<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: GitLab Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving GitLab.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git</title><link>https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html</link><guid isPermaLink="false">cst-3209</guid><description>A researcher released a working proof-of-concept exploit for an unpatched GitLab vulnerability (CVE-18.11.3) that allows authenticated users to execute arbitrary commands with git privileges. The attack requires only two malicious Jupyter notebook commits and a diff request, with no need for administrator rights or CI runner access.</description><pubDate>Sat, 25 Jul 2026 08:34:15 GMT</pubDate></item><item><title>Microsoft’s stance on zero day exploits is a dumpster fire of their own making</title><link>https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4?source=rss----8343faddf0ec---4</link><guid isPermaLink="false">cst-585</guid><description>A researcher going by Nightmare Eclipse has published proof of concept exploits for Microsoft vulnerabilities, claiming difficulty in responsible disclosure. Microsoft responded by disabling their MSRC account, removing exploits from GitHub, and characterizing the activity as potentially criminal. The situation highlights tensions between coordinated disclosure frameworks and researcher access to reporting mechanisms, complicated by Microsoft's historical hiring of security researchers who have publicly disclosed exploits.</description><pubDate>Thu, 28 May 2026 13:44:27 GMT</pubDate></item><item><title>CI/CD pipeline abuse: the problem no one is watching</title><link>https://elastic.co/security-labs/detecting-cicd-pipeline-abuse-with-llm-augmented-analysis</link><guid isPermaLink="false">cst-630</guid><description>Attackers are increasingly targeting CI/CD pipelines rather than production systems directly, compromising developer credentials and modifying workflow files to exfiltrate secrets at scale. The article details specific attack patterns including the GhostAction campaign (327 users, 3,325 stolen secrets), the Shai-Hulud npm worm (46,000 malicious packages), and automated scanning for misconfigurations like the pull_request_target trigger. A new open-source tool, cicd-abuse-detector, has been released to identify suspicious pipeline modifications across GitHub Actions, GitLab CI, and Azure DevOps using regex patterns and language model analysis.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Your control tower to secure code across GitHub, GitLab, and Azure Repos</title><link>https://wiz.io/blog/wiz-code-unify-security-across-github-gitlab-and-azure-repos</link><guid isPermaLink="false">cst-1571</guid><description>Wiz has released a security solution that provides visibility and control across code repositories on GitHub, GitLab, and Azure Repos. The offering integrates configuration checks and code scanning capabilities to secure development pipelines.</description><pubDate>Thu, 18 Jul 2024 14:47:16 GMT</pubDate></item></channel></rss>