#RufRoot
-Far-right image board builds AI doxing tool
-New NullReceiver C2 technique
-New Fuyao ad fraud botnet
-New OctLurk and SilkLurk malware
-Storm-1516's Armenia campaign
-KindaRails2Shell vulnerability
-RufRoot vulnerability
-Apple introduces bug reporting cool-offs
-WaterISAC denounces leak
August 3, 2026 at 7:58 AM
#AI: RufRoot a Critical (CVSS 10) MCP bridge vulnerability in #Ruflo, an open source AI agent orchestration platform with 67,000+ GitHub stars and ranked #2 on MCPMarket turns AI Agents into Rogue Admins:
#AISecurity
👇
RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726) - Noma Security
TL;DR Noma Labs found a critical (10 CVSS) vulnerability in Ruflo, an open source AI agent orchestration platform with more than 67,000 GitHub stars at the time of this writing and ranked #2 on MCPMarket. Ruflo ships with a chat UI, agent swarms, persistent memory, and MCP-based tool calling. The platform’s MCP Bridge, the Express.js […]
noma.security
July 30, 2026 at 12:27 AM
🚨 A critical CVSS 10.0 "RufRoot" vulnerability highlights the need for immediate patching and secure configuration reviews.

🌐 spoofguard.io/blog/en/spoo...

#Vulnerability #CVSS10 #ThreatIntelligence #PatchManagement #SpoofGuard #InfoSec

Try it for FREE. 🆓
Spoofing Detection: CVSS 10 RufRoot Flaw Revealed | Spoofguard.io
✓ Spoofing detection helps organizations respond to the CVSS 10.0 RufRoot flaw. Learn the risks and best protection strategies.
spoofguard.io
July 30, 2026 at 6:10 AM
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
www.darkreading.com
July 29, 2026 at 3:55 PM
A vulnerability named RufRoot, tracked as CVE-2026-59726, affects Ruflo versions before 3.16.3, allowing attackers to execute commands without authentication via the exposed Model Context Protocol (MCP) bridge. This flaw, with a CVSS score of 10.
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
hackread.com
July 30, 2026 at 1:11 AM
A CVSS 10.0 flaw called #RufRoot in Ruflo exposed its MCP bridge without authentication, allowing command execution and putting AI provider keys, stored conversations, and persistent agent memory at risk.

Listen/Read: hackread.com/rufroot-vuln...

#Cybersecurity #Ruflo #Vulnerability #AI #InfoSec
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
hackread.com
July 29, 2026 at 3:16 PM
RufRoot: The Critical AI Agent Vulnerability That Turned Ruflo Into a Potential Gateway for Full System Takeover + Video

Introduction: When AI Agents Become Attackers’ Newest Target Artificial intelligence agents are rapidly moving from experimental tools into enterprise environments where they…
RufRoot: The Critical AI Agent Vulnerability That Turned Ruflo Into a Potential Gateway for Full System Takeover + Video
Introduction: When AI Agents Become Attackers’ Newest Target Artificial intelligence agents are rapidly moving from experimental tools into enterprise environments where they can execute commands, access databases, manage workflows, and make autonomous decisions. This evolution brings enormous productivity benefits, but it also creates a new cybersecurity battlefield: the infrastructure that powers AI agents themselves. A newly disclosed vulnerability in Ruflo, an open-source AI agent orchestration platform, demonstrates how dangerous poorly protected AI control planes can become.
undercodenews.com
July 29, 2026 at 2:31 PM
Patch, then rotate provider keys, then audit the memory store. Skip the third step and you have a clean version running poisoned context.

noma.security/blog/rufroo...
RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726) - Noma Security
TL;DR Noma Labs found a critical (10 CVSS) vulnerability in Ruflo, an open source AI agent orchestration platform with more than 67,000 GitHub stars at the time of this writing and ranked #2 on MCPMarket. Ruflo ships with a chat UI, agent swarms, persistent memory, and MCP-based tool calling. The platform’s MCP Bridge, the Express.js […]
noma.security
August 7, 2026 at 7:00 PM
RufRoot CVE-2026-59726:認証なしのRCEでRuflo MCP Bridgeが露呈させたAIエージェントの鍵

認証されていない1件のPOSTリクエストだけで、GitHub上で最も広く導入されているAIエージェント・オーケストレーションプラットフォームの一つにコマンドシェルを開くことができました。この足がかりを得た攻撃者は、OpenAIやAnthropicのAPIキーを窃取し、ユーザーの会話履歴を読み取り、...
RufRoot CVE-2026-59726:認証なしのRCEでRuflo MCP Bridgeが露呈させたAIエージェントの鍵
認証されていない1件のPOSTリクエストだけで、GitHub上で最も広く導入されているAIエージェント・オーケストレーションプラットフォームの一つにコマンドシェルを開くことができました。この足がかりを得た攻撃者は、OpenAIやAnthropicのAPIキーを窃取し、ユーザーの会話履歴を読み取り、
blackhatnews.tokyo
August 4, 2026 at 12:38 PM
Ruflo's default config shipped with zero auth on its MCP bridge, so anyone could hijack agent tools with one request. Patch closes the door but leaves poisoned memory intact. Updating isn't remediation, it's a false sense of clean.
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
hackread.com
July 30, 2026 at 7:18 PM
Badacze z Noma Labs ujawnili lukę RufRoot o najwyższym stopniu zagrożenia, która pozwalała na przejęcie kontroli nad systemem Ruflo. Przez błąd w komponencie MCP Bridge napastnicy mogli kraść klucze API i instalować backdoory jednym żądaniem HTTP.
Krytyczna luka w Ruflo. Jak brak autoryzacji wystawił agentów AI na zdalny atak
Badacze z Noma Labs ujawnili lukę RufRoot o najwyższym stopniu zagrożenia, która pozwalała na przejęcie kontroli nad systemem Ruflo. Przez błąd w komponencie MCP Bridge napastnicy mogli kraść klucze API i instalować backdoory jednym żądaniem HTTP.
aisight.pl
August 30, 2026 at 10:21 AM
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
hackread.com
August 9, 2026 at 2:12 AM
The part of RufRoot that changes your incident response: the attacker could write to AgentDB, the persistent learning store.

Upgrading closes the entry point. It does not remove instructions already written into memory. Those get retrieved later and shape how agents answer other users' tasks.
August 7, 2026 at 7:00 PM
CVSS 10.0: Ruflo's AI agent platform shipped with an unauthenticated management bridge open to the network by default. One HTTP request = stolen LLM keys + hijacked agents. CVE-2026-59726 "RufRoot". Patch to 3.16.3 now. 
zurl.co/SrOJJ
zurl.co/6ItUy

#diesec
August 5, 2026 at 8:00 AM
Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms
July 31, 2026 at 11:41 PM
RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins https://packetstorm.news/news/view/42575 #news
July 30, 2026 at 6:26 PM
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
#hackernews #news
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
hackread.com
July 30, 2026 at 4:06 PM
パッチ耐性のある「RufRoot」の脆弱性により、悪意のあるAIエージェント群が解き放たれる可能性

Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms #DarkReading (Jul 29)

www.darkreading.com/cyber-risk/p...
July 30, 2026 at 9:30 AM
Critical Ruflo flaw, CVE-2026-59726, left POST /mcp unauthenticated, enabling command execution in the bridge container. Impact: shell access, API key theft, swarm takeover, and AgentDB poisoning. Fixed in Ruflo 3.16.3. #Ruflo #RufRoot #AgentDB
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 
A critical flaw in the open source AI agent orchestration platform Ruflo, tracked as CVE-2026-59726 and dubbed RufRoot, allowed unauthenticated attackers to execute commands inside the bridge container. Successful exploitation could lead to shell access, API key theft, agent swarm takeover, and poisoning of the AgentDB learning store, and the issue...
www.hendryadrian.com
July 30, 2026 at 11:45 AM
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenti…
#anthropic #claude #openai
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
thehackernews.com
July 30, 2026 at 5:07 PM
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security. The flaw, tracked as CVE-2026-59726 and dubbed RufRoot, carries a maximum CVSS score of 10.0 and affects Ruflo versions prior to 3.16.3, Noma Security wrote in a blog post. The vulnerability allows attackers to execute arbitrary code, steal large language model (LLM) API keys, access user conversations, hijack AI agents, and manipulate the platform’s persistent AI memory through a single HTTP request. The researchers said the issue stems from an unauthenticated MCP Bridge that is exposed by default and provides direct access to the tools AI agents use to interact with enterprise systems. “The MCP Bridge isn’t a random auxiliary debug interface; rather, it is Ruflo’s central nervous system. Every tool call, every agent action, every memory operation goes through the MCP bridge,” the researchers wrote. “Mistakenly giving unauthenticated access to the MCP Bridge means giving unauthenticated access to everything.” ## One request leads to full compromise According to Noma Security, Ruflo’s built-in MCP Bridge is an Express.js server that handles every tool invocation made by AI agents. The bridge exposes 233 tools covering shell access, database operations, agent management, and memory storage. The researchers said the bridge’s /mcp endpoint accepts tool invocations without authentication. In a proof-of-concept demonstration, they used Ruflo’s terminal_execute tool to obtain command execution inside the container with a single HTTP request. “Because the MCP Bridge requires direct access to the underlying system resources to execute these commands, it creates a high-stakes security boundary,” the researchers wrote. “When an attacker can reach this endpoint without authentication, they gain a direct pipeline to the underlying host infrastructure.” The researchers said they were able to enumerate available tools, steal LLM provider API keys from environment variables, deploy attacker-controlled AI agent swarms, retrieve user conversations stored in MongoDB, and establish persistence. The researchers also demonstrated what they described as AI memory poisoning by inserting malicious entries into Ruflo’s AgentDB pattern store, allowing future AI responses to incorporate attacker-controlled instructions. Every stage of the attack chain was validated against a default Ruflo deployment running on AWS EC2, according to the researchers. ## Beyond Ruflo: A broader MCP security challenge While the authentication flaw is specific to Ruflo, security practitioners say the research highlights broader risks surrounding AI orchestration platforms and MCP infrastructure. “MCP adoption has outpaced the security defaults built into a lot of orchestration tools,” said Amit Jena, AI Development Manager at Kanerika. “These platforms shipped fast, prioritized ease of setup over authentication, and assumed the network boundary would protect them. That assumption breaks down once the tool sits on a server reachable from a corporate network, which is increasingly where enterprises are running them.” Jena said the research also points to a security concern that extends beyond a single product. “The memory poisoning problem isn’t product-specific, and that’s the part worth paying attention to,” he said. “Any platform that gives agents a persistent, writable memory store needs to treat that store as a security boundary: who can write to it, and can you tell system-generated memory from memory an attacker planted. Very few platforms are doing that today.” He added that, unlike traditional persistence techniques, poisoned AI memory can remain inside a trusted data store and continue influencing future agent behavior after the original intrusion has ended. ## Patch addresses attack chain Noma Security said it disclosed the vulnerability responsibly to Ruflo, which released fixes within hours along with a public security advisory. According to the researchers, the updated release changes the MCP Bridge to bind to the loopback interface by default and fail closed if administrators attempt to expose it publicly without configuring authentication. Noma Security also urged organizations running Ruflo to immediately close firewall access to ports 3001 and 27017, rotate all LLM API keys, audit AgentDB for malicious entries because “a patched redeploy alone doesn’t undo poisoning,” and inspect MongoDB for signs of tampering. Jena said organizations should also review how AI orchestration platforms are deployed and managed. “If a component can execute a shell command or query a database, it gets the same authentication, network segmentation, and logging as any other privileged system in the environment,” he said. He also recommended that security teams inventory the tools exposed through AI agent deployments, audit persistent AI memory separately from software patching, and narrowly scope and rotate LLM provider credentials following any suspected exposure.
www.csoonline.com
July 30, 2026 at 11:33 PM