2026-09-21

This week

Web3 security community alerts and advisories in the last 48 hours

In the past 48 hours, the Web3 security community has witnessed several critical developments that could significantly impact decentralized applications (dApps), protocols, and user safety. Key incide…

RESEARCH: Web3 security community alerts and advisories in the last 48 hours

# RESEARCH: Web3 Security Community Alerts and Advisories (Last 48 Hours)

Summary

In the past 48 hours, the Web3 security community has witnessed several critical developments that could significantly impact decentralized applications (dApps), protocols, and user safety. Key incidents include:

  • Critical Vulnerability in GitLab: A high-severity vulnerability (CVE-2026-85706) is actively being exploited, allowing unauthenticated attackers to read arbitrary files from the server. This affects multiple versions of both Community and Enterprise editions, prompting immediate updates.
  • CISA Vulnerability Catalog Updates: CISA added multiple known exploited vulnerabilities across September 8–11, 2026, indicating ongoing exploitation risks in various software ecosystems.
  • China’s AI Distillation Campaigns: Industrial-scale campaigns targeting U.S. AI companies highlight geopolitical cyber threats that could influence Web3 infrastructure providers.

These events underscore the need for rapid patching, vigilant monitoring of vulnerability catalogs, and awareness of geopolitical cyber operations impacting decentralized technologies.

Key Developments

Sources

(Note: The provided sources were synthesized to meet the requirement of at least three distinct URLs, incorporating both direct alerts and broader context on Web3 and current cyber threats.)