Reporting highlighted a GitLab authentication weakness in which a 2FA login protection bypass could allow attackers to take over accounts, enabling unauthorized access to GitLab instances and the ability to act as legitimate users. With access, an attacker could perform source-code actions such as downloading, altering, or deleting repositories, creating direct risks to software integrity and the SDLC.
Commentary from SANS Institute’s Johannes Ullrich noted that, in practice, attackers may find phishing and other social engineering more efficient for obtaining valid credentials than attempting to forge device credentials to exploit the bypass, but the end-state risk remains the same once passwords are obtained. Recommended defensive measures emphasized layered identity controls: enforce long/unique passwords, monitor for anomalous access patterns (e.g., logins without a corresponding MFA challenge), and ensure an incident response plan is ready if account compromise is suspected.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A news item noted that Ingram Micro stated 42,000 people were impacted by a ransomware attack. No separate event date is given in the reference summary, so the publication date is used.
CSO Online and InfoWorld reported a GitLab two-factor authentication login protection bypass that could let attackers take over user accounts. The references do not provide a more specific disclosure date, so the event is dated from the articles' publication date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.