This day 02:00 06:00 10:01 14:01 18:02 22:02
Info  2026-08-21 10:01Z · last 4h · 12 findings · glm-5.2:cloud

Threat Brief — 2026-08-21

Executive summary

Two critical vulnerabilities we've been tracking have escalated to confirmed in-the-wild exploitation: GitLab's unauthenticated GraphQL flaw (CVE-2026-19478) and Microsoft Entra ID's CVSS 10.0 deserialization RCE. On the defensive side, Google announced a mandatory 24-hour quarantine for apps from unverified Android developers, rolling out globally by 2027. A new "Mammoth" phishing campaign using fake fuel-discount sites stole 3.7M rubles in five days — a reminder that low-tech social engineering remains highly effective.

Top items

Themes

Exploitation acceleration — Both GitLab and Entra ID flaws moved from disclosure to confirmed in-the-wild exploitation within days, continuing a pattern this month where attackers are weaponising critical CVEs faster than patch cycles can absorb. This reinforces the need for rapid patch prioritisation and segmentation of internet-facing services.

Platform-level defensive moves — Google's 24-hour app quarantine is a notable platform-level control that shifts some anti-malware burden from users to the ecosystem itself, complementing existing Android security measures.

===

THREAT-TOPICS===

[{"slug":"gitlab-graphql-unauthenticated-project-deletion","headline":"GitLab CVE-2026-19478 under active exploitation days after disclosure","findingIds":[9101,9097],"status":"developing","development":"watchTowr confirms active in-the-wild exploitation of the 9.4-CVSS GraphQL code-injection flaw within days of public disclosure; first reported 2026-08-17 by The Hacker News"},{"slug":"entra-id-rce-deserialization","headline":"Entra ID CVSS 10.0 deserialization RCE exploited in the wild","findingIds":[9098],"status":"developing","development":"Microsoft confirms CVE-2026-69836 is exploited in the wild with server-side mitigation; first reported 2026-08-20 by MSRC"},{"slug":"google-play-24h-delay-unverified-developers","headline":"Google mandates 24-hour install quarantine for unverified Android developers","findingIds":[9105],"status":"new"},{"slug":"mammoth-fuel-phishing-scheme","headline":"Fake fuel-discount site steals 3.7M rubles in five days","findingIds":[9099],"status":"new"}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db