CVE
CVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Exploitation IoCs 9
Domain canary
Domain corepack[.]org
Filename .bash_history
Filename .sysd
Filename /root/.cache/langflow/secret_key
Filename lib/.threadpool.rb
IP 165[.]154[.]236[.]93
IP France
IP Israel
MITRE ATT&CK TTPs 21
T1003 T1021 T1027 T1056.001 T1059 T1059.001 T1059.003 T1071.001 T1078 T1082 T1083 T1098 T1105 T1114 T1190 T1484 T1485 T1555 T1566 T1570 T1588
OS Credential Dumping
Credential Access
Remote Services
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Keylogging
Collection
Command and Scripting Interpreter
Execution
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Email Collection
Collection
Exploit Public-Facing Application
Initial Access
Domain or Tenant Policy Modification
Defense Evasion
Data Destruction
Impact
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Lateral Tool Transfer
Lateral Movement
Obtain Capabilities
Resource Development
Source Articles
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-0768 in Langflow and CVE-2026-66066 (KindaRails2Shell) in Ruby on Rails, to conduct credential probing, remote code execution, and command-and-control activities. Exploitation of CVE-2026-66066 involves uploading a crafted image to read sensitive files, leak environment secrets, and achieve RCE, particularly when libvips is used for image processing. Attackers have targeted canary systems globally, with source traffic traced to Russia and a single IP in France, and C2 infrastructure in Israel. Additional post-exploitation activities include deploying credential harvesters, cryptominers, disabling auditd, and lateral movement.
hacker-news Sep 1, 2026
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news Aug 3, 2026
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability, CVE-2026-66066, in the Rails Active Storage component allows unauthenticated attackers to read arbitrary files from a Rails application by uploading a specially crafted image when libvips is used for image processing. If successful, attackers can extract sensitive environment variables such as 'secret_key_base', enabling session forgery, data manipulation, and remote code execution (RCE). The vulnerability affects Active Storage versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1, with no workaround available for older libvips versions. Public proof-of-concept exploits have accelerated disclosure and prompted WAF protections from Akamai.
bleeping-computer Aug 1, 2026