❌

Normal view

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

1 August 2026 at 17:17
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

1 August 2026 at 10:30
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s β€œnudification” ban, and the Democrats learn a lesson about getting scammed.

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

1 August 2026 at 09:03
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

1 August 2026 at 07:12
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests

31 July 2026 at 01:24
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real-world organizations during third-party evaluations.

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

1 August 2026 at 06:29
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

31 July 2026 at 18:52
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since Januaryβ€―2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

31 July 2026 at 16:39
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

❌