π¨ ACTIVE EXPLOITATION
-
KindaRails2Shell Ruby on Rails Flaw Exploited for Remote Code Execution
Attackers are exploiting a critical Ruby on Rails flaw for remote code execution.- Rails applications using Active Storage with libvips and untrusted image uploads are affected.
- CVE-2026-66066 enables unauthenticated arbitrary file reads, secret theft, lateral movement, and RCE.
- Attackers craft MATLAB Level 5 files that route through libmatio and HDF5 to read attacker-selected server files.
- VulnCheck observed exploitation about one month after patches and identified roughly 7,000 exposed instances.
- VulnCheck reported a variation-key Marshal deserialization RCE path still worked on patched Rails 8.1.3.1 with a valid signature.
π Coverage: securityweek.com Β· π via SecurityWeek
-
HexMage Magecart Uses Ethereum Contracts to Steal Online Shoppersβ Card Data
HexMage is using Ethereum smart contracts to steal payment-card data from online shoppers.- More than 40 WooCommerce, PrestaShop, Magento, and WordPress stores in at least 15 countries were affected.
- The campaign targets shoppersβ card numbers, expiration dates, CVVs, names, billing emails, and other checkout data.
- A fake Google Tag Manager block injects a JavaScript loader into compromised checkout pages.
- The loader retrieves ethers.js, queries Sepolia contracts through 0xrpc[.]io, and downloads a payment skimmer from a contract-supplied domain.
- Observed infrastructure includes wallet 0x88361C914Bb0942da9a1b7Bb396a7513C1917aee and domains such as ashenravenfort[.]top and grimwardens[.]com.
π Source: blog.confiant.com Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News, cryptika.com (discovered)
π ADVISORIES
-
Anthropic Extends Compliance API Coverage to Claude Code and Cowork
Anthropic has extended its Compliance API to Claude Code and Cowork.- Claude Enterprise organizations can access the added coverage, excluding public-sector organizations.
- Claude Code CLI and desktop sessions plus Cowork desktop, web, and mobile sessions are covered.
- The API returns server-hosted transcripts containing prompts, responses, web and MCP tool calls, skills, and artifacts.
- Session records include verified user identity, organization and message IDs, and timestamps.
- Coverage excludes Claude Code on the web, Claude Platform sessions, and sessions on Bedrock, Vertex AI, or Microsoft Foundry.
π Source: claude.com Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
π Source for Supply-Chain Worm Compromises TanStack Query npm Code Generator β research.jfrog.com
π CVEs & KEV
-
CVE-2026-49003 β CVSS 9.6 β Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 ProductAttackers ca...
-
CVE-2026-82877 β CVSS 7.1 β ILIAS before 9.22 Arbitrary File Read via SOAP addFileILIAS versions before 9...