CVE-2026-66066
Domains:
78[.]138, getmacouscloud[.]com, macostruecloud[.]xyz, macspheres[.]com, render65[.]com, grove-89[.]com
Hashes:
b9ec3261d633c289e51c5fa8842af4350efe68446df39cb995de82e0941d0f3c, 13b868b3ea8b492e7fbab1ca04535c53d0930650185b5a082cd59c1974689cd5, 9f25ec533cb23d020e568fb771500d7776b1300f07119ad9d0876f4329ce22ab, 0a03cf18de28017c0ea591dffc380a6b41fedd2acc3a39e901e58d9188c01836
IP Addresses:
7.2.3.2, 8.0.5.1, 8.1.3.1
Get tomorrow's brief in your inbox
Today: A critical Ruby on Rails RCE vulnerability (CVE-2026-66066, CVSS 9.5) requires immediate patching for any app using Active Storage with libvips. A firmware flaw in Coldcard hardware wallets enabled a $70 million Bitcoin theft across 1,196 addresses. Healthcare continues to take hits: CareCloud disclosed a 350,000-record breach from its AWS environment, DeadLock ransomware claimed Spanish biopharma firm Diater, and multiple hospitals reported phishing compromises.
Ruby on Rails Remote Code Execution via Active Storage (CVE-2026-66066)
An arbitrary file read in Rails Active Storage allows unauthenticated attackers to read any file accessible to the application process, including environment variables containing secret_key_base and external credentials. Attackers can escalate file read to full RCE. CVSS 9.5, EPSS 0.017 (75th percentile). Affects applications using libvips for image processing that accept uploads from untrusted users. No evidence of exploitation in the wild as of July 30.
secret_key_base, database passwords, and API keys. Patching closes the vector but does not undo prior exfiltration.DeadLock Ransomware Claims Spanish Biopharma Firm Diater
Ransomware group DeadLock listed biopharmaceutical company Diater (Madrid, founded 1999) on its dark web leak site. Diater manages sensitive patient and healthcare professional data accumulated over a decade. The double extortion approach threatens both encryption and data publication. Healthcare and pharma organizations remain high-value targets due to the sensitivity of medical records.
Atomic macOS Stealer (AMOS) - Active Campaign
SANS ISC documented a live AMOS stealer infection chain. The attack uses fake "macOS toolkit" websites that instruct users to paste commands into Terminal. The malware steals credentials, browser data, cryptocurrency wallets, and messenger data.
Key IOCs:
- C2 IP: 188.166.78[.]138 (TCP 80, HTTP POST to /api/metrics/run, /contact, /api/join/, /api/bots/device-info)
- Domains: getmacouscloud[.]com, macostruecloud[.]xyz, macspheres[.]com, render65[.]com, grove-89[.]com
- Hashes (SHA-256):
- b9ec3261d633c289e51c5fa8842af4350efe68446df39cb995de82e0941d0f3c (initial zsh script)
- 13b868b3ea8b492e7fbab1ca04535c53d0930650185b5a082cd59c1974689cd5 (extracted script)
- 9f25ec533cb23d020e568fb771500d7776b1300f07119ad9d0876f4329ce22ab (Mach-O binary, /tmp/helper)
- 0a03cf18de28017c0ea591dffc380a6b41fedd2acc3a39e901e58d9188c01836 (persistence binary)
Coldcard Hardware Wallet Firmware Flaw Enables $70M Bitcoin Theft
A firmware integration error dating to March 2021 caused Coldcard hardware wallets to use a weak software PRNG instead of the STM32 hardware RNG for seed generation. Effective entropy dropped to roughly 40 bits on Mk3 and 72 bits on Mk4/Mk5/Q (vs. the expected 128 bits for a 12-word BIP-39 seed). An attacker exploited this to drain 1,082.65 BTC ($70.2M) from 1,196 addresses in 41 minutes on July 30. Coinkite shipped emergency firmware on July 31. Affected versions: Mk2/Mk3 versions 4.0.0-4.1.9, Mk4/Mk5 before 5.6.0, Q before 1.5.0Q.
CareCloud Data Breach Impacts 350,000+ Individuals
Healthcare IT company CareCloud disclosed that attackers accessed an AWS environment hosting electronic health records within its CareCloud Health division. The breach, discovered March 16, 2026, compromised personal and medical information of at least 350,000 people. The incident highlights ongoing risks in cloud-hosted healthcare platforms.
Oceanside, CA School District Systems Disrupted by Suspected Cyberattack
Oceanside Unified School District experienced disruptions to email, internet access, Google Drive, and other applications. The district confirmed a network disruption; separate communications described it as a cyberattack. Systems are being restored.
Healthcare Phishing: Two More Facilities Disclose Breaches
Mon General Hospital (West Virginia) discovered a phishing attack on May 6 targeting a small number of employee accounts, potentially compromising patient personal and medical information. Separately, GO2 Health clinic in Brisbane, Australia waited nearly three months after an April phishing attack to notify patients that their main email mailbox was accessed. The delayed notification pattern continues to be a problem in healthcare.
Joomla Extensions Under Active Exploitation (CVSSv3 10.0)
Attackers are exploiting critical vulnerabilities (perfect CVSS 10.0 scores) in two Joomla extensions: iCagenda and Balbooa Forms. Joomla powers roughly one million websites. Organizations running these extensions should patch or disable them immediately.
DEF CON 2026: Franklin Project and Baochip-1x Security Key Badge
DEF CON launched the Franklin Project, expanding the voting village model to enlist hackers in hardening critical infrastructure across the entire conference. This year's badge, designed by bunnie Huang, features the Baochip-1x, an open source microcontroller designed for verifiable security. The badge doubles as a hardware security token post-conference, with published source code for inspection.
FCC Data Breach Rules Face Sixth Circuit Rehearing
The Sixth Circuit will rehear in full a case upholding expanded telecom data breach notification rules. The FCC under Republican leadership has indicated it will likely reverse the rules, but industry groups and GOP lawmakers want the legal precedent eliminated as well.
CVE-2026-66066 - Ruby on Rails Active Storage Arbitrary File Read
CVSS 9.5 critical. Unauthenticated arbitrary file read in Rails applications using libvips for Active Storage image processing. Affects apps accepting untrusted image uploads. The flaw stems from libvips "unfuzzed" (unsafe) file operations that Active Storage failed to disable. Leads to secret exfiltration and RCE. Fixed in Active Storage 7.2.3.2, 8.0.5.1, 8.1.3.1. EPSS: 0.017 (75th percentile). No known exploitation as of July 30.
Healthcare remains the most targeted sector this cycle: four separate incidents (CareCloud, Diater, Mon General, GO2 Health) spanning ransomware, cloud compromise, and phishing. The GO2 Health three-month notification delay underscores that breach detection-to-disclosure timelines in healthcare remain a systemic problem. Supply chain trust in hardware is also under scrutiny, with the Coldcard PRNG flaw demonstrating that a single misconfigured build macro can undermine years of security assumptions.