








I hope is clear when CISA is reporting a "Known Exploited Vulnerability" that if you have the application exposed on the internet you are already compromised. Many of the alerts are for exploits present for years.
Critical GitLab Bug Under Exploit Enables Account Takeover, CISA Warns: https://t.co/VdPd3YxYcE by darkreading #infosec #cybersecurity #technology #news
A critical @gitlab vulnerability that could enable account takeover was added to the @CISAgov Known Exploited Vulnerabilities (KEV) Catalog. #cybersecurity #infosec #ITsecurity https://t.co/hWlRdJyBeO

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability in GitLab that is currently being actively exploited. The flaw, identified as CVE-2023-7028, allows attackers to take over accounts by sending password reset emails to unverified addresses. This vulnerability has led to the compromise of approximately 1,400 GitLab servers. CISA has urged users to update to the latest patched versions immediately to mitigate the risk. The issue has also been added to CISA's Known Exploited Vulnerabilities catalog, emphasizing the urgency and severity of the threat.