Cybersecurity Weekly Briefing, 3-9 October
GitLab fixes a critical vulnerability in AI Gateway involving remote command execution
GitLab has fixed the critical vulnerability CVE-2026-90970 (CVSSv3 9.9 according to GitLab), present in AI Gateway for self-managed deployments. The flaw allows authenticated users with access to the Duo Agent Platform to escape the template environment and execute arbitrary commands on the AI Gateway. Whilst customers using GitLab’s hosted infrastructure are not affected, many organisations have deployed on-premises gateways to keep AI data within their own environments.
As these systems manage JWT tokens and connectivity with external AI models, a successful exploit could lead to far-reaching compromises. GitLab recommends updating to the patched versions immediately.
A Gentlemen ransomware affiliate turns an MCP into an operational C2 channel
CloudSEK has documented an actual operation in which a Gentlemen ransomware affiliate used an MCP (Model Context Protocol) as an interface to execute commands within compromised networks, turning tools accessible via an AI-based programming assistant into operational infrastructure for the attacker.
The operator, identified as Azazel, used a local MCP service with bearer token authentication to execute SSH commands and remotely check for the presence of ransom notes. The campaign targeted organisations in the logistics, insurance, pharmaceutical, artificial intelligence, medical devices and government-linked infrastructure sectors, whilst the theft of GitLab credentials granted access to passwords, tokens, SSH keys, databases and repositories.
In one instance, more than 120,000 records were stolen and the PostgreSQL data directory was deleted, demonstrating that the operations went beyond conventional encryption.
Atlassian fixes arbitrary file access in its Data Centre products
Atlassian has issued a warning regarding CVE-2026-21589 (CVSSv3 9.3 according to Atlassian), a vulnerability that allows unauthenticated attackers to access specific files within the root directory of Data Centre applications. It affects Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye, meaning its potential impact spans numerous corporate development and collaboration environments. Exploitation requires prior knowledge of the exact file name and path and does not allow directory traversal; however, certain configurations may expose secrets or other sensitive data. Atlassian Cloud is already protected and requires no action from customers.
Organisations should apply the patched versions or, if they are unable to update immediately, take the affected instances offline and restrict all external access. Atlassian states that it is not aware of any active exploitation of the vulnerability.
An investigation links a Chinese money-laundering network to funds stolen by Lazarus
Researcher ZachXBT claims to have infiltrated a Chinese criminal network of intermediaries that is alleged to have laundered over 1 billion dollars’ worth of cryptocurrencies from heists attributed to Lazarus/TraderTraitor, such as the Bybit hack in 2025. The investigation linked private conversations, commission payments, cross-chain transfers and funds originating from attacks. It identified a cluster holding over $12 million and contributed to the freezing of 442,000 USDT.
The full attribution and aggregate figure remain based on the investigator’s claims and are not publicly supported by all transaction records.
PoeLLM hides its C2 in a poem and compromises over 3,400 AI servers
Black Lotus Labs, Lumen Technologies' research team, has documented PoeLLM, malware that has compromised more than 3,400 servers since April by exploiting open-source AI services such as LiteLLM, Ollama, Gotenberg and Gitea. Its most striking feature is how it resolves its C2: the actor posts a poem in a GitHub repository, from which the malware extracts four words positioned next to fixed text anchors, and each word is translated through a hard-coded dictionary into one octet of the command-and-control server's IP address.
This lets the operator rotate infrastructure without updating the binary, and the IP is only visible in the victim's own traffic. The infrastructure was spotted in June during an investigation into a maximum-severity flaw in Ivanti Sentry. For now the botnet is used for exploit scanning and cryptomining, although it includes remote code execution capability and turns every victim into a new attack node.
Researchers point to a likely Italian or Italian-speaking actor, with no links to other known groups.
◾ This newsletter is one of the deliverables of our Operational and Strategic Intelligence service. If you are interested in knowing the rest of the Operational and Strategic Intelligence contents included in the service, please contact us →
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities