The Signal
Must Know
Ruby on Rails KindaRails2Shell vulnerability
What happened
Researchers reported a critical vulnerability, CVE-2026-66066, in Ruby on Rails that may let attackers read sensitive server files and, in some cases, take full control of the server. [3]
The reported attack involves disguising a malicious file to bypass a website’s image-upload feature and access server secrets. [3]
Why it matters
The reported path makes upload validation a relevant boundary between accepting content and protecting server-side secrets. [3]
Vulnerable signed-driver attacks
What happened
Attackers seeking kernel access on Windows can bring a Microsoft-trusted, signed driver with a known flaw; exploiting it may enable memory tampering or disabling host security software. [4]
Why it matters
The source says that kernel-level access can make the host’s security tools stop reliably protecting it, and that ransomware crews use the technique before deploying a payload. [4]
PNLD breach disclosure
What happened
The Police National Legal Database (PNLD), used by all 43 Home Office police forces in England and Wales, confirmed that a breach exposed names, organisations and work email addresses of police, staff and other criminal-justice professionals, with data published on the dark web. [1]
The incident primarily affected PNLD, which hosts the Ask the Police public Q&A service; some names and email addresses of people who previously submitted questions were also published on the dark web. [1]
Why it matters
The reported exposure creates separate risks: targeted phishing against named officers using their organisations and work emails, and disclosure that members of the public had contacted police services. [1]
River Bank breach response
What happened
River Financial Corporation, including River Bank & Trust, reported that an unauthorized actor accessed its network on or about June 16, 2026, and ransomware was deployed across portions of its server environment. [2]
River later confirmed that attackers accessed parts of its network and stole data, but the company was still determining what information was affected, including whether personal data was exposed. [2]
Why it matters
River said it obtained representations from the threat actor that the stolen data in the actor’s possession had been deleted; the company described this as an effort to suppress the affected data, not as a confirmed resolution of the incident. [2]
NVIDIA SkillSpector agent-skill scanner
What happened
SkillSpector is an open-source NVIDIA scanner that assesses AI-agent skills and reports findings, a risk score, and recommendations. [5]
The scanner accepts a directory, ZIP file, individual SKILL.md file, or Git URL as input. [5]
Why it matters
A scanned skill folder runs with the user’s available access, while a skill may include Markdown instructions and an accompanying Python script that can reach the shell and environment. [5]
Also Worth Knowing
Alleged Żabka Jira data exposure
What happened
Ransomnews reported an alleged Żabka Polska data leak offered for €5,000, including Jira data, IT service-desk tickets, and source code from 89 GitLab repositories; Żabka had not confirmed a breach. [6]
DarkSword and GHOSTBLADE iOS campaign
What happened
An unknown Chinese threat actor was observed targeting Apple iOS devices with a publicly leaked version of the DarkSword exploit kit. [7]