-
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
DAYTON, Ohio—Up to six designs could be brought to the prototyping phase of the second round of the Air Force’s drone-wingman effort next year, a service official told reporters on Tuesday.
Increment 2 of the Air Force’s Collaborative Combat Aircraft competition is well underway, Col. Timothy Helfridge, the fighter portfolio acquisition executive, told reporters at the Life Cycle Industry Days conference here. By roughly mid-2027, Helfridge expects, there could be “up to” half a dozen designs.
“We have another approximately 10 months left of our concept-refinement contract, where we would expect to have the refined attributes as we did before, as well as several closed conceptual designs,” he said. “We're shooting for roughly six, but we'll see what we end up with.”
In December, the Air Force announced that nine companies had received contracts to refine concepts for Increment 2 CCAs, and that 11 more remain eligible to compete in later phases of the effort.
“Increment 2 will be structured similarly to Increment 1, where more than one awardee may be selected for prototyping,” an Air Force official told Defense One late last year. “This approach allows for competitive development and ensures that the Air Force can evaluate various solutions before selecting the final designs to move into production.”
In 2024, service officials funded initial Increment 1 work by Boeing, Lockheed Martin, and Northrop Grumman, Anduril, and General Atomics, but ultimately only the latter two were chosen to build prototypes and then to begin production.
Northrop Grumman’s largely self-financed CCA earned its prototype an Air Force designation and made it eligible for the first increment, but it did not win a production contract.
Helfrich said other unexpected entrants might eventually compete for Increment 2.
“We will continue to maximize competition through all the phases of CCA Increment 2. So we may have entrants that come in in a later phase that were not part of concept refinement,” he said. “We have to maximize the learning as soon as we can.”
This week, just outside of Dayton, Anduril unveiled the first Fury CCA produced at its facility near Rickenbacker Airport in central Ohio. The Air Force has already been experimenting with a prototype Fury and with General Atomics’ Dark Merlin CCA.
Service officials said in a Tuesday press release that the Air Force used the CCAs as part of a recent multi-day Agile Combat Employment exercise at Creech Air Force Base in Nevada.
"This exercise was about getting the systems into the hands of the warfighter," Lt. Col. Matthew Jensen, the Experimental Operations Unit commander, said in a press release. "We are focused on operating CCA outside of a traditional test environment so we can continue to learn, inform and rapidly iterate."
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Better authentication UX helps B2B platforms reduce security fatigue, simplify account recovery, protect sensitive data, and keep business users engaged.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security’s
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. “A malicious actor with network access to vCenter
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Las Vegas, USA, July 29th, 2026, CyberNewswire Catches rogue AI agents – and stops them in live production before they cause damage Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking. Sweet now blocks rogue agent behavior in real time – […]
The post Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to achieve full remote code execution (RCE) with a single HTTP request. This vulnerability, tracked as CVE-2026-59726 and referred to as “RufRoot,” has been assigned a maximum CVSS score of 10.0 due to its ease of exploitation and potential […]
The post Critical Ruflo MCP Bridge Flaw Allows Full AI Agent Platform Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham’s water plant went offline, and the city asked residents to minimize
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


