← Latest briefing

Technology

Government Rails site targeted hours after critical ActiveStorage patch

A state agency faced exploitation attempts less than a day after a high-severity Ruby on Rails vulnerability was disclosed.

The short version

  • Security firm Rietta reported that a state government client faced an exploit attempt on July 30, 2026, hours after patching a critical Ruby on Rails ActiveStorage vulnerability (CVE-2026-66066).
  • A public proof-of-concept appeared on GitHub shortly after the patch shipped, effectively circumventing an intended disclosure embargo scheduled through late August.
  • The targeted government system and other patched clients successfully repelled the initial attack and subsequent sustained scanning throughout August.
  • The identity and specific motivations of the attackers remain unconfirmed as security teams continue monitoring adaptive probing campaigns.

Key facts

  • Ruby on Rails released a patch on July 29, 2026, for CVE-2026-66066 (dubbed KindaRails2Shell), a remote code execution vulnerability in ActiveStorage rated 9.5 out of 10 on the CVSS scale.[Hacker News]
  • A public proof-of-concept exploit utilizing a malformed BMP file was published to GitHub on July 29, 2026, roughly five hours before Rietta completed emergency patch deployments for its clients.[Hacker News]
  • An unauthorized attack attempt using a malformed BMP file targeted a state government client's application at 7:10 AM EST on July 30, 2026, approximately eight hours after the hotfix was applied.[Hacker News]
  • The rapid emergence of public reverse-engineered exploits prompted Rails and researchers to release forensic tools and technical write-ups weeks ahead of the original August 28 embargo date.[Hacker News]
  • A wider, automated scanning campaign utilizing rotating international IP addresses and modified file types began on August 3, 2026, and persisted throughout the month without breaching the patched systems.[Hacker News]

What remains uncertain

  • Whether the July 30 attack directly originated from the specific GitHub proof-of-concept or from an independently engineered exploit is unproven.[Hacker News]
  • The identity, precise degree of automation, and overall motivations of the actors conducting the sustained August scanning campaign remain undisclosed.[Hacker News]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.