Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

29/07/2026 0 Comments 0 tags

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

29/07/2026 0 Comments 0 tags

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

29/07/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

29/07/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

29/07/2026 0 Comments 0 tags

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

29/07/2026 0 Comments 0 tags

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

29/07/2026 0 Comments 0 tags

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug

Mythos Asks the Right Question. It Doesn’t Answer It.

29/07/2026 0 Comments 0 tags

AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve been getting wrong all along. The conversation

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

29/07/2026 0 Comments 0 tags

The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

29/07/2026 0 Comments 0 tags

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook