STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 23 August 2026 · 24h windowRISKHIGH
StratQuad CTI Daily Brief, 23 August 2026

Compiled from 52 monitored sources · 140 articles reviewed

Today’s Briefing

CVE-2026-19478 in GitLab is under active exploitation, allowing unauthenticated attackers to remotely modify or delete public projects via a GraphQL flaw rated 9.4 CVSS; GitLab issued an emergency patch this week and WatchTowr confirmed live abuse. Separately, two Android supply chain campaigns are running in parallel: ToxicPanda 2.0 now targets 349 financial institutions across 16 countries and abuses Android Wireless Debugging for credential theft, while a separate operation is infecting aftermarket car head units via a compromised legitimate update app to build proxy botnets and conduct ad fraud. The car head unit campaign was documented by Kaspersky and affects Android-based in-vehicle systems distributed through supply chains serving multiple markets.

Top Stories

  1. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
  2. Hackers infect Android car head units with proxy botnet malware
  3. GitLab Warns of Active Exploitation of Critical GraphQL Flaw

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs