Product
GitLab
- First Reported
- Jul 12, 2026
- Latest Reported
- Oct 5, 2026
Reported Context (3)
- Every confirmed victim was reached through stolen CI/CD secrets. A single compromised GitLab instance produced footholds at two unrelated organisations. CloudSEK Finds Gentlemen Ransomware Affiliate’s Exposed Servers and Stolen Data
- Genians Security Center has been continuously tracking GitHub- and GitLab-based attack activity assessed to be associated with Kimsuky, a cyber threat group known to operate under North Korea's Reconnaissance General Kimsuky Uses AI-Generated Decoys and Experiments with Local LLMs
- In the 2025 attacks, GitHub and Bitbucket were used. However, in the 2026 attacks, we confirmed that GitLab, jsDelivr, and Codeberg, in addition to GitHub, were abused as attack infrastructure. JPCERT Details APT-C-60 Attacks Using SpyGlace in 2026
Malware (2)
People (2)
Threat Actors (5)
MITRE ATT&CK (25)
Vendors (1)
Products (19)
Tools (29)
Industries (12)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.