Neural Newscast
Neural Newscast
Neural Newscast
GitLab Deletion Risk and CISA Ray AI Framework Alert [Prime Cyber Insights]
4 minutes Posted Aug 18, 2026 at 1:23 pm.
Introduction
GitLab Project Deletion Flaw
Ray AI Framework Exploitation
Conclusion
Android Kernel Attacks via Unisoc
0:00
4:18
Download MP3
Show notes
GitLab has issued an emergency security update to address a critical GraphQL vulnerability, CVE-2026-19478, which allows unauthenticated attackers to remotely modify or delete public projects and user data. Rated at a CVSS score of 9.4, this flaw affects self-managed Community and Enterprise Edition installations and requires immediate patching. In tandem, CISA has added a critical vulnerability in the Ray AI and machine learning framework, CVE-2025-62593, to its Known Exploited Vulnerabilities catalog. The Ray flaw involves a DNS rebinding attack that triggers remote code execution, which has been leveraged by threat actors in the ShadowRay 2.0 campaign to turn GPU clusters into cryptocurrency mining botnets. Furthermore, researchers have demonstrated a dangerous two-stage attack chain involving Unisoc T612 modems, where a malicious video call can lead to privileged Android kernel access across multiple smartphone brands including Realme and Motorola.