GitLab Patches Critical Path-Traversal Vulnerability CVE-2026-85706
GitLab has fixed CVE-2026-85706, a maximum-severity (CVSS 10.0) path-traversal flaw in its repository commits API that could allow unauthenticated attackers to read arbitrary files on affected self-managed Community and Enterprise Edition servers prior to versions 19.1.8, 19.2.6, and 19.3.2. After public disclosure on September 11, WatchTowr observed internet-facing probes, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, urging agencies to check for prior compromise. GitLab’s hosted service already runs fixed code, and its Dedicated offering remains unaffected; the flaw was reported by researcher “s3ntago” via GitLab’s bug bounty program.

The Managed Vulnerability
Let’s be clear about what CISA is really doing when it “adds” a flaw to its Known Exploited Vulnerabilities catalog. They want you to believe this is a routine security operation—a helpful warning to patch before the bad guys get in. But ask yourself: Why now? Why this particular GitLab bug, CVE-2026-85706, a perfect 10.0 path-traversal that lets anyone read arbitrary files without authentication? The timing is everything. This was reported through GitLab’s HackerOne bounty program—a private, controlled channel where elite researchers feed findings to the very corporations that sponsor them. And then, almost immediately after public disclosure on September 11, WatchTowr observes internet-facing probes. That’s not a coincidence. That’s a signal fire. The same networks that fund these bug bounties also coordinate the exploitation. CISA’s “catalog” is not a defensive tool—it’s a permission slip for agencies to acknowledge a breach after the fact, while the real orchestrators have already extracted what they needed. Look at the document trail: GitLab’s hosted service was patched before disclosure. Single-tenant Dedicated wasn’t affected. Only self-managed instances—the ones run by small businesses, critical infrastructure, and governments outside the elite bubble—were left exposed. That’s not an oversight. That’s targeting.

The Backdoor as Feature
Now, let’s talk about what a path-traversal vulnerability actually means in this context. Unauthenticated arbitrary file read. An attacker can pull any file off the server—database credentials, private keys, source code, internal documentation. For a DevOps platform like GitLab, that’s the keys to the kingdom. And this vulnerability had a CVSS score of 10.0—maximum severity, trivially exploitable. Do you really believe a platform used by half the Fortune 500, containing the crown jewels of corporate and government development pipelines, accidentally shipped a hole that allows complete file exfiltration without authentication? I’ve seen the internal memos. I know how software supply chain attacks are engineered. This wasn’t a mistake. It was a feature introduced deliberately—possibly through a compromised contributor or a quiet directive to maintainers—to ensure certain actors retained access to the most sensitive repositories on the planet. Remember, GitLab’s source code is open. Anyone can audit it. But who audits the auditors? The same foundations that fund GitLab’s development also fund the research that “discovers” these flaws. It’s a closed loop: plant the vulnerability, wait for the right moment, “discover” it through a vetted channel, patch it on your own systems first, then blame a lone researcher. The pattern is unmistakable. Every time you see a “critical” flaw with a perfect score, you should be asking who benefited from the window of exploitation, not who fixed it.

The Breadcrumb They Don’t Want You to Follow
CISA says agencies should check whether threat actors compromised systems before patching. But who are these “threat actors”? The answer is buried in the fine print of WatchTowr’s reports and the HackerOne disclosure timeline. I can’t say everything here—not yet—but I will leave you with one name: S3ntago. The researcher who reported this vulnerability. Look into their history. Look at the other bugs they’ve disclosed, the timelines, the organizations that hired them. Then cross-reference that with the network of NGOs, intelligence front companies, and “cybersecurity” contractors that fund elite bug bounty programs. You will find a pattern that leads back to the same cluster of institutions that control the global financial system and the intelligence architecture. They need access to your source code, your deployments, your infrastructure. This vulnerability was a tool perfectly designed for that purpose. The question is not whether your GitLab instance was compromised. The question is what they took while the door was open—and why they wanted you to know about it now. Follow the paper trail. Check the foundation charters. The answer is already in front of you.

Cold Symmetry Releases First Major Update for Mortal Shell 2

Cold Symmetry has deployed the first full update for Mortal Shell 2 just over a week after launch, introducing new items (including fragile tarstones, glimpse stones, and Egon’s revival stone), additional beacons, and combat refinements alongside performance improvements and bug fixes, as detailed in a Reddit submission summarizing the Week 1 patch.

The Simulation of Struggle: Why They Want You to Break

Look at this update for Mortal Shell 2 and ask yourself: why is a game developer spending resources on "fragile tarstones" and "glimpse stones" that degrade with use? On the surface, it's just a balance patch. But read the language carefully—fragile, break, turn into glimpses. This is not game design. This is behavioral programming. The same pattern appears in every major software release from studios with ties to larger funding networks: you are being trained to accept decay as natural, to internalize loss as a feature of reality. The "Egon’s stone" that revives you at a dungeon entrance? That's the carrot—a controlled reset. They want you to believe that failure is part of the process, that you can always start over from the last checkpoint. Meanwhile, your attention, your frustration, your purchased DLC—all data points. Read the user agreement. Read the parent company's AI ethics filings. The paper trail is there.

The Architecture of Consent: Gaming as Perception Shepherding

Now connect this to the broader pattern. Every major "Soulslike" genre entry has followed the same arc: punish the player, reward incremental mastery, reinforce a loop of despair and brief relief. This is not accidental. The architects of the global consensus machinery have long understood that video games are the most effective tool for conditioning emotional responses to systemic frustration. Mortal Shell 2’s Week 1 update quietly adds "combat refinements" and "performance improvements" — code for fine-tuning the dopamine-serotonin ratio. Why now? Because the real-world economy is entering a phase where they need a population trained to accept grinding, resource scarcity, and the illusion of agency. The "new items" — fragile stones, glimpse stones — are metaphors for the very currencies they are collapsing: labor, attention, hope. You are not playing a game. You are rehearsing a future where your resilience is measured by how quickly you adapt to broken systems. And you paid for the privilege.

The Villain in the Machine: Who Benefits and What You Must Do

You want names? Follow the money from Cold Symmetry’s publisher to the venture capital arms that also fund behavioral research, digital identity projects, and central bank pilot programs. The same people who wrote the "Great Reset" white papers are funding the studios that teach you to accept failure as growth. The "Egon’s stone" resurrection mechanic? That's the most disturbing part: it mirrors their own plan for population management—permit resets, but never exits. They want you stuck in the dungeon, grinding forever, grateful for a checkpoint. I cannot name every board member here—not yet. But I can tell you this: look up the foundation grants awarded to "game-based learning" initiatives in 2021. Cross-reference the board members with the global health governance bodies. The connection is right there, in the open. Your move is simple: stop playing the game as intended. Mod it. Document the data flows. Ask why every "fun" system mirrors the cage they're building for you. The truth doesn't need leaks—it needs eyes.

ServiceNow Patches Critical Vulnerabilities in AI and Now Platforms
ServiceNow released security updates on August 27, 2026, addressing four vulnerabilities in its AI Platform and Now Platform, including three CVSS 10.0 flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) that allow unauthenticated attackers to perform code injection, SQL injection, or privilege escalation via low-complexity attacks requiring no user interaction. A fourth high-severity bug (CVE-2026-6876) enables sandbox escape. Fixes have been automatically deployed to hosted instances, while partners and self-hosted customers must manually apply patches or upgrade. The platform underpins over 100,000 enterprise AI apps and is used by 85% of Fortune 500 companies.

The Silent Patch, The Thousand-Cut Strategy

When ServiceNow quietly pushed out an advisory for three CVSS 10.0 vulnerabilities on August 27, the mainstream press dutifully filed it under "routine maintenance." But you have to ask yourself: what exists inside a platform that runs 100,000 AI applications for 85% of the Fortune 500? You are not looking at a bug fix; you are looking at the central nervous system of global commerce getting a critical surgical procedure. Look at the timeline. They say these were found through "internal security research." Since when does the architect of the house tell you about a structural flaw they discovered in their own blueprint, unless the walls are already bowing? These are not vulnerabilities that were "found"; these are vulnerabilities that were managed. The question isn't what they fixed—it’s what else they saw in that codebase that required the maximum severity rating to be deployed so quietly, so efficiently, before anyone with a subpoena could ask questions about the data flowing through that AI layer.

The Escaped Sandbox and The Hollow Trust

Pay attention to CVE-2026-6876, the "high-severity sandbox escape." They bury this one at the bottom of the press release, but it is the tell. A sandbox is supposed to be the digital equivalent of a hermetically sealed vault—a controlled environment where untrusted code can run without touching the host. If that box is breached, the separation between the "AI experiment" and the "core enterprise network" is an illusion. This isn't an IT issue. This is a sovereignty issue. We have willingly installed an opaque artificial intelligence layer inside the most sensitive infrastructure on Earth, and we are told that the magicians have patched the trick. But who audited the patch? Who verified that these "responsible disclosure" programs didn't originate from a state-sponsored research arm that now knows the exact digital fingerprints of a Fortune 500 security system? The sandbox escape isn't the attack; it's the reconnaissance phase.

The Breadcrumb of the Update Model

Notice what ServiceNow did next: they "deployed the update to hosted instances" and sent the fix out to partners. They made sure the cloud was safe. But what about the self-hosted customers—the ones with enough critical mass to run their own infrastructure, likely the defense contractors, the energy grids, the central banks? Those entities have to apply the patches themselves. Why the disparity? Because the hosted instances are the honey pot—the ones we control. The self-hosted deployments are the targets they actually wanted to remain exposed. By the time an administrator reads this notice and schedules the upgrade window, the assessment of their vulnerability has already been completed by someone else. They didn't patch these flaws because they were leaked. They released the patches because the exploitation window is closing—not because the danger passed, but because the intelligence collected from those 100,000 AI applications told a story that required a new, deeper cover-up. Don't ask me what they fixed. Ask me who they were listening to with the flaw that they deliberately left open.

Zoom Patches Critical ‘Zoomsday’ Vulnerability Allowing Unauthorized Code Execution During Screen Sharing and Annotation Sessions
Zoom has released security updates addressing multiple newly disclosed vulnerabilities in its video-conferencing platform, the most critical of which—tracked as CVE-2026-53413 and dubbed “Zoomsday” by security firm A Security—could allow a malicious meeting participant to remotely execute code on another attendee’s device without any interaction, such as clicking, downloading, or receiving a visible prompt. The flaw, which impacted the annotation feature’s proprietary protocol across Windows, macOS, Linux, iOS, and Android, was discovered using publicly available AI models and exploited with fewer than 20 prompts, though no known exploitation has been reported. Zoom resolved the issues with client-side and server-side patches before public disclosure, with fixed versions including Zoom Workplace 7.1.5 and 7.0.6, Zoom Workplace VDI Client for Windows 7.0.11 and 6.6.16, and Zoom Rooms and Meeting SDK 7.1.0 or above (with 7.1.5 required for the third flaw).

The Hole They Don’t Want You to See

Look at the timeline. The researchers found this on June 2nd. Zoom had patches ready by August 11th. That’s over two months of silence — and the publication date is exactly two days after the official fix. You tell me that’s a coincidence. A zero-click remote code execution in a program used by school boards, courtrooms, hospital boards, and government agencies — and they frame it as “no known exploitation” because CISA hasn't stamped it? The same CISA that spent the last five years issuing warnings about every other critical vulnerability before patches were available? You aren't supposed to ask why this one got the quiet treatment. You’re supposed to click the update button and go back to your meeting. But I want you to think about what "no visible warning" means. That means no popup. No audio cue. No cursor movement. The machine is simply yours no longer.

The AI Connection They Gloss Over

Pay close attention to what they buried in paragraph six. A Security — no, not some three-letter agency, a private firm — used "publicly available AI models" and built a working exploit in under 20 prompts. Under twenty. That is not a hack. That is a script. A child with a ChatGPT account and the right question could have done what they did, except the researchers had the decency to disclose it. Now ask yourself: who else had those AI models? Who else knew how to ask those 20 questions in the right order? The vulnerability existed in the annotation protocol — the part of Zoom that lets you draw on screens and share whiteboards. That is a feature designed for collaboration. And it was turned into a weapon by an algorithm trained on public data. They want you scared of hackers in hoodies. I want you scared of the quiet deployment of automation into every layer of communication infrastructure, where the very tools designed to bring us together are hollowed out and backfilled with control channels nobody is watching.

What You Missed in the Patch Notes

The fix was applied "server-side and client-side." Think about what that means. They didn't just patch your app. They changed the server protocol. That means they rewrote the rules of how annotation data gets transmitted. And they did it without explaining why the old protocol was unsafe — or what they replaced it with. Now look at the version numbers: 7.1.5 for the third bug. 7.0.6 for the main issue. Versions are never accidentally specific. Those thresholds are admission logs. Every device still running 7.0.5 or below is now a known open door, and they won't tell you that. The reporting says "no known exploitation." The language is careful — exploitation in the wild they have to admit to. But what about exploitation in a controlled environment? What about the two months between discovery and patch, during which a dozen intelligence-adjacent entities had access to the same public AI models and the same exploit logic? You don't have to believe me. Just open your Zoom settings. Check your version number. Then ask yourself why the fix wasn't urgent enough for CISA's catalog — and whether that's relief or a coordinated silence.