Critical VPN and GitLab Flaws Under Active Attack Plus New Phishing Campaign Steals Passwords

by The Creator | Sep 12, 2026

A new phishing campaign using Windows mshta.exe is actively stealing credentials and sensitive data from small businesses. This phishing training response requires immediate staff education, attachment controls, and multi-factor authentication across your organization.

Three urgent security threats require immediate action from small business owners today:

1. Check Point VPN Critical Vulnerabilities: The Dutch National Cyber Security Centre (NCSC) warns that exploitation of two critical flaws (CVE-2026-85102 and CVE-2026-85103) in Check Point VPN products is imminent. These vulnerabilities allow attackers to breach networks without credentials. Businesses using Check Point VPN must apply patches immediately.

2. GitLab Critical Vulnerability (CVE-2026-85706): CISA has added a critical GitLab flaw to its Known Exploited Vulnerabilities catalog. With a severity score of 10.0/10.0, this path traversal vulnerability is being actively exploited in attacks. It affects both GitLab Community Edition and Enterprise Edition, allowing attackers to access sensitive files including passwords, keys, and configuration data. Organizations running internet-accessible GitLab instances must update to the latest version immediately.

3. Active Phishing Campaign Using Windows Mshta.exe: A new phishing campaign active since June 2026 abuses the legitimate Windows utility mshta.exe to steal credentials and sensitive data. Attackers send malicious HTML Application (HTA) files disguised as documents. Because the attack uses a built-in Windows tool, it often evades antivirus detection. Operators regularly recompile malware samples to maintain effectiveness.

Recommended Actions: - Check Point VPN users: Install latest security updates immediately - GitLab users: Update to latest version, especially for internet-facing instances - All businesses: Train employees on phishing recognition, never open unexpected attachments, enable multi-factor authentication on all accounts

Why phishing training response matters after the mshta.exe campaign

The current mshta.exe phishing attack exploits a legitimate Windows utility to evade antivirus detection, meaning your standard email filters may miss it. Attackers disguise malicious HTML Application files as ordinary documents, relying on employee clicks to succeed. CISA and security researchers track this campaign since June 2026. Your phishing training response must include: recognizing unexpected attachments from unfamiliar senders, never executing HTA or HTML files from email, and immediate reporting of suspicious messages. Enable multi-factor authentication on all accounts, especially email and administrative tools. This single control stops credential theft from becoming a full breach, even if phishing succeeds.

Key takeaways

  • Block or disable mshta.exe execution via Group Policy or endpoint controls to prevent HTA file abuse.
  • Train staff to reject unexpected attachments and verify sender identity through a separate communication channel before opening files.
  • Enable MFA on email, cloud services, and VPN accounts to contain damage if phishing captures credentials.
  • Update Check Point VPN and GitLab immediately if your company uses these products; both have critical flaws under active attack.

Frequently asked questions

How does mshta.exe phishing differ from standard phishing attacks?

Mshta.exe is a built-in Windows utility that runs HTML Application files. Attackers abuse it because antivirus software often trusts native Windows tools. The attack file looks like a normal document attachment but executes malicious code when opened, stealing login credentials and data without triggering traditional security alerts.

What should I do if an employee clicked a suspicious attachment?

Assume the device is compromised. Force a password reset for that employee across all systems, enable MFA immediately, and monitor for unauthorized access to email, cloud storage, and sensitive files. Run malware scans on the device and consider replacing it if the employee has administrative access. Check CISA alerts for indicators of compromise specific to this campaign.

Does phishing training alone stop these attacks?

No. Training reduces risk but cannot stop all attacks. Combine training with technical controls: disable mshta.exe, block executable attachments, enforce MFA, and use email filtering rules to flag unexpected file types. Layered defenses catch what human judgment misses.

How often should we train staff on phishing recognition?

Conduct formal training at least quarterly, with monthly reminders or simulated phishing exercises. When active campaigns like this one emerge, send immediate alerts to staff with specific indicators to watch for. Continuous reinforcement is more effective than annual training.

Keep reading