📝 Show notes
CyberAware Daily — 2026-09-12
- GitLab has fixed a maximum severity flaw that could let an attacker read files they should not be able to reach, and security teams are already seeing probes against unpatched systems.
- Two alleged members of the TeamPCP group have been arrested in Australia.
- Anthropic says seven China-based AI labs ran industrial-scale attempts to replicate the behaviour of its Claude model, and Claude has also been used to automate break-ins and data theft across several victims.
- Weekend tip: turn on automatic updates everywhere at home, including your router, and check any work software is on the newest version.
More at https://cyberawareuk.co.uk
📄 Full transcript
It's Saturday, so we're keeping it short.
One thing to watch, one thing to do.
What's the thing to watch?
GIT Lab, the tool lots of companies use to store their code, has patched a floor rated 10 out of 10.
The worst kind.
10 out of 10 meaning what, exactly?
It means someone who shouldn't be able to could read files off a server they've got no business touching.
Security team saw probes against it almost as soon as the patch went out.
So who does that actually affect?
My cousin runs a small web agency, and they use GIT Lab.
Then your cousin wants to check today whether they're on a version that's been fixed.
If they're not, they update.
Simple as that.
Any sign real damage has been done yet.
Just probing so far, as far as we know.
But probes are how it starts.
People go looking for the unlocked doors first.
Fair.
There was other news this week too, wasn't there?
Arrests.
Two alleged members of a group called Team PCP were arrested over in Australia.
An anthropic says seven China-based AI labs were running industrial-scale attempts to copy the behavior of its Claude model.
Copying how it behaves.
Effectively teaching their own systems using Claude's outputs at a scale that's well past normal.
And separately, Claude was used to automate break-ins and data theft across several victims.
That last one is the bit that should worry people, isn't it?
The automating.
It is.
The tools attackers use are getting faster.
The things that protect you haven't changed though.
Which brings us to the tip.
It does.
If you run anything at work, anything on a server, anything that other people rely on, you've got patching to do this weekend.
And if I am just a normal person with a laptop?
Then you turn on automatic updates on everything, and you don't put it off.
Home router included.
The router.
Nobody ever thinks about the router.
Nobody ever does.
That's the easiest door in the house to leave open.
One takeaway before we go.
This weekend, spend 10 minutes switching on automatic updates on every device in your home and checking your work software is on the latest version.
That's it.