Perfect-10 GitLab bug under attack days after patch lands

Summary

A critical GitLab vulnerability, dubbed "Perfect-10," is being actively exploited in the wild just days after a patch was released. CISA has confirmed the exploitation, and security firm WatchTowr has observed attackers probing internet-facing GitLab servers.

IFF Assessment

FOE

Active exploitation of a critical vulnerability poses a direct threat to organizations and their data, making it bad news for defenders.

Severity

10.0 Critical (AI Estimated)

The article refers to a 'Perfect-10' GitLab bug, implying a maximum severity score. Such vulnerabilities typically allow for remote code execution and significant impact on system integrity and confidentiality, warranting a CVSS score of 10.0.

Defender Context

This highlights the critical importance of timely patching for internet-facing services. Defenders should prioritize applying the GitLab patch immediately and monitor their systems for any signs of compromise, as attackers are actively seeking vulnerable instances.

Read Full Story →