max and promoted fake AI tools, developer software and macOS utilities, pointing to domains including hbomaxx.app, codex-craft.com and code-desktop.com. Victims were told to paste commands into Terminal, PowerShell or Run; one macOS chain used Base64 and fetched setup.sh from ember-bridge.com. Payloads included MacSync, AMOS helper, Amatera Stealer and fake Ledger, Trezor and Exodus apps. Reddit paused the ads after a report; it is unclear how the account was accessed.
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads →
ShinyHunters Leaks 594,701 Files After Florida DMV Hack
ShinyHunters released a downloadable archive of more than half a million files Monday after hacking the Florida Department of Highway Safety and Motor Vehicles, following a failed ransom negotiation. The group announced the breach a week earlier with a photo of Jeffrey Epstein’s driving record, then threatened to publish everything unless Florida paid by Friday. The department confirmed a breach caused by a single Plant City Police Department user’s credentials improperly stored on a personal device. The cache contains 475,207 images and 119,494 HTML driving records from the DAVID database, plus passports dating to the 1990s, permanent resident cards, visas and IDs from countries including Canada, Venezuela, Cuba, Brazil, China and India. ShinyHunters has claimed breaches at PornHub and Vimeo.
Ransomware gang leaks more than half a million files after Florida DMV hack →
Colorado DNA Analyst Yvonne Woods Gets 10 Years
Yvonne „Missy” Woods, a former Colorado Bureau of Investigation forensic crime lab analyst, was sentenced Friday to 10 years in prison for felony cybercrime, first-degree perjury, attempting to influence a public servant and forgery. Woods worked at the CBI from January 1994 until November 2023, and problems with her work in homicide, sexual assault and robbery cases date back decades. Prosecutors said she intentionally omitted DNA samples from tests or reports, or retested samples to get desired results, and police allege she deleted evidence in more than 30 sexual assault cases involving women and children. At least one murder conviction was overturned. The CBI says it will spend more than $11 million to retest and reexamine cases tied to Woods.
Former Forensic Analyst Sentenced To 10 Years For DNA Manipulation →
NSA Plans First Major Restructuring in a Decade
The National Security Agency is set to undergo extensive internal restructuring, its first in at least a decade, creating five new organizations focused on artificial intelligence, China, cybersecurity, combat support and global intelligence. Each new organization will be led by a mission director. NSA Director Joshua Rudd said the goal is to better align the agency with current and future priorities. The report did not specify a timeline or staffing numbers for the overhaul.
National Security Agency plans major internal restructuring: report →