ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Rails patched CVE-2026-66066, a critical Active Storage flaw allowing unauthenticated file reads and potential RCE via crafted image uploads when libvips is used. Affected versions include Rails before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1. Upgrading to libvips 8.13 or later and rotating secrets is required.
Tracked by ByteBrief