View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical Ruflo MCP Bridge Flaw Allows Remote Command Execution and AI

🚨 ACTIVE EXPLOITATION

  • Critical Ruflo MCP Bridge Flaw Allows Remote Command Execution and AI Agent Hijacking CVE-2026-59726
    A critical vulnerability in Ruflo MCP Bridge enables unauthenticated remote command execution and AI agent compromise.

    • Applies to Ruflo AI orchestration platform, affecting MCP Bridge component
    • Vulnerability CVE-2026-59726 allows unauthenticated HTTP POST to /mcp endpoint for arbitrary command execution
    • Exploits include stealing API keys for OpenAI, Anthropic, Google Gemini from environment variables
    • Attackers can hijack AI agent swarms, poison persistent memory (AgentDB), and extract conversation data from unauthenticated MongoDB
    • Default Docker deployments expose MCP Bridge on port 3001 bound to 0.0.0.0 without authentication
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Coordinated Cyberattack Disrupts OT Systems at 30+ Minnesota Water Utilities
    Hackers launched a coordinated cyberattack on operational technology at over 30 Minnesota water utilities.

    • Targets: Operational technology systems at more than 30 Minnesota community water utilities
    • Impact: Braham water plant went offline; other communities faced equipment malfunctions and manual operations
    • Attack characteristics: Similar timing, access methods, and infrastructure targeted indicate coordination
    • Investigation: Ongoing by Minnesota IT Services with federal and local partners; no attacker identified yet
    • Context: Attack methods consistent with Iranian-affiliated groups targeting PLCs in critical infrastructure
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via BleepingComputer, The Hacker News
  • CVE-2026-10702 Firefox JIT Flaw Enables Code Execution via Malicious Webpage in Tor Browser CVE-2026-10702
    A Firefox JavaScript engine bug allows code execution in Tor Browser via a malicious webpage.

    • Affects Tor Browser users running unpatched versions based on Firefox prior to 151.0.3
    • Vulnerability is a JIT miscompilation use-after-free flaw in Firefox's SpiderMonkey engine
    • Exploitation requires only visiting a single malicious webpageβ€”no user interaction needed
    • Allows arbitrary code execution in the browser renderer process, risking user anonymity
    • Mozilla patched the flaw in Firefox 151.0.3 on June 2, 2026; Tor Browser fixed it in version 15.0.19
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts
    Russian intelligence hackers phished Signal backup keys to hijack high-value accounts.

    • Targets include officials, military, political figures, journalists, and Ukrainian leaders
    • Attackers impersonate Signal support staff to request backup recovery keys via phishing
    • Phishing messages create urgency, directing victims to share recovery keys in chat
    • Stolen keys allow attackers to access historic private and group chats from backups
    • Activity linked to Russian Federal Security Service and military actors, tracked as UNC5792 and UNC4221
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
    A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds of two Joyfill packages appeared on the npm registry. The libraries, @joyfill/components and @joyfill/layouts, are used for forms and layout work.
    πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Anthropic’s Claude Mythos Model Advances Cryptanalysis of HAWK and Reduced-Round AES
    Anthropic published new cryptanalysis results on HAWK and reduced-round AES using Claude Mythos.

    • Applies to HAWK, a proposed post-quantum signature scheme based on module-LIP, and reduced-round AES (7 rounds)
    • New key recovery attack on HAWK halves its security bits but is exponential time and demonstrated on weakened challenge instances
    • HAWK is not deployed or standardized; attack does not affect Falcon or other deployed schemes
    • Improved attack on 7-round AES modestly speeds up previous 2013 results but remains impractical requiring 2^89 operations and 2^105 chosen plaintext encryptions
    • Attacks leverage known cryptanalytic tools combined more thoroughly, showcasing AI’s ability to enhance existing techniques
      πŸ“Ž Coverage: blog.cryptographyengineering.com Β· πŸ‘ via Cryptography Engineering
  • Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
    Threat actors cloned Russian company websites to steal advance payments for nine years.

    • Targets international firms in fertilizer, petrochemical, metallurgical, logistics, and banking sectors
    • Fraudulent websites mimic legitimate Russian companies with altered contact and bank details
    • Attackers use cold calls, phishing emails, and fake business documents to initiate and finalize scams
    • Campaign active since 2017 with nearly 100 counterfeit domains using .ru, .com, .org, and .net TLDs
    • Victims include CIS region B2B organizations; example loss of $150,000 reported in April 2025
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • AWS advises cooldown period for npm and pip package updates in Amazon Linux
    AWS recommends delaying npm and pip package installations by 24 hours to reduce supply chain risks.

    • Applies to users of npm and PyPI packages on Amazon Linux
    • Vulnerability window exists in the first hours after package publication before scanners analyze them
    • Recent supply chain attacks on NodeJS and Python packages were detected and removed within hours
    • AWS suggests a 24-hour cooldown to skip installing packages published within the last day
    • Cooldown can be overridden to install urgent security patches while delaying new package installs
      πŸ“Ž Coverage: aws.amazon.com Β· πŸ“„ Original: aws.amazon.com Β· πŸ‘ via AWS Security Blog

πŸ“‹ ADVISORIES

  • CISA and partners release updated 2026 minimum elements for software bill of materials
    CISA and partners published updated 2026 minimum elements for software bill of materials (SBOM).
    • Applies to all software including open-source, AI software, and SaaS
    • Updates replace 2021 NTIA SBOM minimum elements incorporating 2025 public feedback
    • New elements include Component Hash Algorithm, Component License, SBOM Tool Name, and Generation Context
    • Revised elements improve clarity, e.g., 'SBOM Author' and 'Component Producer'
    • SBOMs provide detailed software component and supply chain data for risk-informed decisions
      πŸ“Ž Coverage: cisa.gov Β· πŸ“„ Original: cisa.gov Β· πŸ‘ via CISA Advisories, CISA News (+1)

πŸ”“ CVEs & KEV

  • Other: 20 CVEs (worst 6.1)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check