View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

GitLab Issues Emergency Patch for Critical GraphQL Code-Injection Flaw

🚨 ACTIVE EXPLOITATION

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • BTMob Fraud Platform Uses 1,402 Servers for Android Device Takeovers
    BTMob is powering Android device-takeover campaigns through a fraud-as-a-service platform.

    • Android users, banks, and mobile providers are affected by BTMob campaigns.
    • BTMob enables screen monitoring, information theft, account theft, and unauthorized transfers.
    • Attackers use fake apps, cloned download pages, WhatsApp messages, and social-engineering calls to deliver sideloaded APKs.
    • The platform includes a dropper, desktop control panel, backend, reseller system, and automated APK builder.
    • Researchers found 1,402 hosts on port 3000; observed indicators include lnat-tv-pro.apk, btmobrat[.]net, and 77[.]111[.]101[.]24.
      πŸ“„ Source: blog.quimerax.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News, cryptika.com (discovered)
  • Projextor Hides Malware in Trojanized Electron Productivity Apps
    Projextor embeds malware in working Electron-based productivity applications.

    • Users downloading free document converters, PDF tools, meal planners and recipe apps are affected.
    • Trojanized apps include FlipFormat, PDFGrip, FoodFormula and KitchenCanvas.
    • The malware can execute JavaScript, run remote commands and capture screens.
    • NSIS, Squirrel and Inno Setup installers download Electron apps from impersonation websites.
    • Associated domains include flipformatpdf.com, pdfgrip.com, meal-formula.com, kitchen-canvas.com and doceditorinc.com.
      πŸ“„ Source: blog.gdatasoftware.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Cloudflare Tracks RFC 9234 BGP Role Adoption and OTC Stripping
    Cloudflare found two Tier 1 networks stripping RFC 9234’s OTC attribute.

    • BGP operators and Internet transit networks are affected.
    • RFC 9234’s BGP Roles and Only to Customer (OTC) attribute help routers reject route leaks.
    • Cloudflare measured RFC 9234 deployment across networks.
    • Two Tier 1 networks were unexpectedly observed stripping the OTC attribute.
      πŸ“Ž Coverage: blog.cloudflare.com Β· πŸ‘ via Cloudflare Blog
  • Proton’s Lumo Analyzes Exported AI Chats for Privacy Exposure
    Proton launched AI Paper Trail to analyze exported ChatGPT and Claude histories with Lumo.

    • ChatGPT and Claude users can upload exported conversation histories to Proton’s AI Paper Trail.
    • The tool generates a privacy type, AI Exposure Score, and profile of exposed identity, habits, relationships, and interests.
    • Lumo analyzes the uploaded files and estimates the data’s value to an AI provider.
    • Proton says uploaded data is deleted after analysis, while generated reports remain visible only to their creators.
      πŸ“„ Source: proton.me Β· πŸ“Ž Coverage: itsfoss.com Β· πŸ‘ via @agreenberg@infosec.exchange

πŸ“‹ ADVISORIES

  • GitLab Issues Emergency Patch for Critical GraphQL Code-Injection Flaw
    GitLab patched a critical GraphQL code-injection flaw that could let unauthenticated attackers alter or delete public projects.
    • Self-managed GitLab Community Edition and Enterprise Edition deployments are affected; GitLab.com and GitLab Dedicated are already patched.
    • CVE-2026-19478 affects GraphQL directive processing and could enable modification or deletion of public projects and user data.
    • The flaw is remotely exploitable without authentication through GitLab’s GraphQL API.
    • GitLab also fixed CVE-2026-19650, a CSRF flaw allowing GraphQL mutations through malicious GET requests when a victim interacts with the request.
    • Fixed versions include 19.2.4, 19.1.6, 19.0.8, and 18.11.11 across supported branches.
      πŸ“„ Source: rescana.com Β· πŸ“Ž Coverage: cybersecuritydive.com Β· πŸ‘ via Cybersecurity Dive

πŸ”“ CVEs & KEV

  • CVE-2026-73996 β€” CVSS 9.8 β€” WordPress Masteriyo - LMS plugin through 2.3.2 - Arbitrary File Upload vulnerabili...

  • CVE-2026-74015 β€” CVSS 9.3 β€” WordPress Readabler plugin before 2.0.18 - SQL Injection vulnerabilityUnauthentica...

  • CVE-2026-63639 β€” CVSS 8.8 β€” Valkey: UAF in stream deserialization may lead to remote code executionValkey...

  • CVE-2026-74012 β€” CVSS 8.8 β€” WordPress TaxoPress plugin through 3.51.0 - PHP Object Injection vulnerabilityEdit...

  • CVE-2026-75898 β€” CVSS 8.4 β€” RAGFlow before 0.26.3 - Server-Side Request Forgery via Agent Invoke ComponentRAGF...

  • CVE-2026-73400 β€” CVSS 8.1 β€” WordPress Restaurant Menu by MotoPress plugin through 2.4.11 - Local File Inclusio...

  • CVE-2026-56684 β€” CVSS 7.5 β€” Valkey: TLS pending-data processing use-after-free may allow remote code exec...

  • CVE-2026-73994 β€” CVSS 7.5 β€” WordPress Charitable plugin through 1.8.11.3 - Broken Access Control vulnerability...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check