logo

The GitLab Alert That Passed Every Filter (Except One Detail Nobody Checked)

ID: 6c84a931-2399-503a-a9b5-60df8b864a9e

STIX ID: report--6c84a931-2399-503a-a9b5-60df8b864a9e

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers delivered a convincing GitLab sign-in phishing email to employees of a UK specialty insurer that passed SPF/DMARC and had Proofpoint URL Defense-wrapped links, but included an impossible RFC1918 IP (10.115.13.36) in the sign-in details; Themis quarantined four mailboxes before any interaction. The report provides IoCs (displayed private IP, origin relay 46.235.173.194, referenced domain gitlab.tmkiln.cloud, and Proofpoint-wrapped URLs), analyzes why link-rewriting created a false sense of safety, and recommends adding body-text IP routing sanity checks, monitoring first-time senders from known domains, and training users to inspect message content beyond links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.