GitLab Patches Critical Remote Code Execution Vulnerability

DevOps platform GitLab has issued patches for a critical remote code execution vulnerability impacting its GitLab Community Edition (CE) and Enterprise Edition (EE) releases.

Tracked as CVE-2022-2884 (CVSS 9.9/10 severity), the security flaw can be exploited via the GitHub import API, but requires authentication to be triggered.

read more

Apple Patches New macOS, iOS Zero-Days

Apple on Wednesday rolled out emergency patches for a pair of already exploited zero-day vulnerabilities in its flagship macOS and iOS platforms.

Apple confirmed in-the-wild exploitation of the vulnerabilities in separate advisories warning about code execution flaws in fully patched iPhone, iPad and macOS devices.

read more

Assange Lawyers Sue CIA for Spying on Them

Lawyers for WikiLeaks founder Julian Assange sued the US Central Intelligence Agency and its former director Mike Pompeo on Monday, alleging it recorded their conversations and copied data from their phones and computers.

read more