Hacker News
A Ruby on Rails CVE Was Being Exploited in the Wild 8 Hours and 1 Minute After the Patch Shipped
Rietta published a post-mortem on September 4 for CVE-2026-66066, a 9.5-CVSS RCE in Rails 8+ ActiveStorage, nicknamed KindaRails2Shell. The patch shipped July 29 and Rietta deployed it at 11:09 PM EST; the first attack on a state government Rails site it hosts arrived at 7:10:25 AM EST the next morning, a gap of 8 hours 1 minute. The initial payload was a malformed BMP file matching a public proof-of-concept committed to GitHub at 9:47:30 PM UTC on July 29, and the attackers adapted their approach when new mitigations went in, which points at adaptive automated frameworks rather than hand exploitation.
↳ Follow the thread