August 24, 2026
- Public labs and safe PoCs shipped for the exploited GitLab flaws — a reproducible environment for CVE-2026-19478 / CVE-2026-19650 (GraphQL
@gl_introduced) (GitHub) and a second lab for CVE-2026-10053, the npm package-registry path traversal giving arbitrary file write asgit(GitHub). Released on the basis that exploitation is already circulating (earlier coverage). · New Tools & Releases
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline