Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-29 13:00 PDT
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News • 2026-07-29 11:10 • thehackernews.com
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html - Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
BleepingComputer • 2026-07-29 10:54 • www.bleepingcomputer.com
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. […]
https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/ - Measuring the Tendency of AI Agents to Go Rogue
Schneier on Security • 2026-07-29 10:07 • www.schneier.comThis essay was written with Barath Raghavan, and originally appeared in The Guardian.
In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of …
https://www.schneier.com/blog/archives/2026/07/measuring-the-tendency-of-ai-agents-to-go-rogue.html - OpenAI agent used exposed credentials at 4 services in Hugging Face breach
BleepingComputer • 2026-07-29 09:04 • www.bleepingcomputer.com
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. […]
https://www.bleepingcomputer.com/news/security/openai-agent-used-exposed-credentials-at-4-services-in-hugging-face-breach/ - Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
The Hacker News • 2026-07-29 08:39 • thehackernews.com
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security’s
https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html - Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
The Hacker News • 2026-07-29 08:31 • thehackernews.com
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.
“A malicious actor with network access to vCenter
https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html - Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
BleepingComputer • 2026-07-29 07:55 • www.bleepingcomputer.com
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in “a coordinated cyberattack.” […]
https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ - Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
BleepingComputer • 2026-07-29 07:02 • www.bleepingcomputer.com
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. […]
https://www.bleepingcomputer.com/news/security/your-ai-agents-are-guessing-at-scale-permissions-decide-the-damage/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
