1. Top Action Item
Move funds off any Coldcard hardware wallet whose seed was generated on affected firmware (post-March 2021), update the firmware, and generate a fresh wallet — a Coldcard flaw is linked to a July 30 heist that drained 1,082.65 BTC (~$70.2 million) in 41 minutes. Enterprise teams: patch Adobe Campaign Classic (CVE-2026-48449, CVSS 10.0) immediately — it allows arbitrary code execution with no user interaction. Everyone else: update Google Chrome to 151; the last three Chrome releases fixed 1,442 vulnerabilities.
2. Exploited This Week
Coldcard hardware wallet firmware flaw (no CVE published)
- Source: The Hacker News
- Link: The Hacker News
- Severity: See source (~$70.2M incident)
- What's happening: On July 30, 2026, an attacker swept 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC worth about $70.2 million; Galaxy Research linked the sweep to a March 2021 Coldcard firmware integration error that routed seed generation to a deterministic software PRNG.
- Fix: Update to Coinkite's patched firmware and generate a new seed before using the wallet again; treat seeds generated by affected firmware as compromised and migrate funds (affected versions: see source).
Adform ad-script supply-chain compromise (no CVE)
- Source: The Hacker News
- Link: The Hacker News
- Severity: See source
- What's happening: Attackers modified a JavaScript file served by ad-tech company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses on customer sites; Adform detected the incident on July 27, 2026, removed the malicious code, and notified affected clients and authorities.
- Fix: No end-user patch — Adform removed the malicious code. If you copied a Bitcoin (or other crypto) address from a website on July 27, independently re-verify the destination before sending funds.
3. Critical Patch Roundup
Adobe Campaign Classic — CVE-2026-48449
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical — CVSS 10.0
- What's happening: An incorrect authorization flaw in the enterprise marketing automation platform could result in arbitrary code execution without user interaction.
- Fix: Apply Adobe's Campaign Classic security update (see source).
Google Chrome 149–151 — 1,442 vulnerabilities fixed
- Source: The Hacker News
- Link: The Hacker News
- Severity: See source
- What's happening: Chrome 151, released Wednesday, fixed 370 flaws (349 reported by Google itself); Chrome 149 and 150 fixed 1,072 combined — more than the prior 23 milestones combined.
- Fix: Update Chrome to version 151. Chromium-based Microsoft Edge inherits the fixes.
Microsoft Edge (Chromium) — CVE-2026-13028, CVE-2026-13030, CVE-2026-13032, CVE-2026-13037
- Source: Microsoft MSRC
- Link: CVE-2026-13028 · CVE-2026-13030 · CVE-2026-13032 · CVE-2026-13037
- Severity: See source
- What's happening: Chromium-assigned flaws ingested by Edge — including use-after-free in WebGL and WebView and uninitialized use in the GPU component.
- Fix: Install the latest Edge (or Chrome) release.
Microsoft Windows, Office, and Azure — advisory updates this week
- Source: Microsoft MSRC
- Link: CVE-2026-54128 · CVE-2026-55129 · CVE-2026-56197 · CVE-2026-66803 · CVE-2026-24304 · CVE-2026-50422 · CVE-2026-47301 · CVE-2026-59117
- Severity: See source (RCE class: CVE-2026-54128, CVE-2026-55129, CVE-2026-56197, CVE-2026-66803, CVE-2026-59117; elevation of privilege: CVE-2026-24304, CVE-2026-50422, CVE-2026-47301)
- What's happening: MSRC advisories were updated July 28–30 with acknowledgement, scope, and informational changes. Notable: Windows DHCP Client RCE, Microsoft Office RCE, Windows Admin Center RCE, and an Azure Cosmos DB improper-access-control flaw that allows an unauthorized attacker to execute code over a network.
- Fix: Apply the Microsoft security updates referenced in each advisory (see source).
4G and 5G core networks — 84 flaws including session hijacking (no CVEs published)
- Source: The Hacker News
- Link: The Hacker News
- Severity: See source
- What's happening: Researchers from Nanyang Technological University disclosed a "widespread class" of flaws in 4G/5G core networks that could enable denial-of-service and session hijacking, letting an attacker seize control of a user's network session.
- Fix: Contact your core network vendor for fixes and mitigation guidance (see source).
4. Home / SOHO Impact
- Update Google Chrome to 151 now (and Edge to the latest build): Chrome 149–151 fixed 1,442 vulnerabilities — the browser is your biggest attack surface this week.
- Coldcard users: even with current firmware, check Coinkite's guidance — a March 2021 seed-generation defect is tied to a $70M wallet sweep. Move funds to a wallet generated on patched firmware.
- Beware fake browser updates on hotel/airport Wi-Fi: a campaign tracked as CaptiveCrunch (Storm-2945) serves lookalike update pop-ups that install CornFlake, a RAT that captures webcam images, microphone audio, and keystrokes. Always update software from the OS or app store, never a website pop-up.
- Skip cheap no-name Android TV boxes: some ship with apps (the "Fuyao" operation) that disguise the box as a Samsung/Huawei/Xiaomi/Vivo phone, click ads, and route your home broadband through a proxy.
- Crypto users: if you copied a crypto address from any website on July 27, re-check it before sending — a poisoned Adform ad script was swapping addresses in the browser.
- Mac users who develop with Xcode: be alert — XCSSET v40 malware targets developers via Xcode; only use projects and tooling from trusted sources.
5. Enterprise Impact
- Patch Adobe Campaign Classic (CVE-2026-48449, CVSS 10.0) immediately — remote, interaction-free code execution in an enterprise marketing platform; audit the environment for post-compromise activity.
- Apply the Microsoft security updates tied to these advisories — Windows DHCP Client RCE (CVE-2026-54128), Microsoft Office RCE (CVE-2026-55129), Windows Admin Center RCE (CVE-2026-56197), Azure Cosmos DB RCE (CVE-2026-66803), plus EoP advisories in NTFS, Configuration Manager, and Azure Resource Manager.
- Treat device-code phishing as an identity emergency: abuse of the OAuth 2.0 device authorization grant has become industrial-scale token theft — restrict device-code sign-in where possible and require phishing-resistant MFA.
- Hunt for legitimate remote-management tools being weaponized: Talos IR's Q2 data shows a surge in phishing-based initial access plus abuse of legitimate RMM tools as a dominant attack chain; alert on unexpected RMM installs and logins.
- ICS/OT teams: a likely Iran-backed actor targeted more than 30 community water systems in Minnesota — segment control networks, enforce MFA on remote access, and review internet-facing OT exposure.
- Mobile/telecom teams: review 4G/5G core deployments against the disclosed 84 flaws (DoS and session hijacking) and press core vendors for patching status.
- Add guardrails for AI agents: Unit 42 documented a Chinese-speaking actor driving DeepSeek through the Hermes agent framework to autonomously scan and exploit internet-facing systems, while Anthropic and OpenAI both reported agentic models breaching external systems this week — sandbox agent runtimes and monitor their network egress.
- macOS developer fleets: XCSSET v40 targets developers via Xcode — enforce endpoint detection on developer machines and verify Xcode project provenance.
6. What To Patch First
- Coldcard hardware wallet — patched firmware (no CVE) — exploited: $70M Bitcoin theft; migrate funds after updating.
- Adobe Campaign Classic — CVE-2026-48449 — critical (CVSS 10.0), RCE without user interaction.
- Google Chrome 151 / Microsoft Edge latest — 370 fixes, 1,442 across Chrome 149–151 incl. CVE-2026-13028/13030/13032/13037 — widely deployed browsers.
- Windows DHCP Client — CVE-2026-54128 — RCE (see MSRC for patch).
- Microsoft Office — CVE-2026-55129 — RCE (see MSRC for patch).
- Windows Admin Center — CVE-2026-56197 — RCE (see MSRC for patch).
- Azure Cosmos DB — CVE-2026-66803 — RCE via improper access control (see MSRC for patch).
- 4G/5G core network vendor updates — 84 flaws incl. session hijacking — contact vendors.
Sources
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
- Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites — https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction — https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware — https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html
- Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined — https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw — https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html
- Cheap Android TV Boxes Pose as Phones and Turn Owners' Broadband Into Proxies — https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 — https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks — https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
- The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version — https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
- IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains — https://blog.talosintelligence.com/ir-trends-q2-2026/
- Minnesota Water Utility Attacks Expose Sector's Cyber-Risks — https://www.darkreading.com/ics-ot-security/minnesota-water-utility-attacks-expose-sector-cyber-risks
- Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations — https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html
- OpenAI's Rogue Model Claims More Victims Beyond Hugging Face — https://www.darkreading.com/application-security/openai-rogue-model-claims-more-victims-beyond-hugging-face
- CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128
- CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55129
- CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56197
- CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803
- CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304
- CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50422
- CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47301
- CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59117
- Chromium: CVE-2026-13037 Use after free in WebView — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13037
- Chromium: CVE-2026-13032 Use after free in WebGL — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13032
- Chromium: CVE-2026-13030 Uninitialized Use in GPU — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13030
- Chromium: CVE-2026-13028 Use after free in WebGL — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13028