Info
2026-07-25 10:09Z · last 4h · 7 findings
· glm-5.2:cloud
Threat Brief — 2026-07-25 — GitLab PoC, ChonkyChicken, ChatGPT Dark
A working proof-of-concept for an authenticated RCE in self-managed GitLab 18.11.3 went public today — any low-privileged user with commit access can pivot to code execution as the git user. Separately, Kaspersky documented a novel BitLocker extortion method where attackers physically print ransom notes on victims' own printers, and the ChonkyChicken malware (attributed to TAG-195) was shown persisting through credential rotation. ChatGPT is confirmed down worldwide, compounding a rough week for AI service availability.
Top Items
- GitLab self-managed RCE PoC published. Researcher Yuhang Wang (depthfirst) released a working exploit targeting unpatched self-managed GitLab 18.11.3. Any authenticated user can trigger command execution as the git user by committing a crafted payload — meaning a single compromised or insider account on a self-hosted instance is sufficient for full server takeover. If you run self-managed GitLab, patch immediately and audit for unauthorised users. (src: The Hacker News)
- ChonkyChicken malware (TAG-195) survives password resets. TAG-195's toolkit continues tracking victims even after credential replacement, using persistence techniques that evade standard remediation. The group's tooling is described as exceptionally difficult to detect, making password rotation alone insufficient — full endpoint forensics and rebuild are likely needed. (src: SecurityLab)
- Novel BitLocker extortion prints ransom note on victim's printer. Kaspersky dissected an attack where hackers encrypted disks with BitLocker and printed a $3,000 ransom demand directly on the victim's networked printer. The method is notable for weaponising built-in Windows encryption and a ubiquitous office peripheral, requiring no custom ransomware binary. (src: SecurityLab)
- US intelligence warns Chinese espionage is pivoting to AI startups. Congressional testimony flagged that private AI companies — not traditional defence contractors — are now the primary espionage targets, and that intelligence services are failing to protect them. This aligns with the pattern of recent AI-adjacent breaches and signals that AI labs should treat nation-state threat models as baseline, not worst-case. (src: SecurityLab)
- ChatGPT suffers worldwide outage. OpenAI confirmed global connectivity issues affecting ChatGPT. No attribution or root cause has been disclosed yet. This follows a week of high-profile AI service disruptions and raises business-continuity questions for organisations that have embedded ChatGPT into production workflows. (src: BleepingComputer)
- Deep network traffic analysis "highly overrated," new analysis argues. A SecurityLab piece contends that modern encrypted protocols increasingly hide connection metadata, forcing traffic-analysis systems to rely on weak indirect signals and producing higher false-positive rates. The practical takeaway: deep-packet-inspection tooling should not be treated as a reliable control for classifying or blocking covert channels. (src: SecurityLab)
Themes
- Built-in tooling as attack surface. Both the GitLab RCE and the BitLocker-printer extortion abuse legitimate platform features (git commit hooks, Windows BitLocker + print spooler) rather than deploying custom malware — a reminder that hardening default configurations matters as much as threat detection.
- AI services as both target and dependency. The ChatGPT outage and the intelligence warning about AI-lab espionage converge on a single risk: organisations are increasingly dependent on AI services that are themselves becoming prime targets for nation-state actors and operational disruption.
