Cybersecurity

Rails critical Active Storage bug lets attackers read files remotely

Ruby on Rails patched a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), allowing unauthenticated file read on servers using libvips.Attackers can extract secret_key_base, database...

RufRoot vulnerability allows unauthenticated RCE in Ruflo

A maximum-severity vulnerability (CVE-2026-59726, CVSS 10.0) in the open-source AI agent platform Ruflo allows unauthenticated remote code execution.The flaw, codenamed RufRoot, exploits an unauthenticated...

Firefox JIT bug CVE-2026-10702 exploited via malicious webpage

Critical Firefox JIT flaw (CVE-2026-10702) enables remote code execution via a malicious webpage, patched in Firefox 151.0.3.The vulnerability also compromises Tor Browser, with no...

Joyfill npm beta releases drop blockchain-linked RAT

Two beta npm packages from @joyfill were compromised to deliver the DEV#POPPER remote access trojan, using a multi-blockchain resolver structure.The malware retrieves encrypted commands...

Tengu Botnet Uses Watchdog to Reboot Linux Devices

Security researchers at Nozomi Networks Labs discovered Tengu, a new Mirai-derived botnet that exploits Linux hardware watchdogs to reboot compromised devices when its main...

JetBrains TeamCity Flaw Allows Unauthenticated Remote Code Execution

JetBrains has disclosed a critical vulnerability, CVE-2026-63077, affecting all on-premise versions of TeamCity.The flaw, with a CVSS score of 9.8, allows an unauthenticated attacker...

Critical Arista VeloCloud Flaw Under Active Attack, Patch Now

A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation.CISA has added the vulnerability to its...

Dysphoria botnet uses blockchain to evade takedown after police raid

The Dysphoria IoT botnet, tracked by CNCERT and XLab, now uses Ethereum Name Service (ENS) and Solana Name Service (SNS) for resilient command-and-control, making...

Latest news

FTX executive’s wife seeks to block husband’s guilty plea evidence

Michelle Bond, wife of former FTX executive Ryan Salame, filed a motion to exclude evidence of his guilty plea...

Coldcard Firmware Flaw Drains $70M in Bitcoin Heist

An attacker swept 1,082.65 BTC (~$70.2 million) from 1,196 Bitcoin addresses in 41 minutes by exploiting a predictable random...

Ripple, Coinbase-backed PAC spends $2M on Michigan primary

The Protect Progress PAC, funded by crypto companies Ripple Labs and Coinbase, has spent over $2 million on ads...