Image uploads can leak Rails master keys through critical Active Storage bug

A CVSS 9.5 Rails Active Storage flaw lets unauthenticated attackers read arbitrary server files through crafted image uploads.

The Latest

Breaking News and Alerts

Microsoft 365 accounts hijacked through compromised hotel Wi-Fi gateways

Threat actors compromised captive Wi-Fi gateways at hotels to silently redirect business travelers to fake Microsoft 365 login pages.

Spotlight

Cybersecurity Profiles and Stories

Hollowgraph malware turns Microsoft 365 calendars into covert spy channels

Group-IB discovered HOLLOWGRAPH, malware that uses Microsoft 365 calendars as covert command channels with events dated to 2050.

Russian Laundry Bear group exploits Zimbra zero-day to steal email and 2FA codes

US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.

ChatGPT AgentForger bug lets phishing links deploy rogue workspace agents

A vulnerability in OpenAI's ChatGPT workspace agent system could let attackers deploy malicious agents through a single phishing link.

Kimi K3 AI agents discover Redis zero-days and build working RCE exploits

Chinese AI agents from Kimi K3 autonomously found zero-day vulnerabilities in Redis and developed functional remote code execution exploits.

Features

Research and Thought Leadership