View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

KindaRails2Shell Ruby on Rails Flaw Exploited for Remote Code

🚨 ACTIVE EXPLOITATION

  • KindaRails2Shell Ruby on Rails Flaw Exploited for Remote Code Execution
    Attackers are exploiting a critical Ruby on Rails flaw for remote code execution.

    • Rails applications using Active Storage with libvips and untrusted image uploads are affected.
    • CVE-2026-66066 enables unauthenticated arbitrary file reads, secret theft, lateral movement, and RCE.
    • Attackers craft MATLAB Level 5 files that route through libmatio and HDF5 to read attacker-selected server files.
    • VulnCheck observed exploitation about one month after patches and identified roughly 7,000 exposed instances.
    • VulnCheck reported a variation-key Marshal deserialization RCE path still worked on patched Rails 8.1.3.1 with a valid signature.
      πŸ“Ž Coverage: securityweek.com Β· πŸ‘ via SecurityWeek
  • HexMage Magecart Uses Ethereum Contracts to Steal Online Shoppers’ Card Data
    HexMage is using Ethereum smart contracts to steal payment-card data from online shoppers.

    • More than 40 WooCommerce, PrestaShop, Magento, and WordPress stores in at least 15 countries were affected.
    • The campaign targets shoppers’ card numbers, expiration dates, CVVs, names, billing emails, and other checkout data.
    • A fake Google Tag Manager block injects a JavaScript loader into compromised checkout pages.
    • The loader retrieves ethers.js, queries Sepolia contracts through 0xrpc[.]io, and downloads a payment skimmer from a contract-supplied domain.
    • Observed infrastructure includes wallet 0x88361C914Bb0942da9a1b7Bb396a7513C1917aee and domains such as ashenravenfort[.]top and grimwardens[.]com.
      πŸ“„ Source: blog.confiant.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News, cryptika.com (discovered)

πŸ“‹ ADVISORIES

  • Anthropic Extends Compliance API Coverage to Claude Code and Cowork
    Anthropic has extended its Compliance API to Claude Code and Cowork.

    • Claude Enterprise organizations can access the added coverage, excluding public-sector organizations.
    • Claude Code CLI and desktop sessions plus Cowork desktop, web, and mobile sessions are covered.
    • The API returns server-hosted transcripts containing prompts, responses, web and MCP tool calls, skills, and artifacts.
    • Session records include verified user identity, organization and message IDs, and timestamps.
    • Coverage excludes Claude Code on the web, Claude Platform sessions, and sessions on Bedrock, Vertex AI, or Microsoft Foundry.
      πŸ“„ Source: claude.com Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • πŸ“„ Source for Supply-Chain Worm Compromises TanStack Query npm Code Generator β€” research.jfrog.com

πŸ”“ CVEs & KEV

  • CVE-2026-49003 β€” CVSS 9.6 β€” Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 ProductAttackers ca...

  • CVE-2026-82877 β€” CVSS 7.1 β€” ILIAS before 9.22 Arbitrary File Read via SOAP addFileILIAS versions before 9...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check