Compiled from 52 monitored sources · 140 articles reviewed
Today’s Briefing
CVE-2026-19478 in GitLab is under active exploitation, allowing unauthenticated attackers to remotely modify or delete public projects via a GraphQL flaw rated 9.4 CVSS; GitLab issued an emergency patch this week and WatchTowr confirmed live abuse. Separately, two Android supply chain campaigns are running in parallel: ToxicPanda 2.0 now targets 349 financial institutions across 16 countries and abuses Android Wireless Debugging for credential theft, while a separate operation is infecting aftermarket car head units via a compromised legitimate update app to build proxy botnets and conduct ad fraud. The car head unit campaign was documented by Kaspersky and affects Android-based in-vehicle systems distributed through supply chains serving multiple markets.
Top Stories
- ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
- Hackers infect Android car head units with proxy botnet malware
- GitLab Warns of Active Exploitation of Critical GraphQL Flaw
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.