#Ethiack
Ethiack, empresa fundada por el Cristiano Ronaldo de la ciberseguridad, entra en el mercado español
Ethiack, empresa fundada por el Cristiano Ronaldo de la ciberseguridad, entra en el mercado español
www.abc.es
September 27, 2026 at 4:57 AM
A new exploit allows threat actors to bypass the web application firewalls of nine vendors.

The attack abuses parameter pollution techniques and was found by security firm ETHIACK.

It was tested against 9 WAFs in 17 different configurations.

blog.ethiack.com/blog/bypassi...
September 11, 2025 at 12:27 PM
🚨 We discovered a critical RCE in Ruby on Rails via Active Storage.
KindaRails2Shell - discovered by the Ethiack research team.

Any app using Active Storage with the default vips processor and accepting image uploads from untrusted users is affected.

CVE-2026-66066

ethiack.com/info-hub/res...
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous security
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.
ethiack.com
July 30, 2026 at 1:03 AM
Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.
ethiack.com
September 24, 2026 at 10:58 AM
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack
Autonomous Ethical Hacking for continuous security
ethiack.com
September 24, 2026 at 10:59 AM
Got an arbitrary file write that got closed as medium? It shouldn't have been.

Most AFWs get downgraded because nobody could prove RCE 🥷

Some research we've been doing for years just dropped!

Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack — Autonomous Ethical Hacking for continuous security
Autonomous Ethical Hacking for continuous security
ethiack.com
August 12, 2026 at 9:44 AM
There's no doubt that AI is taking bug bounty hunting to the next level.

Check out the full blog by Ben Lampere for tips, tricks, and tools to supercharge your bug bounty game ➡️ blog.ethiack.com/blog/superch...

Stay tuned for more in the Hacking with AI series! 👀

#bugbounty #ethiack
Super-charging Bug Bounty Hunting with the Power of AI
Discover how AI-driven tools supercharge bug bounty hunting. Boost reconnaissance, streamline vulnerability exploitation, and enhance reporting.
blog.ethiack.com
January 17, 2025 at 12:23 PM
Want to learn how AI can be used for ethical hacking? 

Check out the contents from my workshop on Github! 

You'll find:
✅ Workshop guide
✅ Scripts
✅ Tools
✅ CTF Challenges

Get stuck in (feedback welcome!) at 
GitHub - ethiack/ai4eh: AI for Ethical Hacking - Workshop
AI for Ethical Hacking - Workshop. Contribute to ethiack/ai4eh development by creating an account on GitHub.
github.com
September 1, 2025 at 8:34 AM
Ethiack Claims 1 in 5 UK Telco Servers Exposed to Cyber Risk
https://www.ispreview.co.uk/index.php/2026/04/ethiack-claims-1-in-5-uk-telco-servers-exposed-to-cyber-risk.html
A new survey conducted by agentic AI pentesting firm Ethiack claims to have found that 19% of the web servers used by UK […]
Original post on mastodon.scot
mastodon.scot
April 15, 2026 at 9:46 AM
Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack — Autonomous Ethical Hacking for continuous security
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.
ethiack.com
July 31, 2026 at 11:13 AM
🚨We reported KindaRails2Shell, a critical RCE in Ruby on Rails via Active Storage.

It’s not a one-shot RCE, but the preconditions are kinda common under default configurations.

Patch your applications now!

CVE-2026-66066

ethiack.com/info-hub/res...
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous security
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.
ethiack.com
July 30, 2026 at 1:02 AM
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack
ethiack.com/info-hub/res...
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous security
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.
ethiack.com
July 30, 2026 at 7:39 AM
libvips has flagged matload as untrusted for years and exposes a switch to block it. Rails’ ActiveStorage just never flipped it. Until last week.

That’s CVE-2026-66066: a .mat file declared as image/png, arbitrary file read, then RCE.

Full chain👇

ethiack.com/info-hub/res...
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack — Autonomous Ethical Hacking for continuous security
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.
ethiack.com
August 8, 2026 at 10:08 AM
We just open-sourced EthiBench: a new evaluation protocol for AI pentesting agents.

Ground truth and code available here: https://github.com/ethiack/ethibench
July 14, 2026 at 2:31 PM
A plataforma inovadora para testes contínuos de cibersegurança da startup de Coimbra permite às empresas identificar vulnerabilidades nos seus ativos digitais.
Ethiack: startup portuguesa de "hacker éticos" fecha ronda de 4 milhões de euros
Em dois anos, a ETHIACK alcançou o número mágico do milhão de euros de faturação, através de uma carteira com mais de 50 clientes
pplware.sapo.pt
December 17, 2024 at 10:37 AM
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous security
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.
ethiack.com
July 30, 2026 at 2:13 PM
By @castilho101, @s3np41k1r1t0 and me.

Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack — Autonomous Ethical Hacking for continuous security
Autonomous Ethical Hacking for continuous security
ethiack.com
August 12, 2026 at 9:44 AM
Can you hack a vibe coded PHP app? Yes. Can you use AI to hack the same app? Yes.

Just dropped our workshop on AI for Ethical Hacking.

Full materials 👇

github.com/ethiack/ai4e...

Blog post: blog.ethiack.com/blog/dont-fe...
June 27, 2025 at 5:38 PM
Ready to explore how AI is transforming Ethical Hacking?

We've put together some introductory hands-on examples including:

🔍 Recon & Discovery
⚡ Exploit Development
🤖 Hackbots
🧠 Integrations & Plugins
🏆 CTF Challenges

Check it out: https://github.com/ethiack/ai4eh
July 21, 2025 at 8:07 AM
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack — Autonomous Ethical Hacking for continuous security
Autonomous Ethical Hacking for continuous security
ethiack.com
August 8, 2026 at 9:13 AM
AI Pentesting isn’t the future. It’s already here.

@ethiack.com Hackian hackbot compromised a genetics platform in <4h, finding critical bugs humans missed.

Key takeaway: AI finds different vulnerabilities. Test before “bad guys” do.
Keynote: Discovering the Power of AI Pentesting with Pedro Conde (Ethiack) | AppSec Articles
The Talsec Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4, 2025, and…
docs.talsec.app
January 2, 2026 at 2:58 PM