Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The London office, the empty boxes and the £1bn tax loophole | Financial sector

    August 31, 2026

    You Know Who Really Hates AI? Insurance Claims Adjusters

    August 31, 2026

    Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

    August 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The London office, the empty boxes and the £1bn tax loophole | Financial sector
    • You Know Who Really Hates AI? Insurance Claims Adjusters
    • Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
    • Ireland Bars Crypto From State Savings Scheme Targeting $203B in Deposits
    • Scientists find why the liver may not heal even after you stop drinking
    • Elections, Act 10 top list of hot-button issues facing Wisconsin Supreme Court’s new liberal supermajority
    • Colombian rebel group say kidnapped French Foreign Legion soldier is still alive
    • US Open 2026: Novak Djokovic breaks down in tears during loss to Mariano Navone in New York
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 31, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are exploiting a critical-severity Ruby on Rails vulnerability that leads to remote code execution (RCE), VulnCheck warns.

    Tracked as CVE-2026-66066 (CVSS score of 9.5) and referred to as KindaRails2Shell, the flaw is described as an arbitrary file read leading to secret exposure, RCE, and lateral movement.

    The security defect was disclosed in late July, when Ruby on Rails rolled out patches for it, urging the immediate patching of all Rails applications that rely on libvips for Active Storage image processing and allow image uploads from untrusted users.

    Shortly after, security researchers reverse-engineered the bug and released technical information and proof-of-concept (PoC) code targeting it, and Rails published forensic tools to help detect exploitation attempts.

    Rails explained that KindaRails2Shell was rooted in the different methods used by different libraries and functions to read arbitrary files.

    While Rails may rely on the client-supplied content type to interpret a blob as an image, libvips looks at the magic bytes to determine the file type.

    Advertisement. Scroll to continue reading.

    This allows an attacker to craft a file and declare it as MATLAB Level 5, leading to libvips selecting the MATLAB loader. The file is then routed to libmatio, which identifies MAT 7.3 in a header field and hands it to HDF5.

    “HDF5’s External File List lets a dataset’s bytes live in another file named by path and offset, so rendering the ‘image’ reads an attacker-chosen file off the server and returns its contents as pixels. The same confusion, twice, at two layers that cannot see each other’s fields,” Rails notes.

    An unauthenticated attacker could target anything that the Rails process can read, including the credential database and storage keys. Armed with the compromised secrets, the attacker could then forge sessions, access additional systems, and execute arbitrary code remotely.

    According to VulnCheck, threat actors started exploiting CVE-2026-66066 last week, roughly one month after patches were released.

    Furthermore, VulnCheck says that its tests on a patched 8.1.3.1 server revealed that, “while the fix blocks the libvips file read, it does not neutralize the variation-key Marshal deserialization: the RCE gadget still executes on a patched server given a valid signature.”

    In early August, VulnCheck identified around 7,000 exposed Ruby on Rails instances vulnerable to KindaRails2Shell.

    Related: More Details Emerge on Exploited PaperCut Vulnerabilities

    Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

    Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

    Related: Adobe and Nvidia Patch Dozens of Vulnerabilities

    Attackers critical crosshairs rails Ruby Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

    Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’

    Microsoft asks users to ignore ‘Antivirus is turned off’ errors

    More Details Emerge on Exploited PaperCut Vulnerabilities

    Chrome Web Store extensions caught stealing crypto, browser data

    Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The London office, the empty boxes and the £1bn tax loophole | Financial sector

    August 31, 2026

    You Know Who Really Hates AI? Insurance Claims Adjusters

    August 31, 2026

    Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

    August 31, 2026

    Ireland Bars Crypto From State Savings Scheme Targeting $203B in Deposits

    August 31, 2026
    Latest Posts

    After Obamacare Cuts, Hospitals Are Treating More Uninsured Patients

    July 30, 2026

    Fifa World Cup plans: First lot of private cash could be received by end of October

    July 30, 2026

    Poland’s Leader Says Russian Missile May Have Struck Its Territory During Ukraine Attack

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The London office, the empty boxes and the £1bn tax loophole | Financial sector

    August 31, 2026

    You Know Who Really Hates AI? Insurance Claims Adjusters

    August 31, 2026

    Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

    August 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.