Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw affects numer...
Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Window...
Multiple critical vulnerabilities have been discovered in the Linux kernel affecting Ubuntu systems, particularly in versions 24.04 and 26.04 LTS. The vulnerabilities include CVE-2025-10263, which allows local attackers to bypass memory protections and escalate privileges on affected Arm and AMD pro...
Oracle has released a critical advisory (ELSA-2026-500004) addressing multiple vulnerabilities in its Linux kernel. The vulnerabilities include CVE-2026-31663, CVE-2026-46316, and CVE-2026-53362, which could lead to denial of service (DoS) attacks. Affected systems include Oracle Linux 9 and Oracle'...