Skip to content

Sam's News β€” security β€” 2026-08-31

Security

7.5 Critical Ruby on Rails vulnerability KindaRails2Shell enables arbitrary file read and remote code execution

A critical Ruby on Rails vulnerability (CVE-2026-66066, CVSS 9.5) named KindaRails2Shell enables arbitrary file read and remote code execution in applications using libvips for image processing. Attackers exploit differing file-type detection methods to craft files that trigger HDF5's External File List feature, reading server files and extracting credentials. Threat actors began exploiting the flaw one month after patches were released in late July.

  • CVE-2026-66066 with CVSS score 9.5 (critical)
  • Affects Rails apps using libvips for Active Storage with untrusted image uploads
  • Enables arbitrary file read and remote code execution via HDF5 External File List
  • Unauthenticated attackers can extract credential databases and storage keys
  • Exploitation began ~one month after patches released in late July

Sources: SecurityWeek AI Web Searched

7.5 Boston Scientific Recovering from Cyberattack

Boston Scientific disclosed a cyberattack detected on August 25, 2026, that disrupted manufacturing, order processing, and shipping globally. The breach affected some on-premises systems but did not compromise existing implantable cardiac rhythm management devices. By the weekend following the attack, the company found no signs of malicious activity since August 25 and expected partial product shipping resumption by August 31.

  • Cyberattack detected August 25; disclosed August 26
  • Caused global network disruption affecting manufacturing and shipping
  • Limited to some on-premises systems; implantable CRM devices unaffected
  • CrowdStrike engaged for forensic investigation
  • No cybercrime group claimed responsibility; attribution unclear

Sources: SecurityWeek AI Web Searched

7.5 Multiple Critical Cybersecurity Threats: ServiceNow, PaperCut, McKesson

Recent security advisories warn of ServiceNow vulnerabilities, a PaperCut zero-day, and a McKesson healthcare data breach.

Sources: CISO Series RSS

7.5 China-Linked Fire Ant Cyber Espionage Group Compromises Cisco Routers and Authentication Systems

China-nexus cyber espionage group Fire Ant expanded operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts for credential theft and security log manipulation. The group deployed custom malware including tools to suppress logging, filter security alerts, and capture network traffic. Activity was limited to scanning vulnerable environments; no confirmed compromise of critical infrastructure targets.

  • Fire Ant targeted Cisco IOS XR routers, TACACS servers, Linux management hosts
  • Deployed purpose-built malware including TacTap credential-collection tool
  • Custom IOS XR malware filtered logs to show only "Health" strings, hid tunnel configuration
  • Used routers to capture network traffic (PCAPs) and upload to external FTP servers
  • Strong overlap with UNC3886 (China-nexus group targeting virtualization platforms)
  • Activity limited to scanning; no confirmed critical infrastructure compromise

Sources: The Hacker News AI Web Searched

7.5 McKesson warns of service degradation following third-party application cyberattack

McKesson disclosed a cybersecurity incident involving a third-party application where hackers exfiltrated data from oncology and surgical business units, causing intermittent service degradation. ShinyHunters claimed responsibility and demanded ransom; McKesson stated hackers are no longer in systems and will provide credit monitoring to affected customers.

  • Incident disclosed August 30, 2026
  • Data exfiltrated from oncology and surgical business units
  • ShinyHunters claimed responsibility with ransom threat
  • McKesson confirmed hackers no longer have system access
  • $106 billion revenue in last quarter
  • ShinyHunters previously targeted Ticketmaster, AT&T, Carnival Cruises, Rockstar Games

Sources: The Record AI Web Searched

7 Extortion Group Claims Manchester Airports Group Data Breach

Threat actor FulcrumSec claims to have stolen over 80 GB of data from Manchester Airports Group and threatened to leak it publicly.

Sources: SecurityWeek RSS

7 Federal Judge Rules Pentagon's Actions Against Anthropic 'Illegal and Baseless'

A judge has declared the Pentagon's measures against Anthropic, which labeled the company a supply chain risk, to be unlawful and unfounded.

Sources: SecurityWeek RSS

7 PaperCut releases second emergency patch for actively exploited vulnerabilities CVE-2026-82078 and CVE-2026-81578

PaperCut issued a second emergency patch for two critical vulnerabilities being actively exploited in the wild.

Sources: SecurityWeek RSS Update to: PaperCut releases second emergency patch for actively exploited print management vulnerabilities

7 Microsoft Exchange Online experiences widespread outage with authentication and email failures

Microsoft Exchange Online suffers a widespread service issue causing authentication failures and email delays.

Sources: BleepingComputer RSS

7 ServiceNow patches three critical code injection vulnerabilities

ServiceNow patched four vulnerabilities including three critical code injection flaws in its AI platform that allow arbitrary code execution, privilege escalation, and SQL injection attacks without authentication. All three critical CVEs score 10/10 CVSS severity; patches deployed to hosted instances with hotfixes for self-hosted releases.

  • CVE-2026-18885: arbitrary code execution and data access/modification
  • CVE-2026-18886: improper access control enabling privilege escalation
  • CVE-2026-74820: SQL injection via database access
  • All three critical flaws: CVSS 10.0, no authentication required
  • CVE-2026-6876: CVSS 8.7 sandbox escape flaw
  • Patches released August 31, 2026 across Xanadu, Yokohama, Zurich, Australia releases

Sources: SecurityWeek AI Web Searched