TL;DR
GitLab and Dell released critical patches today for remote code execution vulnerabilities affecting AI Gateway and Container Storage Modules. Warlock ransomware is actively exploiting SharePoint flaws against water utilities, telecom operators, and government bodies. Organizations must apply patches immediately and audit SharePoint for unauthorized access.
Executive Summary
- GitLab released patches for critical AI Gateway vulnerabilities allowing arbitrary command execution on self-hosted instances.
- Dell disclosed CVSS 10.0 authentication bypass flaws in Container Storage Modules enabling unauthenticated root access on Kubernetes nodes.
- Warlock ransomware group is actively exploiting SharePoint vulnerabilities to target water utilities, telecom operators, regional government bodies, and universities across multiple countries.
- A China-nexus threat actor deployed the Antino backdoor using Outlook and OneDrive for command and control in a campaign targeting government and policy organizations across Asia.
- Frontline Education disclosed a data breach affecting school district employees after attackers exploited third-party software vulnerabilities.
Top Threats Today
1. GitLab AI Gateway Remote Code Execution
Severity: CRITICAL Affected: Technology
GitLab has released patches for critical vulnerabilities in its AI Gateway service that could allow authenticated users with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway instances [1][2]. The AI Gateway is the service connecting GitLab instances to AI models, and the vulnerability affects only organizations hosting their own infrastructure [1]. CVE-2026-90970 and CVE-2026-85706 have been identified, and GitLab has urged customers to patch immediately [2].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Identify all self-hosted GitLab AI Gateway deployments in your environment
- Apply latest GitLab patches to all affected instances immediately
- Review access logs for Duo Agent Platform users during the vulnerability window
- Restrict AI Gateway access to trusted networks pending patch deployment
2. Dell Container Storage Modules Authentication Bypass
Severity: CRITICAL Affected: Technology
Dell has released security updates addressing multiple critical flaws in Dell Container Storage Modules (CSM) that could enable unauthenticated attackers to take over Kubernetes nodes [1]. a reported vulnerability (identifier could not be verified against NVD and has been withdrawn) carries a CVSS score of 10.0 and involves missing authentication for critical functions, allowing bad actors to gain admin-level access and root privileges on vulnerable systems [1].
Sources:[1] The Hacker News
Recommended Action
- Prioritize patching of all Dell CSM deployments immediately
- Audit Kubernetes clusters for signs of unauthorized access or privilege escalation
- Implement network segmentation to restrict CSM access from untrusted sources
- Monitor container logs for suspicious authentication bypass attempts
3. Warlock Ransomware Expanding SharePoint Exploitation Campaign
Severity: HIGH Affected: Energy Telecom Government Education
The China-linked Warlock ransomware group has been actively exploiting SharePoint vulnerabilities since July 2025 to target critical infrastructure organizations ⚠ including water utilities, telecom providers, regional government bodies, and universities [1][2][3]. The group exploits a variety of SharePoint flaws to gain initial access, and attacks have been documented across Portuguese and Spanish-speaking countries as well as additional regions [2][3]. Warlock uses these vulnerabilities to establish persistence and deploy ransomware payloads against high-value targets [1].
Sources:[1] BleepingComputer[2] The Record[3] SecurityWeek
Recommended Action
- Apply all available Microsoft SharePoint security patches without delay
- Conduct immediate audit of SharePoint access logs for indicators of compromise
- Implement multi-factor authentication on all SharePoint administrative accounts
- Segment SharePoint infrastructure from critical operational technology networks
- Enable enhanced monitoring and alerting for unusual file access or sharing activity
4. Antino Backdoor Campaign Targeting Asian Government Entities
Severity: HIGH Affected: Government
A China-nexus threat actor has launched a campaign deploying the Antino backdoor to target government and policy organizations across Asia, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar [1]. The backdoor uses Outlook and OneDrive for command-and-control communications, leveraging legitimate Microsoft services to evade detection [1].
Sources:[1] The Hacker News
Recommended Action
- Monitor for abnormal Outlook and OneDrive API activity, particularly external data exfiltration
- Audit Microsoft 365 account permissions and remove unnecessary delegated access
- Implement conditional access policies to restrict login from unusual geographic locations
- Review email forwarding rules for unauthorized redirection of sensitive communications
5. Frontline Education Data Breach Affecting School Districts
Severity: HIGH Affected: Education
Frontline Education is notifying school districts of a data breach in which attackers exploited a vulnerability in third-party software to gain unauthorized access to systems and steal employee information, including Social Security numbers [1].
Sources:[1] BleepingComputer
Recommended Action
- Notify affected employees and provide credit monitoring services
- Inventory all third-party software integrations with Frontline Education systems
- Patch the vulnerable third-party software component immediately
- Review logs to determine the extent of data accessed during the compromise window
Ongoing Developments
Microsoft released patches for nearly 1,000 security holes in its Windows operating systems and other software; see earlier coverage for Fortinet FortiMail and related CVEs. Dutch police arrested a 23-year-old convicted cybercriminal suspected of aiding ShinyHunters data theft group. A U.S. Army soldier was sentenced to 70 months in prison for hacking AT&T and Verizon networks and stealing call and text metadata for over 100 million customers. ⚠ An Iranian national alleged to have participated in dozens of university breaches was extradited from Montenegro to face U.S. charges. The FBI is investigating a dark web service offering digital scans of over 153 million U.S. and Canadian drivers licenses.
Today’s Action Checklist
- ☐ URGENT: Patch GitLab AI Gateway instances with latest security releases
- ☐ URGENT: Apply Dell CSM patches to all Kubernetes environments
- ☐ URGENT: Deploy all available Microsoft SharePoint patches and audit for Warlock indicators
- ☐ HIGH: Review SharePoint and Outlook access logs for anomalies
- ☐ HIGH: Audit third-party software integrations in critical business applications
- ☐ MEDIUM: Update incident response plans to reflect expanded Warlock targeting of critical infrastructure sectors