Technology
Government Rails site targeted hours after critical ActiveStorage patch
A state agency faced exploitation attempts less than a day after a high-severity Ruby on Rails vulnerability was disclosed.
The short version
- Security firm Rietta reported that a state government client faced an exploit attempt on July 30, 2026, hours after patching a critical Ruby on Rails ActiveStorage vulnerability (CVE-2026-66066).
- A public proof-of-concept appeared on GitHub shortly after the patch shipped, effectively circumventing an intended disclosure embargo scheduled through late August.
- The targeted government system and other patched clients successfully repelled the initial attack and subsequent sustained scanning throughout August.
- The identity and specific motivations of the attackers remain unconfirmed as security teams continue monitoring adaptive probing campaigns.
Key facts
- Ruby on Rails released a patch on July 29, 2026, for CVE-2026-66066 (dubbed KindaRails2Shell), a remote code execution vulnerability in ActiveStorage rated 9.5 out of 10 on the CVSS scale.[Hacker News]
- A public proof-of-concept exploit utilizing a malformed BMP file was published to GitHub on July 29, 2026, roughly five hours before Rietta completed emergency patch deployments for its clients.[Hacker News]
- An unauthorized attack attempt using a malformed BMP file targeted a state government client's application at 7:10 AM EST on July 30, 2026, approximately eight hours after the hotfix was applied.[Hacker News]
- The rapid emergence of public reverse-engineered exploits prompted Rails and researchers to release forensic tools and technical write-ups weeks ahead of the original August 28 embargo date.[Hacker News]
- A wider, automated scanning campaign utilizing rotating international IP addresses and modified file types began on August 3, 2026, and persisted throughout the month without breaching the patched systems.[Hacker News]
What remains uncertain
- Whether the July 30 attack directly originated from the specific GitHub proof-of-concept or from an independently engineered exploit is unproven.[Hacker News]
- The identity, precise degree of automation, and overall motivations of the actors conducting the sustained August scanning campaign remain undisclosed.[Hacker News]
Sources
Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.