RAILS PATCHES CRITICAL ACTIVE STORAGE VULNERABILITY
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Ruby on Rails has released a patch for a critical flaw in its Active Storage framework that allows unauthenticated attackers to read arbitrary files and potentially execute remote code on affected applications.
■ MORE FROM THE SECURITY DESK
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.
Healthcare software company Unlimited Technology Systems disclosed a data breach affecting 3.8 million individuals. The breach occurred in October 2025.
Cybercriminals are leveraging artificial intelligence to discover and exploit security weaknesses at unprecedented speeds, creating threats that traditional defenses were never designed to counter.