Threat Brief — 2026-08-21
Executive summary
Two critical vulnerabilities we've been tracking have escalated to confirmed in-the-wild exploitation: GitLab's unauthenticated GraphQL flaw (CVE-2026-19478) and Microsoft Entra ID's CVSS 10.0 deserialization RCE. On the defensive side, Google announced a mandatory 24-hour quarantine for apps from unverified Android developers, rolling out globally by 2027. A new "Mammoth" phishing campaign using fake fuel-discount sites stole 3.7M rubles in five days — a reminder that low-tech social engineering remains highly effective.
Top items
- GitLab CVE-2026-19478 now actively exploited — watchTowr reports the 9.4-CVSS code-injection flaw (unauthenticated project modification/deletion via GraphQL) is being attacked within days of disclosure, with no user interaction required. This is a genuine escalation of a story first reported 2026-08-17 by The Hacker News. Any organisation running self-managed GitLab should treat patching and backups as urgent. (src: The Hacker News) (src: SecurityLab)*
- Microsoft Entra ID CVSS 10.0 RCE confirmed exploited in the wild — Microsoft states CVE-2026-69836 (deserialization RCE) is being actively exploited but no customer action is required, suggesting server-side mitigation. This builds on the initial MSRC disclosure first reported 2026-08-20. Entra ID tenants should verify mitigations are in place and monitor for anomalous authentication-deserialization patterns. (src: The Hacker News)
- Google mandates 24-hour quarantine for apps from unverified developers — A new policy will delay installation of apps from unverified developers by 24 hours on all certified Android devices, applying globally by 2027. This is a significant defensive shift that will blunt drive-by installs and social-engineering-driven malware distribution on Android. (src: SecurityLab)
- "Mammoth" phishing scheme steals 3.7M rubles via fake fuel-discount site — A fraudulent site impersonating "Toplivo24" offered 30% fuel discounts and defrauded Russian motorists of nearly 10,000 rubles per victim over just five days. The speed and scale of monetisation highlights the persistent effectiveness of timely social-engineering lures tied to economic pressures. (src: SecurityLab)
Themes
Exploitation acceleration — Both GitLab and Entra ID flaws moved from disclosure to confirmed in-the-wild exploitation within days, continuing a pattern this month where attackers are weaponising critical CVEs faster than patch cycles can absorb. This reinforces the need for rapid patch prioritisation and segmentation of internet-facing services.
Platform-level defensive moves — Google's 24-hour app quarantine is a notable platform-level control that shifts some anti-malware burden from users to the ecosystem itself, complementing existing Android security measures.
===
THREAT-TOPICS===
[{"slug":"gitlab-graphql-unauthenticated-project-deletion","headline":"GitLab CVE-2026-19478 under active exploitation days after disclosure","findingIds":[9101,9097],"status":"developing","development":"watchTowr confirms active in-the-wild exploitation of the 9.4-CVSS GraphQL code-injection flaw within days of public disclosure; first reported 2026-08-17 by The Hacker News"},{"slug":"entra-id-rce-deserialization","headline":"Entra ID CVSS 10.0 deserialization RCE exploited in the wild","findingIds":[9098],"status":"developing","development":"Microsoft confirms CVE-2026-69836 is exploited in the wild with server-side mitigation; first reported 2026-08-20 by MSRC"},{"slug":"google-play-24h-delay-unverified-developers","headline":"Google mandates 24-hour install quarantine for unverified Android developers","findingIds":[9105],"status":"new"},{"slug":"mammoth-fuel-phishing-scheme","headline":"Fake fuel-discount site steals 3.7M rubles in five days","findingIds":[9099],"status":"new"}]
