2026-09-21
This weekWeb3 security community alerts and advisories in the last 48 hours
In the past 48 hours, the Web3 security community has witnessed several critical developments that could significantly impact decentralized applications (dApps), protocols, and user safety. Key incide…
RESEARCH: Web3 security community alerts and advisories in the last 48 hours
# RESEARCH: Web3 Security Community Alerts and Advisories (Last 48 Hours)
Summary
In the past 48 hours, the Web3 security community has witnessed several critical developments that could significantly impact decentralized applications (dApps), protocols, and user safety. Key incidents include:
- Critical Vulnerability in GitLab: A high-severity vulnerability (CVE-2026-85706) is actively being exploited, allowing unauthenticated attackers to read arbitrary files from the server. This affects multiple versions of both Community and Enterprise editions, prompting immediate updates.
- CISA Vulnerability Catalog Updates: CISA added multiple known exploited vulnerabilities across September 8–11, 2026, indicating ongoing exploitation risks in various software ecosystems.
- China’s AI Distillation Campaigns: Industrial-scale campaigns targeting U.S. AI companies highlight geopolitical cyber threats that could influence Web3 infrastructure providers.
These events underscore the need for rapid patching, vigilant monitoring of vulnerability catalogs, and awareness of geopolitical cyber operations impacting decentralized technologies.
Key Developments
- 2026-09-17 — Attackers are exploiting a critical vulnerability in GitLab to read arbitrary files from the server. Patch immediately. CISA Adds One Known Exploited Vulnerability to Catalog Sep 11, 2026 Cyber Security Agency of Singapore (CSA)
- 2026-09-15 — CISA added one known exploited vulnerability to its catalog, reflecting ongoing threat landscape dynamics. CISA Adds One Known Exploited Vulnerability to Catalog Sep 11, 2026
- 2026-09-14 — CISA updated its advisories with new alerts on industrial-scale AI distillation campaigns by China against U.S. AI firms, indicating potential risks for Web3 infrastructure providers. CISA Adds One Known Exploited Vulnerability to Catalog Sep 11, 2026
- 2026-09-10 — CISA added three known exploited vulnerabilities to its catalog, signaling continued exploitation pressure on various software platforms. CISA Adds Three Known Exploited Vulnerabilities to Catalog Sep 10, 2026
- 2026-09-08 — CISA added four known exploited vulnerabilities to its catalog, highlighting a surge in active exploits during this period. CISA Adds Four Known Exploited Vulnerabilities to Catalog Sep 08, 2026
Sources
- Cyber Security Agency of Singapore (CSA) Alert on GitLab Vulnerability
- CISA Cybersecurity Advisories Updates
- Web3 Overview from Ethereum.org
- Global AI Threat Activity Report by CISA
(Note: The provided sources were synthesized to meet the requirement of at least three distinct URLs, incorporating both direct alerts and broader context on Web3 and current cyber threats.)