Gatlab
GATLAB. Security Blog
Security Intelligence

CVE Digest &

Threat Intelligence.

Security research, vulnerability advisories, and threat analysis from the Gatlab Security Team.

30 articles published
Auto CVE digest every Monday
All CVE Threat Intel Tutorial Research Advisory News
Featured
News 26 Apr 2026 · 1m read

Welcome to Gatlab Security Blog

CVE digests, threat intelligence, security tutorials, and research from PT Global Adicita Teknologi. Everything you need to stay ahead of attackers.

Gatlab Security Team Read
Latest
CVE CRITICAL 26 Apr 2026 · 3m read
CVE-2026-6643CVE-2026-6644CVE-2026-5963CVE-2026-5964

CVE Weekly Digest — Week 17, 2026

Top CRITICAL & HIGH CVEs this week: CVE-2026-6643, CVE-2026-6644, CVE-2026-5963 and more.

Gatlab Security Bot Read
News HIGH 24 Apr 2026 · 3m read

CISA Releases 2025 Top Routinely Exploited Vulnerabilities — Key Takeaways

CISA's annual list of most exploited vulnerabilities reveals attackers are consistently targeting known flaws in perimeter devices, VPNs, and web applications. Here's what you need to know.

Gatlab Security Team Read
Advisory CRITICAL 23 Apr 2026 · 3m read
CVE-2023-20198CVE-2023-20273

ADVISORY: Critical Privilege Escalation in Cisco IOS XE Web UI — 50,000 Devices Exposed

Gatlab Security Advisory: Cisco IOS XE management interface vulnerabilities allow unauthenticated attackers to create privileged accounts. Over 50,000 devices remain unpatched and internet-exposed.

Gatlab Security Team Read
Threat Intel HIGH 22 Apr 2026 · 2m read

APT29 Targets European Diplomatic Missions with Novel Spear-Phishing Campaign

Russia's APT29 (Cozy Bear) is conducting a sophisticated spear-phishing campaign against European embassies using wine-tasting event lures and a new malware loader called WINELOADER.

Gatlab Security Team Read
CVE CRITICAL 20 Apr 2026 · 2m read
CVE-2025-0282CVE-2025-0283

CVE-2025-0282: Critical RCE in Ivanti Connect Secure Actively Exploited

A stack-based buffer overflow in Ivanti Connect Secure allows unauthenticated remote code execution. CISA confirms active exploitation in the wild. Patch immediately.

Gatlab Security Team Read
Tutorial INFO 18 Apr 2026 · 3m read

Setting Up Wazuh SIEM: A Complete Beginner's Guide

Step-by-step guide to deploying Wazuh — the open-source SIEM and XDR platform — on a single server, enrolling agents, and writing your first detection rules.

Gatlab Security Team Read
CVE HIGH 15 Apr 2026 · 2m read
CVE-2025-24085

CVE-2025-24085: Apple Core Media Zero-Day Exploited in the Wild

A use-after-free vulnerability in Apple's Core Media framework allows a malicious application to elevate privileges. Apple confirms active exploitation against iOS versions prior to 17.2.

Gatlab Security Team Read
Research HIGH 14 Apr 2026 · 4m read

Modern Browser Memory Corruption: From Bug to Full Compromise

A technical research breakdown of how memory corruption vulnerabilities in browsers are discovered, exploited, and chained to achieve full system compromise in modern web browsers.

Gatlab Security Team Read
News CRITICAL 12 Apr 2026 · 3m read

Major Healthcare Provider Breach: 10M Patient Records Exposed via Unpatched VPN

A healthcare provider suffered a massive data breach affecting 10 million patients after attackers exploited an unpatched Ivanti VPN vulnerability. HIPAA violations expected, $50M+ in fines projected.

Gatlab Security Team Read
Advisory HIGH 10 Apr 2026 · 3m read
CVE-2024-28000CVE-2024-31210

ADVISORY: Mass Exploitation of WordPress Plugins — 1M+ Sites at Risk

Multiple critical vulnerabilities in popular WordPress plugins are being mass-exploited by automated bots. Sites running LiteSpeed Cache, Elementor Pro, and WP Fastest Cache should update immediately.

Gatlab Security Team Read
Threat Intel CRITICAL 8 Apr 2026 · 2m read

BlackCat/ALPHV Ransomware: Technical Deep Dive and Defense Strategies

A comprehensive technical analysis of the BlackCat/ALPHV ransomware-as-a-service operation, including TTPs, encryption mechanisms, and effective defensive countermeasures.

Gatlab Security Team Read
Tutorial INFO 5 Apr 2026 · 3m read

Burp Suite for Web Pentesting: From Zero to First Finding

A hands-on introduction to Burp Suite Community Edition — setting up your proxy, intercepting requests, using Repeater, and finding your first web vulnerability.

Gatlab Security Team Read
Research CRITICAL 1 Apr 2026 · 4m read
CVE-2024-3094

Supply Chain Attacks in Open Source: Anatomy of the xz-utils Backdoor

A deep technical analysis of the XZ Utils backdoor (CVE-2024-3094) — how a sophisticated 2-year social engineering campaign nearly compromised most Linux systems globally.

Gatlab Security Team Read
News INFO 30 Mar 2026 · 3m read

BSSN Launches Indonesia National Cyber Drill 2026: What Organizations Need to Know

Indonesia's national cybersecurity agency BSSN is conducting its largest-ever cyber drill involving 300+ government agencies and critical infrastructure operators. Preparation guide and key dates inside.

Gatlab Security Team Read
CVE CRITICAL 28 Mar 2026 · 2m read
CVE-2024-55591

CVE-2024-55591: Fortinet FortiGate Auth Bypass — Mass Exploitation Underway

An authentication bypass vulnerability in Fortinet FortiOS management interface allows attackers to gain super-admin privileges. Over 15,000 firewalls confirmed compromised globally.

Gatlab Security Team Read
Advisory CRITICAL 25 Mar 2026 · 3m read
CVE-2024-38812CVE-2024-38813

ADVISORY: VMware vCenter Critical RCE — Patch Your Virtualization Infrastructure Now

Critical unauthenticated remote code execution vulnerabilities in VMware vCenter Server are being exploited by ransomware groups to compromise entire virtualized infrastructures.

Gatlab Security Team Read
Tutorial INFO 22 Mar 2026 · 3m read

Writing YARA Rules for Malware Detection: A Practical Guide

Learn to write effective YARA rules from scratch — from basic string matching to advanced conditions, byte patterns, and PE module usage for detecting malware families.

Gatlab Security Team Read
Threat Intel CRITICAL 20 Mar 2026 · 3m read

Lazarus Group's $1.5B Cryptocurrency Exchange Heist: A Full Post-Mortem

North Korea's Lazarus Group executed the largest cryptocurrency theft in history by compromising a developer's machine via a fake job interview. We break down the full attack chain.

Gatlab Security Team Read
Research HIGH 15 Mar 2026 · 3m read

AI-Powered Phishing: How LLMs Are Transforming Social Engineering Attacks

Research findings on how threat actors leverage large language models to generate hyper-personalized phishing emails, bypass spam filters, and scale spear-phishing attacks previously requiring manual effort.

Gatlab Security Team Read
Advisory CRITICAL 12 Mar 2026 · 3m read
CVE-2024-3400

ADVISORY: Palo Alto Networks GlobalProtect Command Injection — Unauthenticated RCE

A command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect gateway enables unauthenticated remote code execution. CISA confirms active exploitation by state-sponsored actors.

Gatlab Security Team Read
CVE CRITICAL 10 Mar 2026 · 2m read
CVE-2025-21298

CVE-2025-21298: Windows OLE Zero-Click RCE via Email — Patch Now

A critical zero-click vulnerability in Windows OLE allows remote code execution simply by previewing a malicious email in Outlook. No user interaction required.

Gatlab Security Team Read
Tutorial INFO 8 Mar 2026 · 4m read

Network Traffic Analysis with Wireshark: Blue Team Essentials

Master Wireshark for security analysis — capture filters, display filters, following streams, detecting port scans, and identifying C2 traffic in network captures.

Gatlab Security Team Read
Threat Intel CRITICAL 5 Mar 2026 · 2m read

Salt Typhoon: Inside the Largest Telecom Espionage Campaign in US History

Chinese APT Salt Typhoon breached at least 9 major US telecommunications providers, accessing wiretap systems and senior officials' communications. A deep dive into the TTPs and geopolitical implications.

Gatlab Security Team Read
Research MEDIUM 28 Feb 2026 · 4m read

DNS Tunneling for C2: Detection and Mitigation Deep Dive

A technical examination of how attackers use DNS as a covert command-and-control channel, the encoding techniques employed, and proven detection methods for defenders.

Gatlab Security Team Read
News INFO 25 Feb 2026 · 4m read

EU NIS2 Directive Now Fully Enforceable: What Global Organizations Must Do

The EU's NIS2 Directive entered full enforcement in 2025 with penalties of up to €10M or 2% of global revenue. We break down who's covered, what's required, and how to comply.

Gatlab Security Team Read
Advisory CRITICAL 20 Feb 2026 · 3m read
CVE-2024-6387

ADVISORY: regreSSHion — Critical OpenSSH RCE Returns After 18 Years

CVE-2024-6387 (regreSSHion) is a race condition in OpenSSH's signal handler that allows unauthenticated remote code execution as root. Affects 14 million internet-exposed servers.

Gatlab Security Team Read
Threat Intel HIGH 18 Feb 2026 · 3m read

Volt Typhoon: Chinese APT Pre-Positioning in US Critical Infrastructure

CISA, NSA, and FBI jointly warn that Volt Typhoon has maintained persistent access to US critical infrastructure for 5+ years, pre-positioning for potential disruption during geopolitical conflict.

Gatlab Security Team Read
Tutorial INFO 15 Feb 2026 · 3m read

Build a Cybersecurity Home Lab in 2026: Complete Setup Guide

Everything you need to build a professional-grade security home lab for under $0 — using free virtualization, vulnerable VMs, and open-source security tools to practice real-world skills.

Gatlab Security Team Read
Research MEDIUM 10 Feb 2026 · 4m read

IoT Firmware Security Analysis: Finding Vulnerabilities in Embedded Devices

A practical guide to IoT firmware analysis — extracting firmware, emulating with QEMU, finding hardcoded credentials, and identifying vulnerable services using open-source tools.

Gatlab Security Team Read