A malicious commit has executed code in your ci/cd pipeline. https:// depthfirst.com/research/going- depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities
mastodon:infosec-exchange 64d ago
Researchers at depthfirst published working proof-of-concept exploit code on July 24 for a GitLab vulnerability affecting self-managed instances (patched June 10). Authenticated users can execute commands as git via malicious Jupyter notebook commits.
Researchers discovered a critical remote code execution chain in GitLab by combining two Oji parser bugs exploitable via Jupyter notebook diffs. The vulnerability affects authenticated users and urgent patches are being urged.
Unrelated collection of WHO health partnership announcements (April 2024), arXiv AI security research, weather statements, congressional bill tracking, FCC wireless innovation notice, and recent AI labor market commentary from November 2026. No coherent story.