Devops
Atlassian CVE-2026-21589: Unauthenticated File Read Hits Eight Data Center Products
Atlassian's emergency advisory for CVE-2026-21589, a CVSS 9.3 pre-auth arbitrary file read affecting Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye Data Center.
GitLab AI Gateway CVE-2026-90970: Prompt Template Sandbox Escape Gives Command Execution
GitLab patches CVE-2026-90970, a CVSS 9.9 Jinja2 prompt-template sandbox escape in self-hosted AI Gateway that lets an authenticated Duo Agent Platform user run arbitrary commands on the host.
Accenture Confirms Breach After Threat Actor '888' Lists 35GB of Source Code and Azure Credentials for Sale
A threat actor known as 888 is selling 35GB of alleged Accenture source code, RSA/SSH keys, and Azure access tokens on a cybercrime forum; Accenture has confirmed an incident but not disclosed the access vector.