← Back to feed
general HackRead

CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login

HackRead

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.

Read the full story HackRead →

Related Coverage

general US sanctions Iranian cyber actors as UK discloses power plant attack The Record · Aug 24 general SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules Cyberscoop · Aug 24 general AWS patches flaw in 7 SDKs SC Media · Aug 24