Cybersecurity Weekly Briefing, 3-9 October

October 9, 2026

GitLab fixes a critical vulnerability in AI Gateway involving remote command execution

GitLab has fixed the critical vulnerability CVE-2026-90970 (CVSSv3 9.9 according to GitLab), present in AI Gateway for self-managed deployments. The flaw allows authenticated users with access to the Duo Agent Platform to escape the template environment and execute arbitrary commands on the AI Gateway. Whilst customers using GitLab’s hosted infrastructure are not affected, many organisations have deployed on-premises gateways to keep AI data within their own environments.

As these systems manage JWT tokens and connectivity with external AI models, a successful exploit could lead to far-reaching compromises. GitLab recommends updating to the patched versions immediately.

More info

A Gentlemen ransomware affiliate turns an MCP into an operational C2 channel

CloudSEK has documented an actual operation in which a Gentlemen ransomware affiliate used an MCP (Model Context Protocol) as an interface to execute commands within compromised networks, turning tools accessible via an AI-based programming assistant into operational infrastructure for the attacker.

The operator, identified as Azazel, used a local MCP service with bearer token authentication to execute SSH commands and remotely check for the presence of ransom notes. The campaign targeted organisations in the logistics, insurance, pharmaceutical, artificial intelligence, medical devices and government-linked infrastructure sectors, whilst the theft of GitLab credentials granted access to passwords, tokens, SSH keys, databases and repositories.

In one instance, more than 120,000 records were stolen and the PostgreSQL data directory was deleted, demonstrating that the operations went beyond conventional encryption.

More info

Atlassian fixes arbitrary file access in its Data Centre products

Atlassian has issued a warning regarding CVE-2026-21589 (CVSSv3 9.3 according to Atlassian), a vulnerability that allows unauthenticated attackers to access specific files within the root directory of Data Centre applications. It affects Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye, meaning its potential impact spans numerous corporate development and collaboration environments. Exploitation requires prior knowledge of the exact file name and path and does not allow directory traversal; however, certain configurations may expose secrets or other sensitive data. Atlassian Cloud is already protected and requires no action from customers.

Organisations should apply the patched versions or, if they are unable to update immediately, take the affected instances offline and restrict all external access. Atlassian states that it is not aware of any active exploitation of the vulnerability.

More info

An investigation links a Chinese money-laundering network to funds stolen by Lazarus

Researcher ZachXBT claims to have infiltrated a Chinese criminal network of intermediaries that is alleged to have laundered over 1 billion dollars’ worth of cryptocurrencies from heists attributed to Lazarus/TraderTraitor, such as the Bybit hack in 2025. The investigation linked private conversations, commission payments, cross-chain transfers and funds originating from attacks. It identified a cluster holding over $12 million and contributed to the freezing of 442,000 USDT.

The full attribution and aggregate figure remain based on the investigator’s claims and are not publicly supported by all transaction records.

More info

PoeLLM hides its C2 in a poem and compromises over 3,400 AI servers

Black Lotus Labs, Lumen Technologies' research team, has documented PoeLLM, malware that has compromised more than 3,400 servers since April by exploiting open-source AI services such as LiteLLM, Ollama, Gotenberg and Gitea. Its most striking feature is how it resolves its C2: the actor posts a poem in a GitHub repository, from which the malware extracts four words positioned next to fixed text anchors, and each word is translated through a hard-coded dictionary into one octet of the command-and-control server's IP address.

This lets the operator rotate infrastructure without updating the binary, and the IP is only visible in the victim's own traffic. The infrastructure was spotted in June during an investigation into a maximum-severity flaw in Ivanti Sentry. For now the botnet is used for exploit scanning and cryptomining, although it includes remote code execution capability and turns every victim into a new attack node.

Researchers point to a likely Italian or Italian-speaking actor, with no links to other known groups.

More info