Critical

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

The Hacker News

Overview

Researchers have identified a serious vulnerability in Ruflo, an open-source agent meta-harness used for AI models like Anthropic Claude Code and OpenAI Codex. This flaw, known as CVE-2026-59726, has a maximum severity rating of 10.0, indicating that it allows unauthenticated attackers to execute remote commands on affected systems. The vulnerability impacts all versions of Ruflo prior to 3.16.3, making it critical for users to update to this version or later. If exploited, this could lead to unauthorized access and manipulation of AI memory, posing risks to data integrity and security. Organizations using Ruflo should prioritize applying the latest updates to safeguard their systems.

Key Takeaways

  • Affected Systems: All versions of Ruflo before version 3.16.3
  • Action Required: Users should update Ruflo to version 3.
  • Timeline: Newly disclosed

Original Article Summary

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Impact

All versions of Ruflo before version 3.16.3

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Users should update Ruflo to version 3.16.3 or later to mitigate this vulnerability.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Update, and 2 more.

Related Coverage

FBI's CJIS v6.1: What Security Teams Need to Know.

BleepingComputer

The FBI has released an updated version of its Criminal Justice Information Services (CJIS) Security Policy, version 6.1, which introduces stricter requirements for encryption and vulnerability scanning. This update reflects a growing emphasis on continuous security assessments in the handling of sensitive criminal justice data. Agencies that rely on CJIS must now enhance their practices around password management, multi-factor authentication (MFA), and identity verification to meet the new standards. As these changes take effect, agencies should prepare for upcoming audits to ensure compliance and protect against potential security risks. This update is particularly important given the sensitive nature of the information processed by law enforcement and criminal justice organizations.

Sep 21, 2026

RatHat Android Trojan Uses AI for Automation

SecurityWeek

The RatHat Android Trojan is a new piece of malware that uses artificial intelligence to enhance its ability to navigate and control infected devices in real-time. This makes it more adaptable and harder to detect by traditional security measures. Users of Android devices are particularly at risk, as the malware can exploit vulnerabilities to take control of their devices. The implications of this are significant, as it could lead to unauthorized access to personal information, financial data, and other sensitive content. As the malware continues to evolve, it raises concerns about the effectiveness of current security protocols against AI-driven threats.

Sep 21, 2026

Rust Team Members and Popular Crate Owners Targeted via Video Calls

SecurityWeek

Members of the Rust programming language team and prominent crate (library) developers have been targeted through video calls in a series of attacks. While it's uncertain if these incidents are part of an ongoing campaign against Rust, the tactics used by the attackers align with those associated with North Korean cyber activities. This situation raises concerns about the security of open-source software development and the potential risks posed to contributors. Developers involved in critical projects may need to bolster their security measures to protect against such targeted harassment and potential data breaches. As these attacks highlight vulnerabilities in communication channels, the incident serves as a reminder for the tech community to remain vigilant.

Sep 21, 2026

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

SecurityWeek

CrowdSec, a cybersecurity firm, has confirmed that its source code was stolen during a supply chain attack linked to the TanStack incident in May 2026. This breach raises significant concerns about the security of software supply chains and the potential for attackers to exploit vulnerabilities in third-party components. The stolen code could allow malicious actors to create unauthorized versions of CrowdSec's software or target its users more effectively. As such, this incident could have far-reaching implications for developers and organizations that rely on CrowdSec's solutions. Companies using their services should be vigilant and review their security protocols to mitigate any risks associated with this breach.

Sep 21, 2026

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

The Hacker News

Cybercriminals are using deceptive tactics to distribute a new remote access trojan (RAT) named ChainScript. This malware disguises itself as popular software applications like Spotify, Zoom Workplace, and Microsoft Teams, making it more likely for users to download it unknowingly. ChainScript has been seen under various names, such as ComponentTask33 and OrchidViolet66. The threat actors are employing ClickFix-like lures to rotate their command and control (C2) infrastructure, which complicates detection and mitigation efforts. This situation poses a significant risk to both individuals and organizations, as it can lead to unauthorized access to sensitive information and systems.

Sep 21, 2026

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The Hacker News

A North Korean hacking group known as Jade Sleet has been linked to a breach involving a smaller Indian IT services firm. Cybersecurity researchers from SentinelOne reported that the attackers used sophisticated backdoors named FLATROOF and ROOFDECK to infiltrate the organization. The breach underscores the ongoing strategy of targeting smaller developers, which can provide access to larger networks. This incident raises concerns about the security practices of IT service providers, as they often hold sensitive information that could be exploited in further attacks. Companies in the tech sector should reassess their security measures to prevent similar breaches.

Sep 21, 2026