Cyber Brief · Aug 1 · 10 stories
Saturday, August 1, 2026 · sent to 1 subscribers
News
· BleepingComputer · Aug 1
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
Advisories
· CISA · Jul 30
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.
The following versions of Toptech Systems RCU II+ and Multiload II+ are affected:
RCU II+ <2025-11-24 (CVE-…
News
· The Hacker News · Jul 30
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation.
The vulnerability, …
News
· BleepingComputer · Jul 30
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
News
· The Hacker News · Jul 30
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial,…
Advisories
· CISA · Jul 30
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected:
Core Flight System (cFS) Health & Safety (HS) Application &…
News
· SecurityWeek · Aug 1
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.
News
· SecurityWeek · Jul 31
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.
News
· CSO Online · Jul 30
A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security.
The flaw, tracked as CVE-2026-59…
News
· Help Net Security · Jul 31
Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting …