Tech & AI News
Hacker News

Government Rails Site Hit Hours After CVE Patch

Rietta released an emergency hotfix for the CVE-2026-66066 “KindaRails2Shell” remote-code-execution flaw in ActiveStorage on July 29, 2026, and deployed it to all client sites by 11:30 PM EST. The first client exploit occurred at 7:10 AM EST on July 30, eight hours later. Forensic tools were leaked on July 30, and Ethiack issued a full technical write-up on July 31.