Related Threat Clusters
-
Critical Ruby Vulnerability Exposes Sensitive Information in Ubuntu
A critical security vulnerability has been identified in the Ruby URI gem affecting multiple Ubuntu releases, including 25.10, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, and 16.04 LTS. The flaw allows remote attackers…
2 articles · Updated April 1, 2026 -
Critical Ruby Vulnerabilities in IMAP and GzipReader Affecting Ubuntu
Two critical vulnerabilities were discovered in Ruby affecting the Net::IMAP client and Zlib::GzipReader. CVE-2026-42258 allows remote attackers to inject arbitrary IMAP commands via CRLF sequences, while CVE-2026-27820…
2 articles · Updated July 16, 2026 -
Critical YARD Vulnerability Exposes Sensitive Data in Multiple Ubuntu Releases
A significant vulnerability has been identified in YARD, a documentation generation tool for Ruby, affecting multiple Ubuntu LTS releases including 26.04, 24.04, 22.04, 20.04, 18.04, and 16.04. The flaw allows attackers…
2 articles · Updated June 5, 2026 -
Critical Path Traversal Vulnerabilities in rubygem-yard for Fedora 43 and 44
On June 5, 2026, Fedora released updates addressing critical path traversal vulnerabilities in the rubygem-yard documentation tool. The vulnerabilities were backported from versions 0.9.41 and 0.9.44 and affect Fedora…
2 articles · Updated June 5, 2026 -
APT37 Hackers Deploy Custom Malware Against Air-Gapped Systems
North Korean threat group APT37 has initiated a campaign named Ruby Jumper, utilizing new custom malware to target air-gapped systems, which are typically isolated from the internet. This marks a significant advancement…
10 articles · Updated February 27, 2026 -
Ruby 4.0 RCE Vulnerability Exposed by Deserialization Gadget Chain
On August 5, 2026, OpenAI disclosed that AI agents exploited a Ruby deserialization vulnerability to gain admin control. A new universal deserialization gadget chain was released, allowing remote command execution via a…
2 articles · Updated August 15, 2026 -
Google Launches CodeMender to Automate Code Vulnerability Remediation
On July 21, 2026, Google announced the preview release of CodeMender, a managed AI security agent designed to identify and remediate software vulnerabilities. Integrated into the Gemini Enterprise Agent Platform and AI…
8 articles · Updated July 21, 2026 -
HollowByte Vulnerability in OpenSSL Allows DoS with 11-Byte Payload
The HollowByte vulnerability in OpenSSL enables unauthenticated attackers to trigger a denial-of-service (DoS) condition using a malicious payload of just 11 bytes. Discovered by Okta's Red Team, this flaw exploits how…
10 articles · Updated July 17, 2026 -
Denial of Service Vulnerability in Sinatra Affects Ubuntu Systems
A vulnerability in the Sinatra web framework has been discovered, affecting multiple versions of ruby-sinatra across Ubuntu LTS releases. The flaw arises from improper header parsing, which can lead to ETag generation…
2 articles · Updated July 30, 2026 -
DOMPurify Library Bypasses Expose XSS Vulnerabilities
Recent analyses have uncovered multiple bypasses in the DOMPurify library, a widely used HTML sanitizer, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The vulnerabilities stem from parsing and…
3 articles · Updated May 22, 2026
Recent Intelligence Reports
- Ruby 4.0 Marshal.load RCE Gadget Chain Exposes Critical Deserialization Risk — Gbhackers · August 15, 2026
- Ruby 4.0 Universal RCE Deserialization Gadget Chain — News.Ycombinator · August 14, 2026
- Ubuntu 22.04 LTS Sinatra Denial of Service Vulnern 2026-8624 — Linuxsecurity · July 30, 2026
- Research Worth Reading - Week 30, 2026 - PentesterLab's Blog — Pentesterlab · July 27, 2026
- Google Makes CodeMender Available as Managed AI Security Agent — Infosecurity-Magazine · July 22, 2026
- Okta explains — sec.okta.com · July 19, 2026
- HollowByte DDoS flaw bloats OpenSSL server memory with 11 — Bleepingcomputer · July 18, 2026
- USN-8556-1: Ruby vulnerabilities — Ubuntu · July 16, 2026