Security news.
Today's security news highlights a critical vulnerability in Ruby on Rails' Active Storage, a significant bitcoin theft linked to a Coldcard hardware wallet flaw, and an active MacOS infostealer campaign. Additionally, supply chain attacks targeting ad platforms and hotel Wi-Fi networks are pushing malware and crypto-stealing scripts.
Rails Patches Critical Active Storage RCE Vulnerability
A critical flaw in the Active Storage framework (CVE-2026-48449) allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE) on Ruby on Rails applications.
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft
A firmware flaw in the Coldcard Bitcoin-only hardware wallet, tied to a March 2021 seed generation error, allowed an attacker to drain 1,196 Bitcoin addresses in 41 minutes, stealing approximately $70.2 million.
Atomic MacOS (AMOS) Stealer Infection
SANS Internet Storm Center reports an active campaign involving the Atomic MacOS (AMOS) stealer, indicating ongoing threats targeting macOS users with information-stealing malware.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses
Attackers modified a JavaScript file from advertising technology company Adform to replace cryptocurrency wallet addresses copied by users on affected customer sites with attacker-controlled ones.
Adobe Patches CVSS 10.0 Flaw in Campaign Classic
Adobe released updates for a maximum-severity flaw (CVE-2026-48449) in Campaign Classic (ACC) that could allow arbitrary code execution without user interaction due to incorrect authorization.
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft researchers report that hijacked hotel Wi-Fi networks are being used to push fake browser updates that deliver CornFlake, a remote access trojan (RAT) capable of capturing webcam images, audio, and keystrokes.
Amgen Discloses Cloud Data Breach Exposing Patient and Proprietary Information
Pharmaceutical company Amgen reported a data breach where threat actors stole corporate and patient information from multiple cloud systems operated by third-party service providers.
Arch Linux Disables AUR Package Adoption Amid Malware Surge
The Arch Linux project has temporarily halted the adoption of Arch User Repository (AUR) packages due to a significant increase in malicious takeovers of existing packages.