Skip to content

Sam's News — security — 2026-08-01

TL;DR

Security

Rails Critical RCE Vulnerability in Active Storage

Rails patched a critical unauthenticated RCE vulnerability in Active Storage (CVE-2026-66066, CVSS 9.5), exploitable through malicious image uploads processed by libvips.

  • CVSS 9.5, unauthenticated attacker can read files and achieve RCE
  • Affects Active Storage before 7.2.3.2, 8.0.5.1, and 8.1.3.1
  • Exploitable when libvips generates thumbnails from untrusted uploads
  • Can expose Rails secret_key_base and database/cloud credentials
  • Fix: upgrade libvips to 8.13+, rotate secrets, or set VIPS_BLOCK_UNTRUSTED

Sources: BleepingComputer Research, SecurityWeek Research

Water Facilities in Seven US States Hit by Cyberattacks

The FBI and EPA warned that seven US water and wastewater utilities suffered cyberattacks starting July 27 that degraded operations, exploiting internet-exposed programmable logic controllers.

  • Attacks began July 27, 2026 across seven states
  • Victims reported flooding and loss of water pressure
  • CISA noted a surge in attacks targeting internet-exposed PLCs

Sources: Engadget Research, Wired RSS, The Record RSS, BleepingComputer RSS

Adobe Campaign Classic CVSS 10.0 Critical Flaw

Adobe issued an emergency patch for a maximum-severity (CVSS 10.0) flaw in Campaign Classic that allows unauthenticated arbitrary code execution, alongside a related SQL injection bug and eight critical Bridge vulnerabilities.

  • CVE-2026-48449: incorrect authorization flaw, CVSS 10.0, no auth or user interaction needed
  • Fixed in ACC v7: 7.4.3 build 9398 for Windows and Linux
  • Secondary flaw CVE-2026-48448 (SQL injection, CVSS 8.6) allows arbitrary file reads
  • Eight critical Adobe Bridge flaws also patched, CVSS 7.8-8.6
  • Adobe says no active exploitation observed in the wild

Sources: The Hacker News Research

Adform Ad Network Supply Chain Attack Steals Cryptocurrency Wallet Addresses

Attackers compromise advertising firm Adform's JavaScript to inject cryptocurrency wallet address-stealing code across customer websites.

Sources: The Hacker News RSS, BleepingComputer RSS

Hotel Wi-Fi Hijacking Delivers CornFlake Remote Access Trojan

Cybercriminals hijack hotel Wi-Fi networks to deliver fake browser updates containing CornFlake malware for webcam, microphone, and keystroke surveillance.

Sources: The Hacker News RSS, Microsoft Security Blog RSS

Arch Linux Temporarily Disables AUR Package Adoption to Combat Malware

Arch Linux halts new package adoptions in the Arch User Repository following surge in malicious takeovers of existing packages.

Sources: BleepingComputer RSS

Amgen Cloud Data Breach Exposes Patient Health and Proprietary Information

Pharmaceutical company Amgen suffers breach of corporate data and patient information stored in multiple cloud systems operated by third-party providers.

Sources: BleepingComputer RSS

HollowFrame Loader and Matryoshka Backdoor Target Law Firm

Cybersecurity researchers uncover previously undocumented HollowFrame loader and Matryoshka backdoor malware deployed in spear-phishing campaign against law firm.

Sources: The Hacker News RSS

DeepSeek AI Used for Autonomous Cyberattacks

Chinese-speaking threat actor uses DeepSeek AI model and Hermes Agent framework to conduct autonomous attacks on vulnerable servers.

Sources: BleepingComputer RSS

Chinese Central Asian Government Cyberattack Campaign

Chinese-speaking threat actors target government organizations in Central Asia including Afghanistan and Tajikistan with OctLurk and SilkLurk malware.

Sources: The Hacker News RSS