Ruby on Rails critical bug puts every image upload under scrutiny
CSO Online 05.08.2026 01:56
A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets.
Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails.
ChainDrop credential stealing worm infects over 400 npm packages
CSO Online 04.08.2026 22:37
A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined.
The attack began with the compromise of a GitHub account belonging to Jared Wray, who maintains Keyv, a package with over 150 million weekly downloads that provides an interface for interacting with key-value storage across multiple backends. Version 6.0.0 published at around 9:00 UTC on Tuesday contained a new version of the Shai-Hulud credential stealing malware.
Check Point: Angreifer können Security-Management-Server übernehmen
Heise Security 04.08.2026 12:05
Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download.
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
The Hacker News 04.08.2026 10:36
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects
Jetzt patchen! Angreifer attackieren N-able N-central
Heise Security 04.08.2026 09:04
N-ables Endpoint-Managementlösung N-central ist verwundbar und Angreifer attackieren bereits Instanzen. Admins sollten zügig handeln.
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The Hacker News 04.08.2026 07:00
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows