← Back to feed
general HackRead

CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login

HackRead

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.

Read the full story HackRead →

Related Coverage

general Check Point Patches Exploited Management Server Zero-Day SecurityWeek · Sep 23 general Researchers Find Malware That Uses AI Models Instead of Human Hackers for Control GBHackers · Sep 23 general Prismor: Open-source runtime control plane for AI agents Help Net Security · Sep 23