ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

GitLab patched a critical path traversal vulnerability (CVE-2026-85706, CVSS 10.0) in its repository commits API that allows unauthenticated file reads. The flaw, which requires at least one public project for exploitation, saw in-the-wild probes within hours of disclosure. GitLab also fixed a critical insecure deserialization bug (CVE-2026-87719, CVSS 9.9) in versions 19.3.2, 19.2.6, and 19.1.8.
Tap to vote and see what everyone thinks.
Summary by ByteBrief