Security firm Rietta rolled out an emergency hotfix across its client base on July 29, 2026, after a Ruby on Rails ActiveStorage vulnerability—later named KindaRails2Shell and tracked as CVE-2026-66066—jumped from an unrated update to a 9.5/10 CVSS severity score within hours. The flaw, discovered by researchers at Ethiack, allows arbitrary file read and remote code execution through variant processing in Active Storage, a core Rails component used in Rails 8 and newer.
rietta.com
· 2026-09-04
1Password pledged $300,000 to Omacom, the nonprofit behind the Omarchy Linux distribution created by David Heinemeier Hansson, prompting criticism from customers and employees over Hansson's history of racist and anti-immigrant commentary. The password manager's leadership, including CEO David Faugno and cofounder Roustem Karimov, has responded internally to concerns about the partnership's optics. Critics on social media have called for boycotts and suggested alternative password managers in response.
theverge.com
· 2026-09-02
A longtime Ruby on Rails developer and HEY email subscriber announced he is quitting the service after growing disillusioned with founder David Heinemeier Hansson's public statements. The writer, who once admired DHH's technical philosophy, says he can no longer support the company after DHH expressed views the writer characterizes as anti-immigrant and racially exclusionary regarding Europe.
kylemcgough.com
· 2026-08-25
DHH describes his Omacom project, including the Omarchy setup, as an application of 'omakase computing' — curated, chef's-choice defaults rather than requiring users to configure every tool themselves. He argues this borrows the same philosophy behind Ruby on Rails, letting newcomers get a cohesive experience while still allowing tinkering once they gain expertise.
learn.omacom.io
· 2026-08-24