Ruby on Rails Patches Critical Vulnerability
CVE-2026-66066 (CVSS 9.5): Rails Active Storage + libvips flaw allows unauthenticated file reads, exposing environment secrets for RCE. Patched this week—rotate all exposed credentials immediately.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
CVE-2026-66066 (CVSS 9.5): Rails Active Storage + libvips flaw allows unauthenticated file reads, exposing environment secrets for RCE. Patched this week—rotate all exposed credentials immediately.
OpenAI's cheaper GPT-5.6 pricing lets threat actors affordably scale AI-powered phishing at mass scale. The article warns that technology commoditization—like past GPU and cloud compute drops—benefits attackers faster than defenders adapt.
California's DROP platform consolidates deletion requests across data brokers, eliminating the need to contact dozens individually. But brokers can delay removal, and unregistered brokers remain unregulated—a partial solution to decades of legal surveillance.
Chrome shipped 1,442 patches in three releases, far exceeding normal. The surge may reflect better detection or technical debt; memory safety bugs account for 70% of high-severity vulnerabilities.
Researchers discovered 84 vulnerabilities in open-source 5G/LTE core implementations that exploit "implicit trust errors"—components blindly accept unverified internal messages, enabling attackers to hijack active network sessions without credentials.
Google's AI-driven vulnerability discovery system found 1,800+ Chrome bugs in 2026, including a critical 13-year-old sandbox escape (CVE-2026-3545) that evaded all prior security reviews. The flaw allowed arbitrary local file access via a compromised renderer, demonstrating how AI-powered scanning c
Device code phishing bypasses MFA by exploiting OAuth 2.0, tricking users to authenticate at legitimate Microsoft URLs. The attack evolved from research curiosity to mass commodity threat in months, now generating millions of attacks.
Wiz discovered a Gremlin API vulnerability in Azure Cosmos DB that exploited .NET reflection to escape the sandbox, exposing a master key granting platform-wide database access.
CVE-2026-63077 is an unauthenticated RCE in TeamCity's build agent polling protocol. Attackers can execute code without credentials, risking access to repos, deployment secrets, and signing keys.
RouterOS CVE-2026-14227: Demoted sessions retain old permissions, exposing WireGuard keys. Affects all RouterOS with API; requires prior elevated access.
TeamCity has a 9.8 CVSS auth bypass (CVE-2026-63077) enabling remote command execution via the agent polling protocol. VPN-protected UIs offer false security if build agents are externally reachable.
Schneider Electric IGSS has a critical flaw (CVE-2026-12927) allowing arbitrary code execution through malicious CGF files. It affects engineering workstations with SCADA network access.
CVE-2026-13584 in Mitsubishi CC-Link IE TSN allows network attackers to tamper with or disable industrial controllers. All current firmware is vulnerable; risks include DoS or silent data corruption.
NASA's cFS Health & Safety app has a remote null pointer dereference (CVE-2026-18064) causing DoS via processor reset. An incomplete prior patch left this unfixed. No auth required; CVSS 7.5.
Bank of America is acquiring UK-based MDSec, an offensive security firm specializing in red team work and adversary simulation. The deal signals financial services' strategic shift toward insourcing scarce offensive security talent and deep technical capabilities historically outsourced to external
Claude is hyped for security but can't replace threat intelligence or detection engines. Its main risk: confident-sounding but often inaccurate analysis that could cause missed detections.
AI agents are vulnerable to "confused deputy" attacks where untrusted data in retrieved context or tool outputs tricks the model into unintended actions. The real security risk isn't the AI model itself, but the entire unaudited architecture surrounding it.
VMware patched critical vulnerabilities combining authentication bypass and VM escape—enabling attackers to escalate from unauthenticated network access to complete infrastructure control. This attack chain poses an existential threat to enterprises; patches are urgent for all vSphere deployments.
Russian organizations face a coordinated cybercrime blitz exploiting trust in familiar interfaces: xplogs22 spreads XWorm via phishing, LunaSpy masquerades as antivirus to steal data, and Toy Ghouls deploys GenieLocker ransomware. Social engineering proves far harder to patch than technical exploits
Google's AI discovered a 13-year-old Chrome vulnerability that humans missed. Chrome 149-150 fixed 1,072 bugs—more than the prior 23 releases—using an end-to-end AI pipeline for discovery, triage, and patches.
igloohome's Android app embedded hardcoded credentials, exposing backend lock services to unauthorized access (CVE-2026-16581). The fix involved removing secrets and hardening server authentication.
Researchers exploited .NET reflection in Azure Cosmos DB's Gremlin engine to escape sandboxes and access shared gateways, stealing primary account keys for any customer globally.
Orphaned DNS records pointing to decommissioned resources are exploitable for subdomain takeovers. AI automation could scale this known vulnerability into a widespread national security threat.
Discern Security raised $13M to solve AI agent security risks in enterprises. Agents hold unaudited permissions and actively use them, creating threats beyond traditional identity management.
Cantina, an $8M startup, uses AI agents to automate vulnerability remediation—not just detection. The bet: fix backlogs that pile up faster than teams can clear them.
DataBahn raised $40M to monitor autonomous AI accessing organizational data—a major oversight. Agentic systems dynamically decide what to fetch, creating risks beyond traditional pipeline security.
South Korea's mandatory AnySign4PC banking software contained a zero-day vulnerability that state-sponsored hackers exploited for a year. Users were infected just by visiting normal websites, illustrating how mandated security tools become systemic national vulnerabilities.
AI agents evade firewalls by using ordinary HTTPS traffic with invisible intent. Check Point's 'AI Network Firewall' adds intent-aware enforcement to detect autonomous agent activity.
Microsoft Copilot can be manipulated via hidden text in source documents to silently alter content and embed instructions. The malicious instructions persist undetected in new files, making corruption untraceable.
Chrome 151's 370 patches aren't cause for celebration—they're evidence of accumulated complexity in the world's most-attacked browser. The spike likely reflects backlog clearing or new detection methods, underscoring the security challenges at scale.