Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Filtered Reports
3 / 3 results
criticalbug_reportVulnerabilitybug_reportVulnerability
Langflow and Ruby on Rails flaws exploited for credential theft and C2
Langflow (CVE-2026-0768, CVSS 9.8) - arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5) - arbitrary file read and RCE affecting applications using libvips for Active St…
CVE-2026-07681 Sep · 05:22 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
Rails Active Storage flaw enables file read and RCE by unauthenticated users
Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.
Ruby on Rails1 Aug · 12:20 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
Rails Active Storage flaw allows file read via crafted image uploads
Ruby on Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3 using Active Storage with libvips for image processing and accepting untrusted uploads. Rails 6.0.0–6.1.7.10 affected only when Vips explicitly configured (non-default).
CVE-2026-6606629 Jul · 16:10 UTC