logo

GitLab, Forminator WordPress, Azure breach: Critical RCEs and 3.6M records stolen

ID: abca9662-e93f-5004-97a8-80fdb801b77b

STIX ID: report--abca9662-e93f-5004-97a8-80fdb801b77b

Feed Name: defend.network

Threat Score
78/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: defend.network

...
...

**TL;DR:** Multiple high-severity threats reported: GitLab patched a critical GraphQL flaw enabling unauthenticated project modification/deletion; Forminator WordPress plugin has an alleged unauthenticated RCE impacting many sites; a threat actor claims theft of 3.6M Azure account records from Fortune 500 companies via compromised credentials; researchers disclosed a GitHub Actions workflow injection affecting Snowflake repositories; and Iranian-linked Cavern C2 activity continues to evolve—urgent patching, credential resets, and audits are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.