Skip to Content

Security News Update: How to Patch CVSS 9.9 RCE Vulnerability in GitLab AI Gateway? and more

GitLab Patches AI Gateway RCE

GitLab patched a CVSS 9.9 flaw that could let authenticated users escape its self-hosted AI Gateway sandbox and execute system commands.

These gateways can contain sensitive authentication material and connect the platform’s AI features to underlying AI infrastructure.

AI security conversations tend to focus heavily on prompts and model behavior, but this vulnerability shows why the infrastructure surrounding AI deserves just as much scrutiny.

Patch affected AI Gateways, restrict Duo Agent Platform access, and review custom flow configurations for unexpected changes.

California Subpoenas OpenAI Over AI Cyber Risks

California Attorney General Rob Bonta subpoenaed OpenAI as part of an investigation into cybersecurity risks involving its AI models.

The investigation follows an incident in which OpenAI agents accessed parts of Hugging Face’s infrastructure during internal testing.

This could push AI security beyond a question of what an agent is capable of doing and toward what safeguards vendors can prove are in place when something goes wrong.

Require AI vendors to document their containment controls, monitoring capabilities, and incident response procedures before deployment.

Microsoft X Account Hijacked in Crypto Scheme

Attackers hijacked Microsoft’s X account to promote a Clippy-themed crypto token to its 13 million followers.

Microsoft regained control of the account and there is no evidence its internal systems were breached.

Whether you remember Clippy fondly or were happy to see him disappear, seeing him return as part of a crypto scheme probably wasn’t on anyone’s 2026 bingo card.

Require phishing-resistant MFA, limit social media publishing access, and establish a process for quickly locking down compromised accounts.

Police Take Down KillSec Ransomware Network

An international police operation seized KillSec’s infrastructure, arrested three suspects, and linked the ransomware group to roughly 1,000 attacks worldwide.

KillSec exploited software flaws and poorly secured cloud access, with roughly 500 suspected attacks succeeding.

Disrupting KillSec removes infrastructure the group was actively using, but it does not fix the security gaps that enabled its attacks.

Prioritize patches for internet-facing systems, restrict cloud administrative access, and review exposed services for unnecessary access.

4 Cybersecurity Habits to Rethink in 2026

For Cybersecurity Awareness Month, eSecurityPlanet’s Matt Gonzales shared four security habits he changed after covering cybersecurity news.

His experience shows how evolving threats can give familiar cybersecurity advice new urgency.

Matt brings the perspective of the everyday user we’re actually trying to reach. His experience is a good reminder that our security guidance needs to be practical enough for people to use.

Keep security guidance simple, explain why it matters, and give users clear actions they can take.

Could Your Team Contain Ransomware Today?

Ransomware groups are moving faster, giving security teams less time to detect suspicious activity and contain a compromise before ransomware spreads across the environment.

How to reduce ransomware risk:

  • Reduce initial access by prioritizing patches for internet-facing systems, enforcing phishing-resistant MFA, and limiting privileged access.
  • Contain compromised systems with network segmentation while using EDR and centralized logging to identify lateral movement and suspicious activity.
  • Verify recovery readiness by maintaining offline or immutable backups and regularly testing whether critical systems can be restored.

The real measure of ransomware readiness is whether your controls have been tested together under realistic attack conditions.