Government Rails Site Hit Hours After CVE Patch
On July 30, 2026, just hours after a severe remote code execution vulnerability in ActiveStorage of Ruby on Rails 8 was patched, a government rail site was compromised. The CVE-2026-66066, named KindaRails2Shell by researchers Ethiack, was disclosed on the same day. The patch introduced a public code diff but withheld detailed exploitation information under embargo.
Despite the embargo, a proof-of-concept exploit was publicly available on GitHub 5 hours before the patch was fully deployed, and the first attack on the government rail site occurred 11 hours later. The initial attack involved a maliciously formed BMP file, which correlated with the public proof-of-concept exploit. The vulnerability research ecosystem's rapid pace likely led to the attack occurring before the embargo lifted, rather than the attacker's skill or speed.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.