{
  "id": 5626960,
  "title": "Government Rails Site Hit Hours After CVE Patch",
  "url": "https://urgent.news/2026/09/04/government-rails-site-hit-hours-after-cve-patch",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-04T19:06:39.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/"
  },
  "original_language": "en",
  "account": "On July 30, 2026, just hours after a severe remote code execution vulnerability in ActiveStorage of Ruby on Rails 8 was patched, a government rail site was compromised. The CVE-2026-66066, named KindaRails2Shell by researchers Ethiack, was disclosed on the same day. The patch introduced a public code diff but withheld detailed exploitation information under embargo. Despite the embargo, a proof-of-concept exploit was publicly available on GitHub 5 hours before the patch was fully deployed, and the first attack on the government rail site occurred 11 hours later. The initial attack involved a maliciously formed BMP file, which correlated with the public proof-of-concept exploit. The vulnerability research ecosystem's rapid pace likely led to the attack occurring before the embargo lifted, rather than the attacker's skill or speed.",
  "summary": null,
  "key_points": [
    "CVE-2026-66066 vulnerability patched on July 30, 2026",
    "Government rail site compromised 11 hours after patch",
    "Malicious BMP file exploited public proof-of-concept"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}