FR
live
archive

All articles

GitLab patches a critical unauthenticated GraphQL code injection flaw (CVSS 9.4)

On August 18, 2026, GitLab released fixes for two vulnerabilities, including a critical code injection via a GraphQL directive (CVE-2026-19478, CVSS 9.4) exploitable remotely without authentication or user interaction, allowing attackers to modify or delete public projects. Every self-managed installation must upgrade immediately — GitLab.com and GitLab Dedicated are already patched.

Mandiant’s AI agents unearth 100+ critical flaws in stolen code in two days

On August 19, 2026, the Google Threat Intelligence Group detailed AVDH, an AI-agent harness Mandiant has run for ten months to audit source code, which validated more than 100 critical flaws in two days on stolen corporate repositories. For defenders, it is the demonstration that manual code review can no longer keep pace with AI — and that a well-built harness can rebalance the fight.

Linux 7.2 ships cache-aware scheduling and up to 5% more IOPS on EXT4 and XFS

On August 16, 2026, Linus Torvalds released the stable Linux 7.2 kernel after seven release candidates, bringing cache-aware scheduling, USB4STREAM host-to-host transfers, and measured gains on EXT4, XFS, and MongoDB. For administrators, this is a performance release that arrives through the standard distro kernel update — the real work is testing MySQL and MongoDB workloads before rolling it out.

AWS opens a fourth London Availability Zone to absorb AI silicon demand

On August 19, 2026, AWS added a fourth Availability Zone (eu-west-2d) to the Europe (London) Region, carrying Trn3 and P6 capacity for training and inference. For architects it is both a four-zone resilience win and a clear signal: cloud expansion now runs on AI silicon.

Citrix NetScaler patches a critical remote authentication bypass (CVSS 9.3) exploitable without credentials

On August 19, 2026, Cloud Software Group published a bulletin for NetScaler ADC and NetScaler Gateway: CVE-2026-19490, a CVSS 9.3 authentication bypass exploitable remotely without credentials, and CVE-2026-19489, an 8.8 denial-of-service. Any internet-facing appliance needs an emergency upgrade, after triage driven by the SAML or vserver configuration.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss