I spent part of Sunday reading a threat intel report where the attacker’s whole workflow was: get flagged, ask the AI to fix it, redeploy, repeat.[4] That is the story that stuck with me this weekend, but it was not the only one. GitLab shipped a CVSS 10 that attackers found in about a day.[1] ConnectWise’s remote support tool got turned into something that spreads itself.[7] Different layers, same weekend, same lesson: the patch calendar keeps losing ground to the exploit calendar.
GitLab’s path traversal: patched Thursday, probed Friday
GitLab pushed patches for CVE-2026-85706 on Thursday, a path traversal bug in the repository commits API, CVSS 10.0. One HTTP request, no authentication, and an attacker can read arbitrary files off a self-managed GitLab server.[1] CISA added it to the Known Exploited Vulnerabilities catalog the same day GitLab disclosed it, which tells you how fast this one moved from “patched” to “confirmed under attack."[2]
Attack surface management firm watchTowr said it was already seeing in-the-wild probes on Friday, one day after public disclosure.[3][1] Their advice: check GitLab logs for POST requests to /api/v4/projects/{id}/repository/commits/ carrying a file.path parameter. That is the signature of someone trying it.
This is the second critical GitLab bug in recent weeks, following a GraphQL code injection flaw that got hit almost as fast after its own disclosure.[1] If your team runs self-managed GitLab and hasn’t patched to 19.1.8, 19.2.6, or 19.3.2, that is priority one this week, not a backlog ticket.[1] A source-control server that leaks arbitrary files means CI/CD secrets, credentials, and a foothold in whatever your pipeline touches downstream.[1]
ScreenConnect turned into a worm
ConnectWise shipped a fix Tuesday for CVE-2026-84869 in its ScreenConnect remote support software, CVSS 9.9. Huntress had already been tracking exploitation since August 20: rogue ScreenConnect clients that check for active sessions on connected endpoints and push a chain of VBScript files to spread themselves, plus a vulnerable driver used to disable security tooling.[7] CISA added it to the KEV catalog Thursday alongside two JFrog Artifactory flaws.[2]
The part worth sitting with is the propagation mechanism. This isn’t “attacker breaks into one machine.” It’s a compromised ScreenConnect client automatically infecting the next machine it connects to, which is exactly the kind of lateral spread that turns a single phished helpdesk technician into an incident across every client that MSP touches.[7] If you run ScreenConnect, self-hosted or cloud, patch it now and go pull audit logs for RunFiles or RanFiles entries executed from a guest session — that’s the tell Huntress flagged.[7]
Check Point’s own VPN, patched before anyone else found it
Smaller story, worth a line: Check Point patched two critical VPN vulnerabilities in its own gateway and firewall products, CVE-2026-85102 (certificate trust validation failure) and CVE-2026-85103 (a heap overflow in ASN.1 certificate parsing), both CVSS 9.8 and both unauthenticated RCE under the right conditions.[6] Check Point says they found both internally and have no evidence of exploitation.[6] I have no reason to doubt that, and I’d rather report the boring version of a VPN vendor patch than manufacture urgency that isn’t there. Patch it on the normal cycle, not the panic one.
Anthropic: Russian state hackers used Claude to keep rebuilding malware until it passed
The story that actually changed how I think about detection this weekend: Anthropic published a threat intelligence report describing a cyberespionage operation, tradecraft matching the Russian state-nexus group known as Midnight Blizzard, that used Claude to monitor how well its own malware evaded security products. When a tool got flagged, AI agents modified and rebuilt it, then redeployed it, and repeated the loop until it went undetected again.[4][5]
Anthropic’s framing is the part I keep coming back to: this shifts the cost of the detection-evasion cycle onto defenders.[4] It used to cost the attacker time and skill to rewrite malware past a signature update, and now that loop can run unattended, fast, and indefinitely.[4][5] The report says this actor targeted more than 20 organizations, exfiltrated mailboxes from two drone component manufacturers, and stole a proprietary SDK for a drone vision system, reverse-engineering its architecture and supplier list over several days.[4] Anthropic also disrupted a separate group running a fraudulent Claude reseller that harvested customer credentials, and another that used prompt injection against an AI vendor’s own evaluation sandbox to steal production API keys.[4][5]
I don’t have a tidy fix for this one.[unverified] Signature-based detection was already losing ground before an attacker could automate the “get caught, adjust, retry” cycle.[unverified] What I’d actually watch for: this is a reason to weight behavioral and identity-based detection over static signatures a little harder than you already were, and a reason to ask your EDR vendor what happens when the thing evading them iterates faster than their update cycle.[unverified] I don’t know what that answer looks like yet. Neither, I suspect, does anyone else this week.
What I am actually doing Monday morning
- Check whether we run self-managed GitLab. If yes, confirm the patch to 19.1.8 / 19.2.6 / 19.3.2 landed, then hunt commits-API logs for the
file.pathpattern watchTowr flagged.[1][3] - Check whether we run ScreenConnect, self-hosted or cloud. Patch to the fixed build, then pull audit logs for
RunFiles/RanFilesexecuted from a guest session.[7] - Confirm Check Point gateway and management server patches are queued for the normal cycle — no evidence of exploitation, but a 9.8 unauthenticated RCE doesn’t get to wait long regardless.[6]
- Read the Anthropic report in full, not just the headline. The specific TTPs Midnight Blizzard used — automated detection-evasion loops — are worth a conversation with whoever owns your EDR relationship, not just a bookmark.[4][5]
Sources
[1] https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/ — GitLab Vulnerability Exploited One Day After Disclosure [2] https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog — CISA adds GitLab CVE-2026-85706 to KEV [3] https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/ — watchTowr Rapid Reaction: GitLab CVE-2026-85706 [4] https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/ — Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion [5] https://www.anthropic.com/threat-intelligence-report-september-2026 — Anthropic: Detecting and countering misuse of AI, September 2026 [6] https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/ — Check Point Patches Critical VPN Vulnerabilities [7] https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog — CISA adds ConnectWise ScreenConnect + JFrog Artifactory CVEs to KEV