Rails Patches Critical Active Storage Flaw That Lets Unauthenticated Attackers Read Secrets and Escalate to RCE
CVE-2026-66066 lets attackers upload a crafted image to steal a Rails app's secret_key_base and escalate to remote code execution.
Signal
197 articles covering "cybersecurity"
CVE-2026-66066 lets attackers upload a crafted image to steal a Rails app's secret_key_base and escalate to remote code execution.
SQLite's own CVE tracker and the National Vulnerability Database both rejected six reports as AI-hallucinated after a JFrog researcher found the underlying code and PoCs didn't exist or didn't work.
CISA added a Cisco Firewall Management Center static-credential flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch by August 1.
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
A critical Gitea vulnerability lets a repository writer convert a crafted patch into a live Git hook and run shell commands as the service account.
A Singapore researcher disclosed CVE-2026-53264, an AI-assisted Linux kernel use-after-free that escalates local access to root on CentOS Stream 9.
JetBrains fixed CVE-2026-63077, a 9.8-severity flaw letting unauthenticated attackers run OS commands on TeamCity servers via the agent polling protocol.
An unauthenticated API flaw in the Pope's official prayer app exposed names, emails, and birth dates of over 719,000 users for six months before a fix.
AnMed shut most of its clinics after a malware disruption hit its network; emergency rooms stayed open and physician offices began reopening Tuesday.
Researchers found 24,650 of 36,872 exposed server management interfaces disclose crackable password hashes before login, via a 2013 IPMI flaw still unpatched by Dell.
JFrog researchers turned a 16-year-old FFmpeg decoder bug, CVE-2026-8461, into working remote-code-execution exploits against Jellyfin and Nextcloud using one 50 KB video file.
Arista patched a maximum-severity command injection flaw in VeloCloud Orchestrator that attackers were already exploiting; CISA gave federal agencies until July 30 to fix it.