← Back to feed
general HackRead

CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login

HackRead •

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.

Read the full story HackRead →

Related Coverage

general Co-creator of Empire Market dark web marketplace given 40-year sentence The Record · Oct 10 general OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks SecurityWeek · Oct 9 general Airline Zoom Calls,Pix, Windows, TP-Link, AgentCorruption, OSS Scanner, Josh Marpet - SWN #623 SC Media · Oct 9