- Microsoft SharePoint remote code execution vulnerability
- Windows Task Host privilege escalation vulnerability
ThreatNoir Afternoon Brief — August 18
Afternoon Review in IT Security — August 18, 2026
The threat landscape continues to evolve with critical vulnerabilities emerging across multiple platforms and frameworks. Today's security briefing covers active exploitation campaigns targeting Windows systems, GitLab infrastructure, distributed computing frameworks, and open-source package repositories, underscoring the persistent risk to organizations across diverse technology stacks.
CISA: Windows Task Host Flaw Now Exploited by Ransomware Gangs
The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware gangs are actively exploiting a high-severity Windows Task Host vulnerability that was previously flagged as exploited in April. The vulnerability, tracked as CVE-2025-60710 and CVE-2026-45659, represents a significant privilege escalation vector that threat actors have incorporated into their operational toolkit. Source: CISA: Windows Task Host flaw now exploited by ransomware gangs
Organizations running unpatched Windows systems remain at elevated risk, as ransomware operators continue to leverage this flaw as part of their attack chains. The active exploitation by multiple criminal groups highlights the critical importance of timely patching and vulnerability management in enterprise environments.
GitLab Patches Critical Code Injection Vulnerability
GitLab has released patches addressing a critical code injection vulnerability that poses significant risk to organizations relying on the platform. Source: GitLab Patches Critical Code Injection Vulnerability
The vulnerability, identified as CVE-2026-19478 and CVE-2026-19650, permits unauthenticated attackers to modify or delete user data and public projects. This supply-chain risk is particularly concerning given GitLab's role as a central repository for development workflows across numerous organizations. Immediate patching is recommended to prevent unauthorized data manipulation and project compromise.
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical vulnerability affecting Ray to its Known Exploited Vulnerabilities catalog following evidence of active exploitation in the wild. Source: CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Ray, an open-source Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads, is affected by CVE-2025-62593, which enables browser-based remote code execution. The vulnerability's impact on AI and machine learning infrastructure represents an emerging threat vector as organizations increasingly adopt these frameworks for production workloads. Developers and organizations utilizing Ray should prioritize remediation efforts immediately.
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have identified a coordinated typosquatting campaign targeting RubyGems users with malicious packages designed to harvest sensitive information. Source: 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
OpenSourceMalware discovered the activity on August 15, 2026, tracking the threat under the moniker StubMaker. The campaign leverages a Windows-based information stealer to extract browser credentials and cryptocurrency wallet data from compromised systems. The malware components, including abe_payload.dll and wincfg, communicate with command and control infrastructure at dresslee.com. Developers should exercise caution when installing dependencies and verify package authenticity before integration into projects.
The convergence of these threats across infrastructure, development platforms, and supply-chain vectors underscores the multifaceted nature of modern cybersecurity risks. Organizations must maintain vigilant patch management, implement robust dependency verification processes, and monitor for exploitation attempts across their technology ecosystems.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Cross-site request forgery (CSRF) vulnerability in GitLab GraphQL multiplex query handler
- Critical code injection vulnerability in GitLab GraphQL directive allowing unauthenticated data modification
- Critical flaw in Ray framework allowing browser-based RCE
- StubMakerMoniker for the malware campaign.
- wincfgGo-based stealer payload.
- abe_payload.dllDLL payload for credential extraction.
dresslee.comDomain used to receive stolen data.