Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Ruby on Rails released fixes for CVE-2026-66066, a critical Active Storage vulnerability (CVSS 9.5) that allows unauthenticated attackers to read arbitrary server files through crafted image uploads when libvips is used for image processing. The flaw can expose secret_key_base, Rails master key, database passwords, cloud storage credentials, and API tokens, potentially enabling remote code execution or lateral movement.
OpenWrt released version 24.10.8 to fix CVE-2026-53921 (CVSS 9.8), a critical DHCPv6 stack overflow in odhcpd that lets unauthenticated attackers execute code as root. Embedded hardware commonly lacks stack canaries and ASLR, making exploitation realistic in typical deployments.
Nearly half of people encounter a scam on their phone every single day.
Nearly half of individuals encounter scams on their phones daily, according to a 2025 Malwarebytes survey of 1,300 respondents across the US and Europe. The survey revealed alarming trends: 25% of victims reported harassment or blackmail, nearly 20% had private information exposed, and 15% lost money.
Reddit users discovered that shared conversations from Anthropic's Claude AI chatbot were appearing in Google search results, exposing sensitive data like crypto wallet keys, personal details, and private discussions. The issue stemmed from Claude's Share feature, which generated public web links for shared chats and Artifacts (interactive documents created by Claude).
Reddit users found that by using a specific Google search query, it was possible to find Claude conversations that users had shared. This exposed sensitive material, including crypto wallet keys, names, addresses, work notes, and...