threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million Bitcoin theft, while Russian actors exploited a Microsoft OWA flaw for persistent access. Furtherm… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
vulnerability Ruby on Rails Patches Critical Vulnerability A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code… SecurityWeek · Aug 1, 2026 Critical CVE-2026-66066rubyrailslibvips
vulnerability Vulnérabilité dans Ruby on Rails activestorage (30 juillet 2026) A critical vulnerability has been identified in Ruby on Rails’ activestorage library, allowing attackers to execute arbitrary code remotely and potentially compromise data confidentiality. This affects older versions of… CERT-FR · Jul 30, 2026 Critical CVE-2026-66066ruby on railscvevulnerability
vulnerability Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads A critical vulnerability (CVE-2026-66066, CVSS 9.5) in Ruby on Rails' Active Storage component, using libvips for image processing, allows unauthenticated attackers to read arbitrary files from application servers. This… The Hacker News · Jul 29, 2026 Critical CVE-2026-66066rubyrailslibvips