Sam's News — security — 2026-08-01¶
TL;DR¶
- Rails Critical RCE Vulnerability in Active Storage
- Water Facilities in Seven US States Hit by Cyberattacks
- Adobe Campaign Classic CVSS 10.0 Critical Flaw
- Adform Ad Network Supply Chain Attack Steals Cryptocurrency Wallet Addresses
- Hotel Wi-Fi Hijacking Delivers CornFlake Remote Access Trojan
- Arch Linux Temporarily Disables AUR Package Adoption to Combat Malware
Security¶
Rails Critical RCE Vulnerability in Active Storage¶
Rails patched a critical unauthenticated RCE vulnerability in Active Storage (CVE-2026-66066, CVSS 9.5), exploitable through malicious image uploads processed by libvips.
- CVSS 9.5, unauthenticated attacker can read files and achieve RCE
- Affects Active Storage before 7.2.3.2, 8.0.5.1, and 8.1.3.1
- Exploitable when libvips generates thumbnails from untrusted uploads
- Can expose Rails secret_key_base and database/cloud credentials
- Fix: upgrade libvips to 8.13+, rotate secrets, or set VIPS_BLOCK_UNTRUSTED
Sources: BleepingComputer Research, SecurityWeek Research
Water Facilities in Seven US States Hit by Cyberattacks¶
The FBI and EPA warned that seven US water and wastewater utilities suffered cyberattacks starting July 27 that degraded operations, exploiting internet-exposed programmable logic controllers.
- Attacks began July 27, 2026 across seven states
- Victims reported flooding and loss of water pressure
- CISA noted a surge in attacks targeting internet-exposed PLCs
Sources: Engadget Research, Wired RSS, The Record RSS, BleepingComputer RSS
Adobe Campaign Classic CVSS 10.0 Critical Flaw¶
Adobe issued an emergency patch for a maximum-severity (CVSS 10.0) flaw in Campaign Classic that allows unauthenticated arbitrary code execution, alongside a related SQL injection bug and eight critical Bridge vulnerabilities.
- CVE-2026-48449: incorrect authorization flaw, CVSS 10.0, no auth or user interaction needed
- Fixed in ACC v7: 7.4.3 build 9398 for Windows and Linux
- Secondary flaw CVE-2026-48448 (SQL injection, CVSS 8.6) allows arbitrary file reads
- Eight critical Adobe Bridge flaws also patched, CVSS 7.8-8.6
- Adobe says no active exploitation observed in the wild
Sources: The Hacker News Research
Adform Ad Network Supply Chain Attack Steals Cryptocurrency Wallet Addresses¶
Attackers compromise advertising firm Adform's JavaScript to inject cryptocurrency wallet address-stealing code across customer websites.
Sources: The Hacker News RSS, BleepingComputer RSS
Hotel Wi-Fi Hijacking Delivers CornFlake Remote Access Trojan¶
Cybercriminals hijack hotel Wi-Fi networks to deliver fake browser updates containing CornFlake malware for webcam, microphone, and keystroke surveillance.
Sources: The Hacker News RSS, Microsoft Security Blog RSS
Arch Linux Temporarily Disables AUR Package Adoption to Combat Malware¶
Arch Linux halts new package adoptions in the Arch User Repository following surge in malicious takeovers of existing packages.
Sources: BleepingComputer RSS
Amgen Cloud Data Breach Exposes Patient Health and Proprietary Information¶
Pharmaceutical company Amgen suffers breach of corporate data and patient information stored in multiple cloud systems operated by third-party providers.
Sources: BleepingComputer RSS
HollowFrame Loader and Matryoshka Backdoor Target Law Firm¶
Cybersecurity researchers uncover previously undocumented HollowFrame loader and Matryoshka backdoor malware deployed in spear-phishing campaign against law firm.
Sources: The Hacker News RSS
DeepSeek AI Used for Autonomous Cyberattacks¶
Chinese-speaking threat actor uses DeepSeek AI model and Hermes Agent framework to conduct autonomous attacks on vulnerable servers.
Sources: BleepingComputer RSS
Chinese Central Asian Government Cyberattack Campaign¶
Chinese-speaking threat actors target government organizations in Central Asia including Afghanistan and Tajikistan with OctLurk and SilkLurk malware.
Sources: The Hacker News RSS