Cookie Consent by Free Privacy Policy Generator

Cyber Brief: Cisco Zero-Day, GitLab Supply Chain Risk

Today's brief focuses on vulnerabilities being actively exploited in widely deployed enterprise systems, supply chain security risks, and the continuing evolution of social engineering techniques that bypass technical controls. Each story highlights the importance of timely patching, understanding how attackers abuse legitimate processes, and maintaining clear ownership of security response across the organisation.

Cisco Secure Email Gateway vulnerability under active exploitation

Cisco has confirmed that a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway is being actively exploited in the wild. SecurityWeek reports that CVE-2026-76461, which carries a CVSS score of 9.8, allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system with root privileges. The flaw stems from insufficient validation in the email parsing logic. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue, and Cisco has released patches for affected versions. The Hacker News notes that exploitation does not require authentication or user interaction, making this a particularly serious exposure for organisations running vulnerable versions.

Cisco Secure Email Gateway is widely deployed across UK organisations for email security, spam filtering and threat protection. The fact that this vulnerability is already being exploited in the wild means that any organisation running an unpatched version is at immediate risk of compromise. Root-level command execution gives an attacker complete control over the email gateway, which could be used to intercept communications, deploy further malware, pivot into internal networks, or exfiltrate sensitive data passing through the mail system. Email gateways sit at a critical point in most organisations' infrastructure, making them high-value targets for attackers seeking initial access or persistent visibility into business communications.

Why it matters

For UK businesses running Cisco Secure Email Gateway, this is a prompt to verify patch status immediately and ensure monitoring is in place to detect any signs of compromise. If patching cannot be completed quickly, consider whether temporary mitigations or increased monitoring can reduce exposure until updates are applied.

Source: SecurityWeek

Maximum severity GitLab vulnerability puts supply chains at risk

GitLab has disclosed a critical path traversal vulnerability, CVE-2026-85706, with a maximum CVSS score of 10.0. Dark Reading reports that the flaw affects both GitLab Community Edition and Enterprise Edition instances, and could allow an attacker to traverse file paths and access sensitive data or execute code. The vulnerability impacts the software supply chain, as GitLab is widely used for source code management, CI/CD pipelines and DevOps workflows across enterprises. GitLab has released patches, and organisations are being urged to update immediately. The severity rating reflects the potential for widespread impact if exploited, particularly given GitLab's role in managing code repositories and deployment pipelines.

GitLab is a core component of many UK organisations' software development and deployment processes. A vulnerability of this severity in a platform that manages source code, credentials, CI/CD pipelines and deployment secrets represents a significant supply chain risk. An attacker who successfully exploits this flaw could gain access to proprietary code, inject malicious changes into software builds, steal API keys and deployment credentials, or compromise downstream systems that rely on code and artefacts managed through GitLab. The maximum severity score reflects the fact that exploitation could lead to full system compromise without requiring authentication or user interaction, depending on configuration.

Why it matters

For organisations using GitLab, this is a prompt to prioritise patching and review access controls, monitoring and audit logging around your GitLab instances. Consider whether your current visibility into GitLab activity would detect unauthorised access or suspicious changes to repositories and pipelines.

Source: Dark Reading

ClickFix social engineering attacks target Mac and Windows users

TechCrunch reports that a new wave of ClickFix attacks has been targeting both macOS and Windows users through compromised social media accounts and malicious advertising. The Register describes the campaign as a "massive 48-hour malvertising blitz" that included the compromise of the HBO Max Reddit account. ClickFix attacks trick users into copying and running malicious commands by presenting fake error messages or system prompts that instruct users to paste and execute code in their terminal or PowerShell. The attacks bypass traditional technical controls by relying entirely on social engineering to convince users to manually execute malware on their own systems. The campaign demonstrates how attackers are increasingly targeting users directly rather than relying solely on technical exploits.

ClickFix represents a shift in attacker tactics that UK organisations need to understand and prepare for. These attacks succeed not because of a software vulnerability, but because they manipulate users into bypassing security controls themselves. The technique is effective because it mimics legitimate troubleshooting steps that users may have encountered before, and because it works across different operating systems and security configurations. The compromise of high-profile social media accounts like HBO Max's Reddit presence shows how attackers are using trusted channels to distribute these attacks. Traditional endpoint protection may not detect or block ClickFix attacks because the malicious code is executed voluntarily by the user, making awareness and user education critical defensive layers.

Why it matters

For many organisations, this is a reminder to review user awareness training and ensure that staff understand the risks of copying and running commands from untrusted sources. Consider whether your current security awareness programme covers social engineering techniques that bypass technical controls.

Source: TechCrunch

Revolut confirms customer data breach through fake government requests

TechCrunch reports that Revolut has confirmed a customer data breach that occurred through fake government data requests. Attackers submitted fraudulent legal requests impersonating law enforcement or government agencies, successfully convincing Revolut to disclose customer information. The company has notified affected customers and alerted the relevant government agency, law enforcement and financial regulators. The incident highlights a growing trend of attackers abusing legitimate legal and regulatory processes to obtain sensitive data without needing to exploit technical vulnerabilities. This type of attack relies on social engineering and process manipulation rather than traditional hacking techniques.

This incident is significant for UK organisations because it demonstrates how attackers are targeting the processes and procedures that organisations use to comply with legal and regulatory obligations. Many UK businesses receive data requests from law enforcement, regulators or other government bodies, and have established processes for responding to them. If those processes do not include robust verification steps, they can be exploited by attackers who understand how to craft convincing fake requests. The Revolut breach shows that even large, security-conscious financial services organisations can be vulnerable to this type of attack. For organisations that handle customer data, payment information or other sensitive records, this is a reminder that compliance processes themselves need to be treated as potential attack vectors.

Why it matters

For UK businesses that handle data subject access requests, law enforcement requests or regulatory enquiries, this is a prompt to review verification procedures and ensure that staff understand how to authenticate the legitimacy of requests before disclosing sensitive information.

Source: TechCrunch

Today's Key Actions

  • Verify patch status for Cisco Secure Email Gateway instances and prioritise updates for CVE-2026-76461 if your organisation uses this platform
  • Review and prioritise patching for GitLab instances, and consider whether current monitoring would detect unauthorised access to repositories or CI/CD pipelines
  • Update security awareness training to cover ClickFix and similar social engineering techniques that instruct users to run commands from untrusted sources
  • Review procedures for responding to data requests from law enforcement or regulators, and ensure verification steps are in place before disclosing customer information
  • Ensure clear ownership exists across the organisation for vulnerability management, user awareness, supply chain security and data handling procedures

Secarma Insight

Today's stories illustrate that effective security requires attention across multiple layers: timely patching of critical systems, understanding how attackers exploit trust and process rather than just technology, and ensuring that compliance and operational procedures are designed with security in mind. The most mature organisations treat security as a set of habits and disciplines that are already in place before incidents occur, rather than something that is bolted on in response to events. Clear ownership, regular review of both technical and procedural controls, and a culture where security is understood and supported across the business remain the foundation of resilient cybersecurity practice.

News and blog posts
GitLab has disclosed a critical path traversal vulnerability, CVE-2026-85706,...
A new wave of ClickFix attacks has been targeting both macOS and Windows users...
Revolut has confirmed a customer data breach that occurred through fake...
Today's brief focuses on vulnerabilities being actively exploited in widely...