GitLab exploit leaves no traversal string says Black Hills Information Systems

Posted in Commentary with tags on September 15, 2026 by itnerd

Black Hills Information Security has just published new research, “The GitLab Exploit With No Traversal In It,” showing that detection guidance circulating for the recently exploited GitLab vulnerability, CVE-2026-85706, may send security teams looking for the wrong indicators.

The critical vulnerability allows unauthenticated attackers to read arbitrary files from affected GitLab servers under certain conditions. CISA lists it as exploited in the wild, making the question of how to detect exploitation immediately relevant.

Black Hills’ Active SOC team examined nginx and Rails logs and tested Sigma and Suricata detection rules. Its research challenges reliance on commits-endpoint monitoring alone and gives security teams practical guidance for investigating suspicious activity. The testing described in “The GitLab Exploit With No Traversal In It” is controlled validation, it’s not a count of attacks observed against customers.

Eric Capuano, Black Hills Information Security’s Director of SOC Operations, notes that for enterprises, the concern extends beyond the initial file read: exposed credentials or secrets could enable further compromise. Patches are available in GitLab versions 19.1.8, 19.2.6, and 19.3.2. Updating closes the vulnerability, but does not establish whether sensitive information was accessed beforehand.

Approov Named Gold Sponsor of Cloudflare Connect 2026

Posted in Commentary with tags on September 15, 2026 by itnerd

Approov Limited will participate as a Gold Sponsor of Cloudflare Connect 2026, the company announced today. The conference runs Oct. 19-21, 2026, at Moscone West in San Francisco. Approov will be on site all three days, including the Global Partner Summit on Oct. 19.

Approov and Cloudflare have partnered since 2024 to close a gap that web-focused defenses were never built to address: traffic that originates from mobile applications. Cloudflare Bot Management and API Shield inspect and score traffic at the edge. Approov adds cryptographic proof of what is calling the API, verifying that a request comes from a genuine, untampered instance of the customer’s own app running on an uncompromised device. Requests that cannot prove their provenance never reach the origin.

That distinction has become more consequential as agentic AI systems mature. Automated agents can navigate interfaces, solve challenges, replay credentials and generate traffic that is behaviorally indistinguishable from a person using a phone. Heuristic and behavioral scoring degrades against an adversary that can imitate behavior on demand. Attestation does not. An agent operating outside the genuine app cannot produce a valid Approov token, however convincingly it mimics human interaction.

Approov is also a Cloudflare customer. The Approov attestation service runs on Cloudflare’s global network and uses Argo Smart Routing to cut latency on attestation traffic, a material requirement because every protected API call waits on a verification decision returning inside the time budget of a mobile app. Building the service on the same network its customers already run on means protection is enforced close to the user rather than in a distant round trip.

The partnership was extended in 2026 and now runs through 2028, giving joint customers a multiyear commitment behind the integration and giving both engineering teams a stable horizon for continued work on message signing and enriched mobile threat telemetry. Visit approov.io/approov-cloudflare-partnership to learn more about the partnership.

Attendees can find Approov in the sponsor hub throughout Connect 2026. Book a time with the Approov team at the event.

Inside Infostealer Attacks By Specops

Posted in Commentary with tags on September 15, 2026 by itnerd

An infostealer needs only a short window on an endpoint. It searches browsers and local folders for saved passwords, session cookies and cloud keys, packages what it finds and sends it out. Removing the malware afterwards doesn’t reach any of that. Mandiant found at least 79.7 percent of the accounts used in the 2024 Snowflake attacks had credentials exposed beforehand, the earliest traced to November 2020.

The research publishes alongside an update adding more than 46 million newly compromised passwords. You can view it here: Inside Infostealer Attacks

Volvo Cars launches long-range plug-in hybrid variants of best-selling XC60 and XC90 SUVs

Posted in Commentary with tags on September 15, 2026 by itnerd

Volvo Cars today launches its first ever long-range plug-in hybrids for the European and American markets, introducing new variants of the best-selling XC60 and XC90 SUVs. The new XC60, which also has a comprehensive design update, delivers class-leading electric range of up to 126 kilometres on a single charge, with the XC90 providing up to 117 km.

These long-range hybrids are a key part of Volvo Cars’ bridge to a fully electric future. They offer drivers paradigm-shifting electric range that makes school runs, daily commutes and weekend trips effortless and free of tailpipe emissions, with the quiet refinement of electric driving.

The electric range of the mid-size XC60 and large XC90 is now more than two and a half times as high as on the existing plug-in hybrid variants. This is thanks to a new, larger-capacity, floor-integrated battery and a more powerful electric motor, while the petrol engine can take over when needed. Both cars also remain available as mild hybrids.

Significant design and safety upgrades for new XC60

A new front and rear exterior design give the new XC60 a more contemporary and dynamic look. An upgraded grille and redesigned front bumper, hood, front wings and new wheels provide a new elegant interpretation of Volvo Cars’ Scandinavian design language.

The new design of the Thor’s Hammer Matrix LED headlights is one of the most eye-catching updates, with the iconic light signature refined to its purest expression, emphasising its technical sophistication. The design of the tailgate, rear LED lamps and rear bumper have been updated with a stronger emphasis on the horizontal lines to give the car a more powerful, confident stance.  

Inside, a new dashboard and door panel design, wood decor and Cardamom ventilated Nappa leather create a calm, Scandinavian-inspired cabin, with top-of-the-line interior illumination adding a sophisticated ambience.

The XC60 now includes the company’s latest active safety technology. If a potential collision is detected, the car can respond in real time – warning the driver or stepping in to help avoid or reduce the impact. From steering around danger with automatic emergency steering, braking instantly with automatic emergency braking, to alerting occupants of an approaching cyclist before a door is opened, it is designed to help choose the safest possible action in the moment.

To help make driving easier, the XC60 also comes with a wide range of advanced driver support features that work quietly in the background, enabled by an upgraded sensing set including radars, cameras and other sensors. Features such as lane change assist and a 360 camera with 3D view help drivers feel more aware behind the wheel.

The new XC60 also puts key information and controls within easy reach, providing easy access to key information and helping drivers to stay focused on the road. An 11.2-inch screen gives access to Volvo Car UX, the company’s latest infotainment system.

With Google Gemini, the next-generation AI assistant from Google, drivers can interact with the car naturally. From planning journeys and finding great stops to managing messages on the move, Gemini understands everyday language.  

The XC90, now even better than before

The Volvo XC90 has earned a reputation as one of the most acclaimed premium family SUVs, setting a benchmark for safety, comfort and Scandinavian design. Building on recent technology and design updates, this seven-seater continues to be one of the safest cars on the road.

The XC90 is designed to be a space where every journey feels more relaxing, restorative and comfortable. It embraces Scandinavian luxury, blending premium materials, natural light and a smooth wood decor that draws nature closer.

The optional Bowers & Wilkins premium sound system transforms the cabin into a space for immersive listening and unparalleled sound. Like the XC60, the XC90 also now features Google Gemini.

Securing continued popularity

These long-range plug-in hybrids underpin Volvo Cars’ sales and profitability ambitions. They represent efficient investments in the company’s existing line-up, securing continued popularity for the coming years and extending the important bridge towards full electrification.

Like all new Volvo cars, the new XC60 and XC90 will benefit from regular over-the-air updates, meaning a car that is great from day one gets better as time goes on. Order books for the new XC60 and XC90, including the Black Edition, are open from today in selected markets, with production starting later this autumn.

The small print

  • Range figures are preliminary and based on EPA testing standards obtained under specific testing conditions. Actual range can vary depending on charge level, car specification, outdoor temperature, battery temperature, weather, topography, driving style and car speed.
  • Availability of the features and services mentioned above may vary by market. Features may differ depending on subscription, and results may vary. Some features and services mentioned are optional and require customer opt-in.
  • Google and Gemini are trademarks of Google LLC. Some connected apps require setup. Compatibility and availability vary. 18+

Today Is National IT Professionals Day

Posted in Commentary on September 15, 2026 by itnerd

With National IT Professionals Day being today, September 15, I wanted to share some perspectives on this day from a couple of IT professionals.

Jason Tierney, SVP of Managed Services at C3

For defense contractors and other regulated organizations, IT support has a bigger job than closing tickets. We can’t just go do something and move on. The team needs a consistent process, clear approvals, and an understanding of the user’s work to explain why the compliance controls are there.

Those tickets are far more important than many realize. Each ticket is an artifact. It shows what changed, who approved it, and whether it was handled the right way. That matters when an assessment team asks how a system is being managed. When those pieces are in place, IT doesn’t scramble to prove it’s compliant when an assessment arrives. IT enables an assessment-ready position at all times.

A lot of the assessment issues I’ve seen are not caused by an unusual technology problem, but by assumptions and poor communication. People and processes get out of sync. The internal IT team, the MSP, and the compliance team may all be doing their part, but they need to understand that their roles are collaborative. Task ownership becomes unclear, a small process change made at the MSP can go undocumented in the compliance documentation, or a new SaaS application can be deployed internally without being reported to the MSP or compliance team. I’ve seen all of these turn into problems during both preparation and assessment.

This is where partnering with a quality managed services provider matters. It is not just about answering the phone or keeping systems running. It is about understanding the customer’s needs and ensuring those needs are being met. For us at C3, our customers are with us to become and stay compliant. As a result, our processes are built around achieving and maintaining that goal.

Mark Christie, Field CTO, StorMagic

“IT professionals play a part in nearly every workday. They make it possible for employees to log on, access critical systems, collaborate with colleagues, and get their work done without having to think about the technology behind it. When something does go wrong, they are often the first people called to identify the problem, find a solution and get everyone moving again.

National IT Professionals Day is an opportunity to recognize how much we depend on IT professionals, but their role extends far beyond keeping things running. Good IT is about more than technical expertise. IT professionals also help determine which technologies are worth investing in, whether they will actually solve the problem at hand and how they will fit into the way people work every day. That combination of technical knowledge and practical judgment enables and empowers employees, giving employees the tools and support they need to focus on their jobs.”

New data shows Canadian SMEs pull back on hiring as wages climb

Posted in Commentary with tags on September 15, 2026 by itnerd

With Small Business Month approaching in October, new first-party payroll data from, Employment Hero, the all-in-one employment platform for Canadian businesses, offers a timely look at how SMEs are faring heading into the final quarter of 2026.

The latest data points to a growing workforce balancing act: SMEs are pulling back on headcount, while continuing to pay more for talent.

Key findings include:

  • SME headcount declined 1.7% year-over-year in August, marking the second consecutive month of negative annual growth.
  • At the same time, wages rose 5.5% year-over-year, the highest annual increase recorded in the report’s 13-month reporting window, up from 4.1% in July.
  • The picture varies across the country: headcount declined 2.6% in Ontario and 3.1% in B.C., while remaining positive in Alberta (+0.5%), Quebec (+1.4%) and Nova Scotia (+2.4%).
  • Consumer-facing businesses are bucking the national trend, with headcount across retail, hospitality and tourism up 1.7% year-over-year.

The data suggests Canadian SMEs are becoming more cautious about adding people while continuing to invest in the talent they need, putting retention, productivity and smarter workforce planning firmly on the agenda as businesses head into Small Business Month and Q4.

Full findings are available here: Canadian SMEs Enter Small Business Month with Softer Employment and Rising Wages, New Employment Hero Data Shows.

VDURA Launches Sentinel: Storage Support That Opens the Service Request Before the Customer Sees a Fault

Posted in Commentary with tags on September 15, 2026 by itnerd

VDURA today announced VDURA Sentinel™, a proactive support capability included with the VDURA® Data Platform V12. Sentinel runs natively on the platform, watching continuously for faults and other notable events. Customers can share that health data with VDURA’s support team through the Sentinel cloud service, where it is analyzed against patterns drawn from thousands of VDURA systems in the field. When Sentinel spots an issue, it automatically opens a service request with VDURA support, complete with a proposed fix, often before anyone on site knows there’s a problem.

For operators running GPU clusters, the cost of a storage fault is measured in the hours between the fault and the fix: idle accelerators, stalled training jobs, and for a neocloud, tenant SLAs at risk. Conventional storage support adds delay at every step. Someone notices a symptom, files a ticket, gathers logs, describes the problem, and waits for a technician to work out what happened. Sentinel removes that cycle.

Sentinel continuously reads health, capacity, and alert telemetry from each system and compares it against failure patterns VDURA has resolved across thousands of systems in the field. When a pattern matches, the VDURA support team receives a plain-language summary, a trend view, and a recommended action, with the service request already open and, where needed, a parts dispatch initiated on the customer’s behalf. The first person to look at the ticket is looking at a diagnosis, not a blank page.

Sentinel is built on the same API-first foundation as the rest of the V12 platform. The collector gathers its telemetry through the platform’s published APIs, and everything Sentinel sees is equally available to the customer’s own dashboards and observability tooling. There is no privileged vendor-only view: operators get fleet-level observability into their storage as a first-class part of the platform, and VDURA support sees only the subset the customer chooses to share.

Built for security-conscious infrastructure teams

AI factories and GPU cloud providers operate under strict data-handling and tenant-isolation requirements, and many will not accept a vendor agent with write access or an opaque telemetry stream. Sentinel was designed around those constraints:

Read-only, outbound-only. The collector runs inside the customer’s environment with read-only credentials and makes only outbound HTTPS connections. There is no inbound access and no ability to change configuration or touch data.

File data never leaves the building. Sentinel does not transmit file contents, credentials, user or workload information, or logs. Only four categories of operational metadata can be shared: fleet health and capacity metrics, node inventory, alerts, and deep-dive diagnostics.

Per-category control, no support call required. Each of the four categories can be switched off independently, or all sharing can be disabled entirely, by the customer at any time. The local dashboard and the underlying storage are unaffected either way.

Inspect before it ships. A built-in payload inspector shows the exact contents of every outbound push before it is sent.

Auditable code. VDURA publishes the collector as dependency-free, readable Python so customer security teams can review exactly what it does.

Availability

Sentinel is included with the VDURA Data Platform V12 release, including the local fleet health dashboard and API access to the underlying telemetry. Proactive service requests and parts dispatch are delivered through VDURACare Premier, VDURA’s 10-year support offering that covers hardware, software, and 24×7 expert response under a single contract. 

Learn more: vdura.com/vdura-sentinel-support

Hackers move quickly to exploit maximum-severity GitLab flaw

Posted in Commentary with tags on September 14, 2026 by itnerd

Attackers are already probing for a maximum-severity GitLab vulnerability just one day after it was publicly disclosed and added to CISA’s KEV Catalog.

The flaw, tracked as CVE-2026-85706, carries a CVSS score of 10.0 and affects both GitLab Community Edition and Enterprise Edition. It allows an unauthenticated attacker, under certain conditions, to read arbitrary files from a vulnerable GitLab server.

The vulnerability is a path traversal issue in GitLab’s repository commits API caused by improper path confinement and missing authentication enforcement. Security researchers at watchTowr reported seeing in-the-wild probing beginning on September 11, within hours of disclosure.

GitLab patched the flaw in versions 19.1.8, 19.2.6 and 19.3.2 and is urging customers to upgrade immediately.

Denis Calderone, CTO, Suzu Labs:

“This is a big problem if you have an internet exposed GitLab instance. It takes just one request to pull gitlab-secrets.json gives an attacker the secret_key_base, and from there it’s session forgery, admin access, and full remote code execution on the box. We’re talking about a complete compromise path for the system that builds and ships your software.

“This patch came out September 10, watchTowr’s honeypots picked up active probing by 06:00 UTC on September 11, and multiple working proof-of-concept exploits hit GitHub the same day. CISA added it to the KEV catalog and gave federal agencies until today to patch. There are over 20,000 self-managed GitLab instances sitting on the public internet right now, and the only thing needed for exploitation is that a public project has to exist on the instance, which is extremely common.

“Obviously, if you have a self-hosted GitLab instance, get it patched, but if your GitLab instance was exposed to the Internet before September 10, you need to assume someone already tried this and hunt for IOCs. The detection signature is simple enough and you just need to look for HTTP POST requests to the repository commits API containing a file.path parameter. Legitimate use of that endpoint doesn’t include that parameter, so any hit is almost certainly an exploitation attempt. If you find one, rotate everything that server had access to. Everything is at risk including SSH keys, database credentials, deploy tokens, CI/CD variables, runner registration tokens. And if your self-managed GitLab doesn’t actually need to be internet-facing, this is as good a reason as any to pull it behind a VPN.”

Eric Capuano, Director of SOC Operations, Black Hills Information Security:

“The probing versus exploitation distinction does not mean much on this one. CVE-2026-85706 is a single unauthenticated HTTP request that returns the contents of a file. There is no payload, no staging, no second stage to wait for. Whoever is sending requests to find vulnerable servers is reading files with the same request they use to find them. Your exposure window opened on September 10 when GitLab shipped 19.1.8, 19.2.6 and 19.3.2, not on September 11 when someone noticed the traffic.

“What makes this worse than a typical file read is where it lands. A self-managed GitLab server holds gitlab-secrets.json, database and Redis credentials, CI/CD variables, runner registration tokens, deploy keys and personal access tokens. Reading files as the GitLab process is a credential harvest, and an upgrade does not un-steal a credential. The follow-on activity will not touch GitLab at all. It will be valid tokens authenticating to your registry and your build infrastructure, and it will look like normal pipeline traffic.

“Detection here is thin and teams should know that going in. A file read spawns no process, so EDR has nothing to show you. Your only record is the web tier. watchTowr’s hunting guidance is specific and worth taking: look for POST requests to /api/v4/projects/{id}/repository/commits/ carrying file.path parameters, and for unauthenticated requests to the commits API generally. If your logs have already rolled past September 10, you cannot prove you were not read, and you should work from the assumption that you were.

“Order of operations. Get an accurate version for every self-managed instance, including the one a product team stood up without telling anyone, and upgrade. The patch carries database migrations and takes single-node installs down, and that change window is the actual reason these boxes sit unpatched for weeks, so pull the instance off the internet until you can absorb the outage. Then rotate. Rotating GitLab’s own secrets file is ugly, because it breaks encrypted CI variables and 2FA seeds, which is exactly why people skip it and why you should not. CISA added this to KEV on the eleventh with a three day deadline and a forensic triage requirement attached, and triage is the half that gets dropped.”

Ryan McCurdy, VP of Marketing, Liquibase:

“The fact that attackers were probing for this vulnerability within hours of disclosure shows how little time organizations now have to respond to a critical CVE.

“Finding the vulnerability and releasing a patch are only the first steps. Enterprises still have to know whether they’re affected, understand the risk, test the fix, and get it into production without breaking something else. When exploitation starts almost immediately, slow or unclear remediation processes become part of the risk.

“That makes the response path just as important as the vulnerability itself. Organizations need to know who is accountable when a critical CVE is discovered, how quickly they can get a supported fix, and how they’ll safely deploy it across the systems that depend on that software.

“The question isn’t whether the software you depend on will ever have a vulnerability. It’s how prepared you are when the next critical one is discovered.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This GitLab vulnerability, and a number of other vulnerabilities like it, don’t concern me all that much when we’re talking about enterprise teams that have good security awareness and solid patching processes.

“What concerns me are all the smaller, fly-by-night development shops standing up their own Git instances that simply aren’t plugged into security news. They aren’t following the alerts. They aren’t watching for the latest vulnerabilities.

“And that’s a question the security community has been wrestling with since its inception. How do we reach those people?

“There’s so much preaching to the choir. There’s this massive infosec echo chamber, while so much of the actual damage from these vulnerabilities happens to organizations that aren’t plugged in and aren’t getting security updates on a regular basis.

“For everything we’re seeing with CISA and all the different alerts being published, that’s great. I think the heart is in the right place. But it still doesn’t answer the bigger question.

“How do we reach the people who aren’t listening in the first place?”

I have said it before. Threat actors will quickly exploit any unpatched or patched vulnerability. Thus while you need to patch all the things, you also need to do continuous scans to make sure the bad guys never get in.

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads 

Posted in Commentary with tags , on September 14, 2026 by itnerd

Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours. 

Commenting on this is Ensar Seker, CISO at SOCRadar

“This incident demonstrates how attackers are increasingly weaponizing trust rather than relying purely on technical exploitation. A malicious advertisement coming from a random account immediately raises suspicion, but an advertisement associated with a verified HBO Max account carries an implicit level of legitimacy. Once attackers compromise a trusted brand identity, they effectively inherit that trust and can use it as part of the social-engineering attack chain.

ClickFix is particularly effective because the attacker convinces the victim to execute the malicious action themselves. Instead of delivering a conventional executable that security controls may block, the victim is instructed to copy and paste commands into PowerShell, Windows Run, or macOS Terminal. From a detection perspective, this is challenging because legitimate operating-system tools are being used, and the initial execution is performed by the user. In this campaign, researchers observed payloads ranging from information stealers to cryptocurrency theft tools, with targeting across both Windows and macOS.

The larger security lesson is that organizations must treat corporate social-media and advertising accounts as privileged infrastructure. These accounts should have phishing-resistant MFA, tightly controlled administrator access, continuous monitoring, and rapid credential and session revocation capabilities. Organizations also need visibility beyond their traditional endpoints and domains, because attackers can compromise a trusted external platform and weaponize the organization’s brand without ever breaching the corporate network itself.
For users, there should also be a very simple rule: a website, advertisement, CAPTCHA, or software installer should almost never require you to manually paste an unfamiliar command into PowerShell or Terminal. That behavior should immediately be treated as a potential compromise attempt.”

This is an illustration of think before you click. Because threat actors are counting on the fact that you won’t do that and get pwned as a result.

Attackers are chaining three JFrog Artifactory bugs to plant admin backdoors 

Posted in Commentary with tags on September 14, 2026 by itnerd

Multiple threat actors have been chaining three JFrog Artifactory vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, in active exploitation confirmed between August 15 and September 8, using two of the bugs together to extract an anonymous-user token and escalate it to admin privileges, or exploiting the third for unauthenticated remote privilege elevation on its own. Once inside, attackers deployed persistent admin accounts, malicious plugins enabling arbitrary code execution, and SSH keys attached to newly created user accounts for sustained access. Patches are available across six version branches, and CISA has given federal agencies a two-week mandatory patch window.

Adrian Culley, Offensive Security Engineer, SafeBreach:

“Two medium-severity bugs beat a critical one here, and that’s the story. CVE-2026-42018 leaks an internal anonymous-user token; CVE-2026-42016 fails to enforce that token’s scope. Neither is exploitable alone — chained, they turn an unauthenticated request into an admin-scoped token, matching T1190 and T1078, before attackers reach Artifactory’s native plugin framework for code execution.

What makes this a validation failure rather than a patching one: both CVEs were fixed in July and August, yet the majority of exposed organisations were still running vulnerable versions when the chaining campaign started in mid-August. Patch availability was never the gap — verifying the token boundary actually held was.

Owning the fix isn’t the same as knowing whether your environment would have caught the chain before the plugin endpoint was reached. That’s a control you test, not one you assume.

Priority: upgrade to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20+; audit for unexpected admin accounts and attached SSH keys; review plugin installs and token-issuance logs; then validate the auth-bypass-to-RCE chain directly rather than relying on patch status as a proxy.”

It’s time to patch all the things when it comes to JFrog. Because clearly this has gotten out to the public domain which means that it’s only a matter of time before you get pwned.