Rails KindaRails2Shell Under Attack, Fire Ant Implants Cisco IOS XR Routers, and a Public Kaspersky Endpoint LPE Exploit

Covering the trailing ~48 hours (August 29–31, 2026). Every item below was checked against its primary advisory, vendor blog, or original research before inclusion.

Rails “KindaRails2Shell” (CVE-2026-66066) comes under active exploitation

VulnCheck · August 31, 2026

Attackers have begun exploiting CVE-2026-66066 (CVSS 9.5), the pre-auth arbitrary file read to RCE chain in Ruby on Rails Active Storage that abuses parser confusion between Rails, libvips, libmatio, and HDF5 to read attacker-chosen server files as “image” pixels. Affected releases are Rails 7.2.0–7.2.3.1, 8.0.0–8.0.5, and 8.1.0–8.1.3 in default configuration; fixes shipped in 7.2.3.2, 8.0.5.1, and 8.1.3.1 in late July. VulnCheck reported exploitation roughly a month after patches landed, following public PoC code, and previously counted around 7,000 exposed Rails instances. The flaw is not currently listed in CISA’s KEV catalog. VulnCheck also warns that patching does not close the whole chain.

“[W]hile the fix blocks the libvips file read, it does not neutralize the variation-key Marshal deserialization: the RCE gadget still executes on a patched server given a valid signature.” — VulnCheck

Source: VulnCheck initial access intelligence · Rails forensic tooling · SecurityWeek

Fire Ant turns Cisco IOS XR routers and TACACS servers into collection platforms

Sygnia · August 30, 2026

Sygnia published an investigation into the China-nexus actor Fire Ant, which has moved beyond its 2025 VMware ESXi and vCenter tradecraft into the network and identity layer: Cisco IOS XR edge routers, TACACS authentication servers, and Linux management hosts. On the routers, the actor deployed purpose-built implants that hooked the IOS XR logging path — a modified syslog library that forwarded a message only if it contained the string “Health” — and appended an | exclude filter to show command output to hide its GRE tunnel from administrators. Investigators also found a VMCI-socket backdoor on the TACACS server and a credential-collection toolset Sygnia tracks as TacTap, plus PCAP captures exported from multiple routers to external FTP infrastructure. No CVE is attached; this is post-compromise abuse of trusted infrastructure rather than a single exploited flaw.

“[W]hen a threat actor controls routers, they do not only gain reach. They gain perspective.” — Sygnia

Source: Sygnia research · BleepingComputer

“HardBreacher” PoC drops for a Kaspersky Endpoint Security privilege escalation

Nightmare Eclipse / Kaspersky · August 31, 2026

The researcher known as Nightmare Eclipse (also Chaotic Eclipse) released a public proof-of-concept over the weekend targeting a privilege escalation vulnerability in Kaspersky Endpoint Security, dubbed HardBreacher. No CVE ID or CVSS score has been assigned publicly. Kaspersky told SecurityWeek the underlying issue is resolved and that the fix ships through automatic database updates, so an operator who has disabled or delayed database updates remains exposed. The same researcher’s prior drops — ShieldBreak and LegacyHive — targeted Windows and Microsoft Defender, and a few have gone on to be exploited in the wild.

“The interesting part about this is the Kaspersky completely loses it when you take control over the UI process, you can cause it to stop functioning, grant/block access to files its not supposed to, if the PoC succeeds, the entire operating system becomes a hot mess.” — Nightmare Eclipse

Source: HardBreacher PoC · SecurityWeek

Microsoft details “TerminalFix,” a ClickFix variant that ends in a reverse tunnel

Microsoft Threat Intelligence · August 29, 2026

Microsoft published analysis of a social-engineering campaign it calls TerminalFix, which serves fake Cloudflare CAPTCHA overlays on compromised websites, silently copies a malicious PowerShell command to the victim’s clipboard, and steers them into Windows Terminal or PowerShell rather than the Run dialog. The chain that follows uses DLL sideloading and steganographic payload extraction to plant a reverse-tunnel implant, giving the operator a route into the internal network — a materially worse outcome than the infostealer payloads typical of ClickFix. There is no vulnerability to patch here; the campaign relies entirely on user execution, and Microsoft’s post includes detection and hunting guidance.

“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully.” — Microsoft Threat Intelligence

Source: Microsoft Security Blog · BleepingComputer

Silver Fox hides ValleyRAT inside signed Chinese adware

Kaspersky (Securelist) · August 31, 2026

Kaspersky documented a new ValleyRAT (Winos 4.0) distribution wave attributed to Silver Fox, built around QN Wallpaper — a real Chinese desktop-wallpaper tool that is adware in its unmodified form. The installer unpacks a modified copy and runs the signed QnWallpaper.exe, which sideloads a malicious libcef.dll from the same directory, so the backdoor executes inside a legitimately signed process. The abuse is compounded by users adding adware of this kind to their antivirus exclusions. Kaspersky recorded more than 100,000 detections of ValleyRAT and related malware during 2026 across over 1,500 unique users, primarily in China and India. No CVE is involved.

“This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear.” — Kaspersky

Source: Securelist

Cronos halts its blockchain after a ~$75M Tectonic lending exploit

Cronos / Tectonic · August 30, 2026

An attacker inflated the price of the thinly traded TONIC governance token roughly 100x in about 20 minutes, deposited the revalued tokens into the Tectonic lending protocol, and borrowed real assets against the manipulated collateral — a price-oracle manipulation in the mold of the 2022 Mango Markets attack rather than a code vulnerability with a CVE. Validators halted the Cronos chain in response, limiting the attacker to roughly $6 million bridged to Ethereum out of an estimated $75 million affected. The network has since resumed trading; Tectonic’s total value locked fell from about $121.7 million on August 26 to roughly $3 million.

Source: The Block · CoinDesk · BleepingComputer


This brief covers the trailing ~48 hours (August 29–31, 2026).

Primary sources:

One thought on “Rails KindaRails2Shell Under Attack, Fire Ant Implants Cisco IOS XR Routers, and a Public Kaspersky Endpoint LPE Exploit

  1. Pingback: CVE-2026-66066?Rails Active Storage ????????CVSS 9.5 PoC ???

Leave a Reply