← Back to feed
general GBHackers

GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs

GBHackers • • GitLab

A long-lived GitLab incoming email token embedded in project email addresses for the “Email work item” feature can be exploited to push attacker-controlled c...

Read the full story GBHackers →

Related Coverage

general Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM Privileges GBHackers · Oct 10 general AWS Bedrock AgentCore Flaw Allowed Attackers to Hijack AI Agents Using a Single Prompt GBHackers · Oct 10 general Co-creator of Empire Market dark web marketplace given 40-year sentence The Record · Oct 10