GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
We haven't written up this one. Dark Reading has the full story — the link below goes straight to it.