Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News 29.07.2026 18:10
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.
Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
The Hacker News 29.07.2026 15:39
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.
The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
Stackable Data Platform 26.7: Sicherheit, SBOMs und flexible Registries
Heise Security 29.07.2026 15:37
Stackable stellt die Data Platform 26.7 auf Qualität und Supply-Chain-Sicherheit um. Neben SLSA-Provenance drohen bei der Registry-Logik Breaking Changes.
Kritische Schwachstelle in JetBrains TeamCity entdeckt
Heise Security 29.07.2026 09:13
JetBrains hat eine kritische Sicherheitslücke in TeamCity geschlossen. Angreifer können CI/CD-Pipelines kompromittieren und Befehle auf dem Server ausführen.
OpenWrt: Updates schließen teils kritische Sicherheitslücken
Heise Security 29.07.2026 09:08
Das OpenWrt-Projekt hat aktualisierte Fassungen veröffentlicht, die teils als kritisches Risiko eingestufte Sicherheitslücken stopfen.
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
The Hacker News 29.07.2026 08:58
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that