August 2026 Summaries
2 posts from Fastly
Filter
Month:
Year:
Post Summaries
Back to Blog
CVE-2026-66066 is an arbitrary file read vulnerability in the Active Storage component of Rails that can lead to remote code execution (RCE) when exploited alongside libvips versions below 8.13. Rails released patches and advisories on July 29, 2026, to address this issue, affecting Active Storage versions below 7.2.3.2, 8.0 up to 8.0.5.1, and 8.1 up to 8.1.3.1. Fastly's Next-Gen WAF customers can activate a virtual patch for immediate protection while waiting for the underlying components to be patched. To fully mitigate the vulnerability, it is recommended to update Active Storage and libvips to the latest versions. Rails has also provided guidance for forensic analysis to detect potential exploitation, and Ethiack has detailed the vulnerability's cause in their research.
Aug 03, 2026
294 words in the original blog post.
Fintech companies face unique challenges with security and performance, particularly when handling sensitive data and financial transactions, where even minor disruptions can cause significant user stress and potential financial loss. To address these challenges, high-performing fintechs are moving away from fragmented legacy tools in favor of modern security solutions delivered at the edge, such as the Fastly Edge Cloud Platform. This platform integrates Web Application Firewall (WAF), bot management, DDoS protection, API security, and edge delivery into a single system, which reduces operational complexity, enhances real-time visibility, and stabilizes infrastructure during traffic spikes. By streamlining security processes and meeting regulatory expectations, the platform helps fintechs maintain robust cybersecurity resilience without compromising developer velocity, ultimately ensuring faster incident response times and lower total cost of ownership.
Aug 02, 2026
749 words in the original blog post.