cognitive cybersecurity intelligence

News and Analysis

Search

Maximum-severity GitLab flaw allowing account hijacking under active exploitation

A major vulnerability in GitLab that allows hackers to take over accounts is now being actively exploited. The problem arose from a feature implemented in May 2023 that enabled users to change passwords through secondary email addresses. GitLab released a patch for the problem in January but many users have yet to install it. The US Cybersecurity and Infrastructure Security Agency has told all federal agencies to install the patch immediately. Even with the patch, previously breached accounts cannot be secured. It is advised GitLab users enable multi-factor authentication.

Source: arstechnica.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts