← Latest brief

Security news.

·Afternoon Brief

Today's security brief highlights a critical flaw in Coldcard hardware wallets leading to a $70 million Bitcoin theft. Major software vendors, including Rails and Adobe, have released urgent patches for high-severity vulnerabilities, while a supply chain attack compromised Adform to steal cryptocurrency. Additionally, CISA has issued warnings regarding increased attacks targeting US water utilities.

BREACH
READ

Coldcard Wallet Flaw Led to $70 Million Bitcoin Theft

A firmware error in Coldcard, a Bitcoin-only hardware wallet, is linked to a $70.2 million Bitcoin theft on July 30, where an attacker drained 1,196 addresses in 41 minutes.

BLEEPINGRCE
6h agoREAD

Rails Patches Critical Active Storage RCE Flaw

Ruby on Rails has released patches for a critical vulnerability in its Active Storage framework (CVE-2026-48449) that could allow unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.

RCE
READ

Adobe Campaign Classic Flaw Allows Remote Code Execution

Adobe issued security updates for a maximum-severity (CVSS 10.0) incorrect authorization vulnerability (CVE-2026-48449) in Campaign Classic, enabling arbitrary code execution without user interaction.

BREACH
READ

Adform Script Compromised to Steal Crypto

Attackers modified a JavaScript file from advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses on affected customer sites.

BLEEPINGBREACH
22h agoREAD

Amgen Discloses Cloud Data Breach Exposing Patient Info

Pharmaceutical company Amgen reported a data breach where threat actors stole corporate and patient health information from multiple third-party cloud systems.

BLEEPINGMALWARE
23h agoREAD

Arch Linux Disables AUR Adoption Amid Malware Surge

The Arch Linux project has temporarily halted adoption of Arch User Repository (AUR) packages due to a significant increase in malicious takeovers of existing packages.

MICROSOFT SECURITY BLOG
1d agoREAD

Midnight Blizzard Targets Travelers via Hotel Wi-Fi

Microsoft's researchers track "CaptiveCrunch," an operation by Storm-2945 (a Midnight Blizzard sub-cluster), which hijacks hotel Wi-Fi to push fake browser updates and deliver surveillance malware like CornFlake.

CISAICS/OT
2d agoREAD

CISA Warns of Increased Attacks on US Water Utilities

CISA is observing a significant rise in cyber threat actors targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector and urges immediate action to remove them from public access.

Generated twice daily from public security RSS feeds. Informational only.