Threat Brief — 2026-07-26 — Patches That Don't Patch
Two critical patch-management failures dominate today: GitLab sat on an RCE for 1.5 months disguised as a routine update while a working exploit circulated, and Redis shipped fixes that attackers bypassed trivially—leaving thousands of servers exposed. Meanwhile, the AFX Trade bridge-drain campaign continues to escalate, and the Pentagon is belatedly waking up to the absence of protection for undersea internet cables.
Top items
- GitLab RCE exploit public after 1.5-month disclosure delay. GitLab concealed an authenticated RCE vulnerability under the guise of a routine update for roughly six weeks; a working exploit is now in the wild. This is a developing story—first reported 2026-07-25 as a PoC publication (original coverage)—with the new development being GitLab's failure to disclose responsibly, leaving self-managed instances exposed throughout the window. Any self-managed GitLab instance not yet patched should be treated as potentially compromised. (src: securitylab-ru)
- Redis patches bypassed — thousands of servers still exposed. Redis developers attempted to fix the previously reported RCE zero-days (first reported 2026-07-24, The Hacker News) but shipped buggy patches that attackers circumvented with ease. This is a developing story: the original AI-found zero-days are now compounded by failed remediation, meaning patched instances remain vulnerable. Re-verify all Redis installations against the latest advisories rather than trusting the initial fix set. (src: securitylab-ru)
- AFX Trade bridge drained of nearly all locked assets. The AFX Trade bridge attack—part of the broader bridge-hack campaign first reported 2026-07-24 (xakep)—has escalated, with AFX losing almost all locked assets after the attacker exploited human error rather than a code flaw. The attack vector sidestepped smart-contract logic entirely, underscoring that bridge security depends as much on operational controls as on code audits. (src: securitylab-ru)
- Pentagon flags unprotected undersea internet cables. The Pentagon has identified that no entity is effectively guarding undersea internet cables critical to global communications, and that a single false signal can compromise sensor arrays and disrupt entire monitoring operations. This is a new story with strategic implications—cable disruption could sever connectivity for millions with minimal attribution. (src: securitylab-ru)
- DPRK state-trained hackers turned on their own Central Bank. Building on the arrests first reported 2026-07-24 (xakep), new reporting adds that the DPRK regime was reportedly caught off guard when its own elite hackers robbed the Central Bank of North Korea—a case of state-sponsored tooling being redirected inward. The development highlights insider-threat risk even in authoritarian cyber programs. (src: securitylab-ru)
Themes
Patch fatigue is becoming an attack surface. Both GitLab and Redis demonstrate that the gap between "patched" and "actually fixed" is weaponisable. GitLab's concealment and Redis's broken fixes show that organisations cannot assume a vendor patch cycle equals remediation—verify independently, and treat unpatched-but-"fixed" software as still vulnerable until confirmed.
Bridges remain the soft underbelly of DeFi. The AFX Trade drain is the latest in a sustained campaign against cross-chain bridges, and notably the attack succeeded through human error rather than a smart-contract exploit. Operational controls, key management, and multi-sig discipline matter as much as code audits.
