Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
Wiz published a DFIR cheatsheet covering log visibility, incident readiness, and threat hunting across GitHub, GitLab, Bitbucket, and Azure DevOps.
Wiz researchers released a practitioner's guide to version control system forensics, incident response, and threat hunting. The cheatsheet maps log sources, audit capabilities, and hunting workflows across GitHub, GitLab, Bitbucket, and Azure DevOps. It aims to improve incident readiness for source code and CI/CD compromise scenarios.
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Jenkins patched 20 vulnerabilities across 13 plugins, including Groovy sandbox bypasses enabling remote code execution on CI/CD controllers.
Jenkins released security updates on September 16, 2026 for 20 vulnerabilities across 13 plugins, including nine fixes in the Script Security Plugin for Groovy sandbox bypasses. CVE-2026-92127 (classpath abuse) and CVE-2026-92128 (TOCTOU race on remote JAR loading) could allow arbitrary code execution in the controller JVM, exposing build secrets, credentials, and downstream deployment environments. Other flaws include stored XSS in the Warnings, Coverage, OWASP Dependency-Check and Gitee plugins, SSRF in the Gradle and Bitbucket plugins enabling credential capture, credential exposure via CVE-2026-92130, arbitrary file write via CVE-2026-92137, OAuth token theft, and an open redirect in the Keycloak Authentication Plugin. No exploitation is reported; fixes include Script Security Plugin 1422.v06869826dd9b_.
Multiple vulnerabilities in Jenkins plugins
Jenkins releases security fixes for multiple plugins including Bitbucket, GitLab, Gitee, Coverage, and Gradle integrations.
Jenkins published security updates for several plugins, including Bitbucket Push and Pull Request Plugin 4.1.0, Bitbucket Server Integration Plugin 6.0.2, Coverage Plugin 3.3361.v0626103a_67e6, Gitee Plugin 1304.v2702f1d71cde, GitLab Plugin 1.2152.veec0897048b_0, and the Gradle Plugin. The announcement is a routine open-source security release notice without exploit details.
Jenkins Security Advisory 2026-09-16
Jenkins released a security advisory patching vulnerabilities across 13 plugins, including GitLab, Bitbucket, Gradle, Keycloak Authentication, and Script Security.
The Jenkins security advisory dated September 16, 2026 addresses vulnerabilities in 13 plugins: Bitbucket Push and Pull Request, Bitbucket Server Integration, Coverage, Gitee, GitLab, Gradle, Keycloak Authentication, OWASP Dependency-Check, Pipeline: Groovy Libraries, Pipeline: Multibranch, Robot Framework, Script Security, and Warnings. Jenkins users should update the affected plugins to the patched versions listed in the advisory.