Cybersecurity
News
Rails critical Active Storage bug lets attackers read files remotely
Ruby on Rails patched a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), allowing unauthenticated file read on servers using libvips.Attackers can extract secret_key_base, database...
News
RufRoot vulnerability allows unauthenticated RCE in Ruflo
A maximum-severity vulnerability (CVE-2026-59726, CVSS 10.0) in the open-source AI agent platform Ruflo allows unauthenticated remote code execution.The flaw, codenamed RufRoot, exploits an unauthenticated...
News
Firefox JIT bug CVE-2026-10702 exploited via malicious webpage
Critical Firefox JIT flaw (CVE-2026-10702) enables remote code execution via a malicious webpage, patched in Firefox 151.0.3.The vulnerability also compromises Tor Browser, with no...
News
Joyfill npm beta releases drop blockchain-linked RAT
Two beta npm packages from @joyfill were compromised to deliver the DEV#POPPER remote access trojan, using a multi-blockchain resolver structure.The malware retrieves encrypted commands...
News
Tengu Botnet Uses Watchdog to Reboot Linux Devices
Security researchers at Nozomi Networks Labs discovered Tengu, a new Mirai-derived botnet that exploits Linux hardware watchdogs to reboot compromised devices when its main...
News
JetBrains TeamCity Flaw Allows Unauthenticated Remote Code Execution
JetBrains has disclosed a critical vulnerability, CVE-2026-63077, affecting all on-premise versions of TeamCity.The flaw, with a CVSS score of 9.8, allows an unauthenticated attacker...
News
Critical Arista VeloCloud Flaw Under Active Attack, Patch Now
A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation.CISA has added the vulnerability to its...
News
Dysphoria botnet uses blockchain to evade takedown after police raid
The Dysphoria IoT botnet, tracked by CNCERT and XLab, now uses Ethereum Name Service (ENS) and Solana Name Service (SNS) for resilient command-and-control, making...
Latest news
New Coldcard attack wave steals 389 Bitcoin; Thorn warns
Galaxy research head Alex Thorn warned Monday of a fourth wave of coordinated thefts targeting Coldcard hardware wallet users218...
Coldcard Hack Ongoing: $88M Stolen in Three Waves
Galaxy Research now tracks roughly $88.6 million stolen from approximately 4,585 Coldcard addresses across three attack waves.Galaxy's Alex Thorn...
STRC shares stay below $100 par, August dividend holds at 12%
Strategy's STRC preferred shares closed July at $89.46, well below their $100 par value, while the August dividend was...
