>

Weekly Threat Intelligence: GitLab Exploited in Days, the 86-Minute Rust Backdoor, and NetScaler 9.3 (August 2026 W3)

GitLab CVE-2026-19478 went from disclosure to in-the-wild exploitation in days; a compromised maintainer account backdoored three Rust crates with 245M downloads for 86 minutes; Citrix shipped a CVSS 9.3 NetScaler auth bypass. The week's threats, IoCs, and your Monday patch list.

Continue ReadingWeekly Threat Intelligence: GitLab Exploited in Days, the 86-Minute Rust Backdoor, and NetScaler 9.3 (August 2026 W3)

Your Source Code Is Showing: The Exposed .git Mistake We’ve Found for 10 Years Straight

One curl request to /.git/HEAD hands attackers your full source, every commit ever made, deleted files, and usually a working credential. A decade of research says this mistake is not aging out. Here is the exploit chain — and the three-layer fix.

Continue ReadingYour Source Code Is Showing: The Exposed .git Mistake We’ve Found for 10 Years Straight
Read more about the article Software Supply Chain Security: Risks in Dependencies, Builds, and Secrets
Supply Chain Security: Risks in Dependencies, Builds & Secrets

Software Supply Chain Security: Risks in Dependencies, Builds, and Secrets

A practical guide to software supply chain security covering dependency risks, secrets exposure, CI/CD trust failures, artifact integrity verification, SBOM management, and real-world attack case studies.

Continue ReadingSoftware Supply Chain Security: Risks in Dependencies, Builds, and Secrets
>