Ruby, Rails & AI Daily: Active Storage RCE Under Active Exploitation, ZJIT Inlines GC
Kicking off a daily roundup on RubyInsights covering Ruby, Rails, and AI. Today’s edition leads with CVE-2026-66066 (“KindaRails2Shell”), the Active Storage RCE that’s now confirmed under active exploitation months after patches shipped for Rails 7.2.3.2, 8.0.5.1, and 8.1.3.1, worth a fleet check even if you patched back in July. Also covered: ZJIT learning to inline GC allocations, this week’s Rails codebase updates, Claude Fable 5.1 topping the Agents on Rails benchmark, Chrome 153’s 230 security fixes, and the new wave of cybersecurity-focused models from OpenAI, Anthropic, and Google. Full roundup with sources.
Post a comment