GitLab Patches Critical Code Injection Vulnerability
GitLab issued an emergency out-of-cycle patch for a critical, unauthenticated code injection flaw tracked as CVE-2026-19478 (CVSS 9.4), which stems from improper handling of a GraphQL directive and lets attackers modify or delete user data and public projects without logging in. A second, lower-severity CSRF bug in the GraphQL multiplex query handler was fixed in the same release. The flaws affect all Community and Enterprise Edition versions from 18.2 and 19.0 through 19.2, and were resolved in 18.11.11, 19.0.8, 19.1.6, and 19.2.4; GitLab.com and GitLab Dedicated were patched automatically, but self-managed instances need to upgrade immediately. Both issues were reported through GitLab’s HackerOne bug bounty program, and there is no indication either has been exploited in the wild.
Cyberattack forces UT San Antonio to delay start of fall semester
The University of Texas at San Antonio, which serves more than 42,000 students, pushed the start of its fall semester back three days after detecting an intrusion attempt at the edge of its academic network over the weekend. University leaders say the activity was contained before reaching core systems and that no evidence of data theft has surfaced so far, but the school proactively took some services, including phone lines and its password reset tool, offline while it reinforced defenses. Classes originally set to begin August 19 will now start August 24, and no group has claimed responsibility for the attempted breach.
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Researchers at Wiz disclosed a workflow injection vulnerability in a public Snowflake .NET connector repository that let a specially crafted GitHub issue title execute arbitrary shell commands inside a CI workflow, ultimately exposing an internal Jira API token during a five-day exposure window. Wiz’s autonomous “Red Agent” found and exploited the bug during authorized testing, receiving an out-of-band callback that yielded credentials with read access to engineering, security compliance, and bug bounty Jira projects. Snowflake merged a fix and rotated the token the same day the issue was reported through HackerOne, and says its investigation found no evidence of unauthorized access or misuse of the exposed token.
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft confirmed it is developing a fix for “ShieldBreak,” a Defender privilege-escalation zero-day now tracked as CVE-2026-69414 that a researcher publicly disclosed without advance notice. The flaw bypasses an earlier patch for a related Defender bug and reportedly gives local attackers with limited permissions a 100 percent reliable path to SYSTEM privileges on fully patched Windows 10, 11, and Server systems, provided Defender itself is enabled. It is the latest in a string of unpatched Windows zero-days released by the same researcher amid an ongoing dispute with Microsoft over its vulnerability disclosure and bug bounty practices, and no patch timeline has been given yet.
Hackers Expose Data of 1.2 Million Heights Finance Customers
Consumer lender Heights Finance is notifying more than 1.2 million people that a third-party cloud platform used to store customer data was accessed without authorization in early May, exposing names, addresses, Social Security numbers, government IDs, and bank account details. The company says the incident was limited to the cloud platform and did not touch its loan management systems, and that operations continued uninterrupted throughout. Affected individuals, who include current and former borrowers as well as loan applicants, are being offered two years of free credit monitoring and identity protection, and the company reports no sign the stolen data has surfaced for sale.