Breaking
SickKids data breach exposes employee and job applicant informationGitLab’s critical CVE-2026-19478 is under active exploitation within days of disclosure.Khazanah affirms governance push after third-quarter board meetingQR code payments launched for ShopeePay users in ChinaBanjarbaru delays school start times as haze worsensLuxury sales drop more than 10% in China as tax crackdown bitesCDL net profit surges 230.7% in first half on Lumina Grand recognitionTrade Minister sets US$25 billion Trade Expo Indonesia 2026 targetTeladan Group swings to RM9.31 million profit in 2QFY2026 on higher progressive billingsAI Living @ i-City to launch in Shah Alam with four agenciesNevada approves 8,000 robotaxis for Tesla, Uber and WaymoAI data startup Micro1 reaches $500M gross run rate amid AI training boomMan jailed and caned for stabbing Singapore priest during communionEmployee of town council managing agent charged with corruption offencesDialog Group rises 2% as oil price boost lifts earnings hopesOAuth apps on Cloudflare hit 1,000 mark since June with over 1 million user consentsCISA issues logging guidance for US federal agencies ahead of 2026 deadlineRussian missile strikes kill 17 in Kyiv, Guterres demands ceasefireGaza shelter crisis deepens as Israeli strikes and aid curbs bitePrince Harry, Meghan and children return to Britain: key factsSickKids data breach exposes employee and job applicant informationGitLab’s critical CVE-2026-19478 is under active exploitation within days of disclosure.Khazanah affirms governance push after third-quarter board meetingQR code payments launched for ShopeePay users in ChinaBanjarbaru delays school start times as haze worsensLuxury sales drop more than 10% in China as tax crackdown bitesCDL net profit surges 230.7% in first half on Lumina Grand recognitionTrade Minister sets US$25 billion Trade Expo Indonesia 2026 targetTeladan Group swings to RM9.31 million profit in 2QFY2026 on higher progressive billingsAI Living @ i-City to launch in Shah Alam with four agenciesNevada approves 8,000 robotaxis for Tesla, Uber and WaymoAI data startup Micro1 reaches $500M gross run rate amid AI training boomMan jailed and caned for stabbing Singapore priest during communionEmployee of town council managing agent charged with corruption offencesDialog Group rises 2% as oil price boost lifts earnings hopesOAuth apps on Cloudflare hit 1,000 mark since June with over 1 million user consentsCISA issues logging guidance for US federal agencies ahead of 2026 deadlineRussian missile strikes kill 17 in Kyiv, Guterres demands ceasefireGaza shelter crisis deepens as Israeli strikes and aid curbs bitePrince Harry, Meghan and children return to Britain: key facts
Economy

GitLab’s critical CVE-2026-19478 is under active exploitation within days of disclosure.

According to cybersecurity firm watchTowr, the 9.4-CVSS code-injection flaw lets unauthenticated attackers rewrite or delete publicly accessible GitLab projects. The vulnerability can be triggered via a GraphQL directive, GitLab said in versions 19.2.4, 19.…

Source: The Hacker News · August 21, 2026 at 10:01 AM · AI-assisted report

Single-source
IntelligenceDomainFork
Image: DomainFork

KUALA LUMPUR, 21 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

According to cybersecurity firm watchTowr, the 9.4-CVSS code-injection flaw lets unauthenticated attackers rewrite or delete publicly accessible GitLab projects. The vulnerability can be triggered via a GraphQL directive, GitLab said in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11.

Market Impact

watchTowr reproduced the issue minutes after disclosure and detected in-the-wild attacks against its honeypot network. Principal security researcher Jake Knott said AI-enabled attackers are compressing the time from disclosure to exploitation.

“Organizations that haven’t patched should hunt web logs for requests containing ‘@gl_introduced’,” Knott said. He also advised restricting unauthenticated access to “/api/graphql” or removing public repository access if patching is delayed.

The flaw can delete entire repositories and forge merge records to disguise failed fixes, watchTowr added. It urged organizations running internet-facing self-hosted GitLab instances to upgrade immediately.

Reporting based on The Hacker News. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.