GitLab is urging customers who run their own AI Gateway to update now. The company fixed a critical vulnerability that could let an authenticated attacker execute arbitrary commands on the service.
The flaw is tracked as CVE-2026-90970. According to GitLab, an attacker needs only basic privileges and access to the Duo Agent Platform to exploit it on an unpatched instance.
What the AI Gateway does
AI Gateway is the component that connects GitLab users to the AI-native features of GitLab Duo, the company's set of AI-assisted development tools. GitLab runs its own cloud-based AI Gateway, which serves GitLab.com, GitLab Self-Managed and GitLab Dedicated customers.
The city of Vicksburg, Mississippi, has shut down its computer systems following a ransomware attack, Mayor Willis Thompson told residents on Thursday evening.
Thompson announced the incident in a statement published in the local newspaper. He said the city is investigating the attack and described the shutdown as "temporary." Emergency services have not been affected, but residents cannot currently pay their utility bills through the usual channels.
Vicksburg has more than 20,000 residents and lies about 40 minutes west of Jackson, the state capital.
No shut-offs or late fees during the investigation
To ease concerns about the payment disruption, the mayor said no one's services will be disconnected while the investigation continues. The city will also not issue penalties for late payments.
A newly documented macOS backdoor called CloudSyncD is reaching victims through a fake Zoom installer, according to researchers at Jamf. The malware gives attackers persistent, quiet access to infected Macs.
Jamf first came across CloudSyncD in mid-September, while it was still under development. Within a few days the researchers found more samples. These suggested the operators had finished testing and begun using the malware against real targets.
A disk image posing as Zoom
The attack depends on social engineering. Victims are persuaded or tricked into downloading what looks like a Zoom installer for Mac. If they fall for it, they receive a disk image that mounts as a volume named Zoom.
Dell has fixed two maximum severity vulnerabilities in Container Storage Modules (CSM), the software that links the company's enterprise storage arrays to Kubernetes environments. The company is urging customers to update as soon as possible.
CSM works with Dell's main storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT. It adds features on top of the standard Container Storage Interface (CSI) drivers, which Kubernetes uses to talk to external storage systems.
Two critical flaws in the Authorization module
According to a security advisory Dell published on Thursday, both flaws sit in the CSM Authorization security module. Dell traces both to the same type of weakness: "missing authentication for critical functions."
Attackers took over Microsoft's official account on X on Thursday and used it to promote a cryptocurrency token in what looks like a pump-and-dump scheme. The @Microsoft account has more than 13 million followers.
In a pump-and-dump scheme, promoters inflate interest in an asset, often a little-known token, so they can sell their own holdings at a higher price before the value collapses. Access to a widely followed corporate account gives that kind of hype a large and trusting audience.
How the hijack unfolded
According to The Verge, which first reported the incident, the compromise became visible when @Microsoft followed and reposted a tweet from @clippymsftcto. That account impersonated Clippy, the animated paperclip assistant Microsoft shipped with older versions of Office. X has since suspended it.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.