ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Repair Hacked Website
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Active Exploits Target Langflow and Rails: How to Shield Your Servers

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Active Exploits Target Langflow and Rails: Ho...
  • All articles
  • Categories
  • Tags
  • Statuses

Active Exploits Target Langflow and Rails: How to Shield Your Servers

Critical Vulnerabilities Under Active AttackCybersecurity teams across Europe are on high alert following confirmed reports of active exploitation tar...

Critical Vulnerabilities Under Active Attack

Cybersecurity teams across Europe are on high alert following confirmed reports of active exploitation targeting two widely used platforms: Langflow and Ruby on Rails. The attacks are not merely attempts to crash applications; they follow a deliberate pattern of credential harvesting, secret exfiltration, and preparation for command-and-control (C2) infrastructure. For system administrators and hosting providers in Spain, understanding these threats is the first step toward building a resilient defence.

Digital shield blocking malicious IPs from a server fortress

The Langflow Flaw: CVE-2026-0768

Langflow, a popular tool for building AI and data pipelines, is vulnerable to a critical flaw that allows attackers to execute arbitrary Python code with root privileges. The root cause is insufficient input validation. Observed attacks show a clear focus on extracting environment variables and locating credentials. Attackers have been seen querying variables like LANGFLOW_SUPERUSER, OPENAI_API, and AWS access keys. They also attempt to read sensitive files such as /root/.cache/langflow/secret_key and probe for local access artifacts like .ssh directories and .bash_history files.

The Ruby on Rails Risk: CVE-2026-66066 (KindaRails2Shell)

Even more concerning is the vulnerability in Ruby on Rails, dubbed KindaRails2Shell. This flaw arises from an arbitrary file read when Active Storage processes image uploads using libvips. The attack requires two conditions: the application uses Vips as its image processor, and it accepts uploads from untrusted users. By exploiting discrepancies between how Active Storage interprets files and how libvips processes them, attackers can read secrets from the Rails process itself. This includes secret_key_base, the Rails master key, database credentials, cloud storage keys, and tokens for external services. With these, attackers can escalate from file reading to remote code execution (RCE), pivot to other systems, and maintain persistence without valid credentials.

Geographic Patterns and Attack Vectors

Campaign indicators show distributed activity. For Langflow, traffic has been linked primarily to Russia, with canaries affected in the United Kingdom. For Rails, attacks have targeted canaries in Singapore, Israel, and the UK, with C2 communications pointing to a host in Israel from a single IP in France. These patterns suggest organised, opportunistic actors scanning for exposed instances.

Immediate Steps to Protect Your Infrastructure

For businesses in Lleida, Barcelona, or anywhere in Catalonia, the urgency is clear. Here is a practical checklist to mitigate these risks:

  • Inventory and Exposure Assessment: Identify all public-facing Langflow instances and Rails applications using Active Storage. Prioritise those accepting uploads from the internet.
  • Patch Immediately: For Rails, update to versions 7.2.3.2, 8.0.5.1, or 8.1.3.1, depending on your branch. Also, review the ruby-vips and libvips chain to ensure unsafe operations with untrusted content are blocked.
  • If Patching Is Delayed: Disable Vips processing or restrict image uploads until patches are applied.
  • Rotate All Secrets: Assume potential exposure. Rotate secret_key_base, the master key, and any cloud, database, or API credentials.
  • Monitor Logs and Telemetry: Look for suspicious reads of /proc/self/environ, config/master.key, and other secret paths. Enhance detection for C2 communications and block known malicious indicators.

Beyond Patching: Proactive Server Defence

While patching is critical, it is not enough. The attack pattern—probe, steal secrets, establish C2—demands a layered defence. This is where a centralised security approach becomes invaluable. Instead of managing security on each server individually, consider a solution that aggregates threat intelligence across your entire infrastructure.

Imagine a system that automatically blocks malicious IPs the moment they are detected, not just on one server, but across all your machines. This is the essence of proactive protection. By sharing a reputation feed between servers, you can stop attackers from pivoting from a compromised instance to a clean one. Such a system reduces the window of opportunity for attackers and gives your team breathing room to focus on strategic tasks.

How ALMC Can Help

At ALMC.es, we understand the challenges of managing secure infrastructure. Our Abuse Shield service is designed to centralise your server protection. It provides automatic blocking of malicious IPs, managed fail2ban across multiple machines, and a shared reputation feed. This means if one server detects a threat, all your servers are immediately protected. For system administrators and hosting providers in Spain, this offers a practical way to enhance security without adding operational overhead.

Don't wait for an incident to expose your vulnerabilities. Take proactive steps today to secure your Langflow and Rails deployments, and consider how a unified defence can strengthen your overall security posture.

Related

  • Critical JFrog Artifactory Flaw: Protect Your Software Supply Chain
  • Chrome Zero-Day: Update Now to Patch Actively Exploited Flaw
  • Chrome Zero-Day: Urgent Patch for Actively Exploited V8 Flaw
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Performance Optimization
Full Stack Web Development Laravel, Vue.js
Process Automation (Scripts and Bots)
Server Management & Monitoring
Process Automation Scripts and Bots
Relacionados
  • CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server
    Cybersecurity · 24 minutes ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 24 minutes ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 24 minutes ago
  • Zimbra CVE-2026-73570: Patch Now, Then Hunt for Intrusions
    Cybersecurity · 24 minutes ago
  • GeoServer RCE: Critical Flaw CVE-2024-36401 Under Active Attack
    Cybersecurity · 24 minutes ago
  • Critical JFrog Artifactory Flaw: Protect Your CI/CD Supply Chain
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Gmail MCP Server
    Communication
  • FastDomainCheck
    Search
  • Git Commit Message Generator
    Version Control
  • GreptimeDB
    Official 🌟 Oficial
  • Dynamics 365 MCP Server by CData
    Database
  • Facebook Ads
    Communication
  • Chaitin IP Intelligence
    Search
  • Meme MCP Server
    Other
  • MS-365 MCP Server
    Productivity
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar