View all sources for this day →

The Signal

Security attention here is divided between responding to disclosed or ongoing incidents and examining trusted interfaces that can broaden attacker access. The latter includes server upload handling, signed drivers, and agent-skill execution environments. [1][2][3][4][5]

Must Know

Ruby on Rails KindaRails2Shell vulnerability

Vulnerability · Research

What happened

Researchers reported a critical vulnerability, CVE-2026-66066, in Ruby on Rails that may let attackers read sensitive server files and, in some cases, take full control of the server. [3]

The reported attack involves disguising a malicious file to bypass a website’s image-upload feature and access server secrets. [3]

Why it matters

The reported path makes upload validation a relevant boundary between accepting content and protecting server-side secrets. [3]

Vulnerable signed-driver attacks

Vulnerability · Platform

What happened

Attackers seeking kernel access on Windows can bring a Microsoft-trusted, signed driver with a known flaw; exploiting it may enable memory tampering or disabling host security software. [4]

Why it matters

The source says that kernel-level access can make the host’s security tools stop reliably protecting it, and that ransomware crews use the technique before deploying a payload. [4]

PNLD breach disclosure

Identity · Incident

What happened

The Police National Legal Database (PNLD), used by all 43 Home Office police forces in England and Wales, confirmed that a breach exposed names, organisations and work email addresses of police, staff and other criminal-justice professionals, with data published on the dark web. [1]

The incident primarily affected PNLD, which hosts the Ask the Police public Q&A service; some names and email addresses of people who previously submitted questions were also published on the dark web. [1]

Why it matters

The reported exposure creates separate risks: targeted phishing against named officers using their organisations and work emails, and disclosure that members of the public had contacted police services. [1]

River Bank breach response

Incident

What happened

River Financial Corporation, including River Bank & Trust, reported that an unauthorized actor accessed its network on or about June 16, 2026, and ransomware was deployed across portions of its server environment. [2]

River later confirmed that attackers accessed parts of its network and stole data, but the company was still determining what information was affected, including whether personal data was exposed. [2]

Why it matters

River said it obtained representations from the threat actor that the stolen data in the actor’s possession had been deleted; the company described this as an effort to suppress the affected data, not as a confirmed resolution of the incident. [2]

NVIDIA SkillSpector agent-skill scanner

AI & Agents · Security

What happened

SkillSpector is an open-source NVIDIA scanner that assesses AI-agent skills and reports findings, a risk score, and recommendations. [5]

The scanner accepts a directory, ZIP file, individual SKILL.md file, or Git URL as input. [5]

Why it matters

A scanned skill folder runs with the user’s available access, while a skill may include Markdown instructions and an accompanying Python script that can reach the shell and environment. [5]

Also Worth Knowing

Alleged Żabka Jira data exposure

Incident · Platform

What happened

Ransomnews reported an alleged Żabka Polska data leak offered for €5,000, including Jira data, IT service-desk tickets, and source code from 89 GitLab repositories; Żabka had not confirmed a breach. [6]

DarkSword and GHOSTBLADE iOS campaign

Cloud

What happened

An unknown Chinese threat actor was observed targeting Apple iOS devices with a publicly leaked version of the DarkSword exploit kit. [7]

Sources (7)
  1. [1] PNLD Confirms Data Breach Affecting UK Police and Justice Staff

    securityaffairs · August 3, 2026

  2. [2] River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted

    securityaffairs · August 3, 2026

  3. [3] KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

    helpnetsecurity · August 3, 2026

  4. [4] Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support

    helpnetsecurity · August 3, 2026

  5. [5] SkillSpector: NVIDIA’s open-source security scanner for AI agent skills

    helpnetsecurity · August 3, 2026

  6. [6] Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys

    securityaffairs · August 3, 2026

  7. [7] Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

    the hacker news · August 3, 2026