LIVE · cybersecurity feed
Live wire
CVE-2026-73570 · Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesCVE-2026-12569 · Cl0p Targets 40+ Organizations Through PTC Windchill FlawCVE-2026-69836 · Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineHackers poison arrayref Rust crate to push infostealer malwareNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsSenators press TikTok over withholding of safety features for some usersAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureChatGPT for Teens tackles risky chats and homework shortcuts
gitlabmedium

GitLab 19.3 helps enterprises scale agentic development securely

GitLab's latest update, version 19.3, enhances security and control for enterprises scaling agentic software development. Key features include running GitLab Duo Agent Platform within dedicated single-tenant environments, allowing custom model integration, and keeping AI data within existing security boundaries. The release also introduces improved secrets management, bulk SAST false positive detection, and a Flow Creator Agent for simplified automation.

zeroday.news ·

GitLab has released version 19.3 of its platform, introducing updates designed to enhance control and security for enterprises adopting agentic software development. Key features include the integration of the GitLab Duo Agent Platform into GitLab Dedicated environments, a new Secrets Manager, and tools for bulk SAST vulnerability remediation.

For GitLab Dedicated customers, the AI Gateway for GitLab Duo Agent Platform now operates within their existing single-tenant SaaS infrastructure. This allows agentic workloads to adhere to the same data residency and isolation models as other software development lifecycle components, enabling organizations to connect their own models for inference and maintain AI-processed data within their established security boundaries.

The new GitLab Secrets Manager is now available in limited release as a paid add-on for GitLab.com customers, billed via GitLab Credits. This feature extends secret management beyond pipelines, ensuring that every CI secret is scoped to the specific environment, branch, and protection status of the job requiring it. The manager also supports Kubernetes, Terraform, OpenTofu, and custom tools, aiming to consolidate credential management within the same platform that runs code and pipelines.

GitLab 19.3 also introduces capabilities for bulk SAST false positive detection and agentic SAST vulnerability resolution. These tools allow security teams to address multiple findings in the Vulnerability Report simultaneously. The system provides a confidence score for each finding, and confirmed risks can generate ready-to-merge fixes, streamlining the remediation process for entire vulnerability backlogs. GitLab will continue to automatically triage and remediate new critical and high-severity findings as they emerge.

The Flow Creator Agent, accessible through Agentic Chat within the GitLab Duo Agent Platform, aims to simplify custom automation. Users can describe desired automations in plain language, and the agent generates a runnable flow ready for registration from the AI Catalog. These flows operate under a scoped service account with composite identity, requiring a Maintainer role or higher to enable.

Additional features in GitLab 19.3 include the general availability of GitLab Credits usage caps, allowing administrators to set monthly spending limits for agentic AI. These caps can be configured at the subscription level in the Customers Portal, with options for default per-user caps or per-user overrides via the GraphQL API. Restricted visibility for custom agents and flows per GitLab group is also now generally available, making them accessible to members across multiple projects within a group, in addition to existing per-project and public visibility options.

gitlabdevsecopsaisecurityautomation
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek.

vulnerability

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueCon

vulnerability

Microsoft Rolls Out 22 Fresh Security Patches

Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek.

cisahigh

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA has issued a directive for immediate patching of critical vulnerabilities affecting TrueConf software. The Head Mare hacktivist group is actively exploiting these flaws to distribute the PhantomCore malware. Organizations using TrueConf are urged to apply the necessary updates to prevent further compromise.

CVE-2026-12569critical

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

The Cl0p ransomware group has claimed responsibility for exploiting a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software, impacting over 40 organizations. The group is using a custom implant for data theft and extortion, demanding payment from victims. Several major companies, including Shell and Philips, are reportedly among the targeted entities, though most have only acknowledged awareness and are investigating.