Post
DIESEC
diesec.bsky.social
did:plc:xbsbtrxnaey7fq4uth4vowhx
CVSS 10.0: Ruflo's AI agent platform shipped with an unauthenticated management bridge open to the network by default. One HTTP request = stolen LLM keys + hijacked agents. CVE-2026-59726 "RufRoot". Patch to 3.16.3 now.
zurl.co/SrOJJ
zurl.co/6ItUy
#diesec
2026-08-05T08:00:11.467Z