← August 2026
News 2026-08-01

πŸ›‘οΈ Cybersecurity Vulnerability Watch

Move funds off any Coldcard hardware wallet whose seed was generated on affected firmware (post-March 2021), update the firmware, and generate a fresh wallet β€” a Coldcard flaw is linked to a July 30…

πŸ›‘οΈ Cybersecurity Vulnerability Watch
Open report

πŸ›‘οΈ Cybersecurity Vulnerability Watch

Week of: July 26 – August 1, 2026 Reporting window: Most recently completed Sunday–Saturday (excludes the in-progress week).


1. Top Action Item

Move funds off any Coldcard hardware wallet whose seed was generated on affected firmware (post-March 2021), update the firmware, and generate a fresh wallet β€” a Coldcard flaw is linked to a July 30 heist that drained 1,082.65 BTC (~$70.2 million) in 41 minutes. Enterprise teams: patch Adobe Campaign Classic (CVE-2026-48449, CVSS 10.0) immediately β€” it allows arbitrary code execution with no user interaction. Everyone else: update Google Chrome to 151; the last three Chrome releases fixed 1,442 vulnerabilities.


2. Exploited This Week

Coldcard hardware wallet firmware flaw (no CVE published)

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: See source (~$70.2M incident)
  • What's happening: On July 30, 2026, an attacker swept 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC worth about $70.2 million; Galaxy Research linked the sweep to a March 2021 Coldcard firmware integration error that routed seed generation to a deterministic software PRNG.
  • Fix: Update to Coinkite's patched firmware and generate a new seed before using the wallet again; treat seeds generated by affected firmware as compromised and migrate funds (affected versions: see source).

Adform ad-script supply-chain compromise (no CVE)

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: See source
  • What's happening: Attackers modified a JavaScript file served by ad-tech company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses on customer sites; Adform detected the incident on July 27, 2026, removed the malicious code, and notified affected clients and authorities.
  • Fix: No end-user patch β€” Adform removed the malicious code. If you copied a Bitcoin (or other crypto) address from a website on July 27, independently re-verify the destination before sending funds.

3. Critical Patch Roundup

Adobe Campaign Classic β€” CVE-2026-48449

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: Critical β€” CVSS 10.0
  • What's happening: An incorrect authorization flaw in the enterprise marketing automation platform could result in arbitrary code execution without user interaction.
  • Fix: Apply Adobe's Campaign Classic security update (see source).

Google Chrome 149–151 β€” 1,442 vulnerabilities fixed

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: See source
  • What's happening: Chrome 151, released Wednesday, fixed 370 flaws (349 reported by Google itself); Chrome 149 and 150 fixed 1,072 combined β€” more than the prior 23 milestones combined.
  • Fix: Update Chrome to version 151. Chromium-based Microsoft Edge inherits the fixes.

Microsoft Edge (Chromium) β€” CVE-2026-13028, CVE-2026-13030, CVE-2026-13032, CVE-2026-13037

  • Source: Microsoft MSRC
  • Link: CVE-2026-13028 Β· CVE-2026-13030 Β· CVE-2026-13032 Β· CVE-2026-13037
  • Severity: See source
  • What's happening: Chromium-assigned flaws ingested by Edge β€” including use-after-free in WebGL and WebView and uninitialized use in the GPU component.
  • Fix: Install the latest Edge (or Chrome) release.

Microsoft Windows, Office, and Azure β€” advisory updates this week

  • Source: Microsoft MSRC
  • Link: CVE-2026-54128 Β· CVE-2026-55129 Β· CVE-2026-56197 Β· CVE-2026-66803 Β· CVE-2026-24304 Β· CVE-2026-50422 Β· CVE-2026-47301 Β· CVE-2026-59117
  • Severity: See source (RCE class: CVE-2026-54128, CVE-2026-55129, CVE-2026-56197, CVE-2026-66803, CVE-2026-59117; elevation of privilege: CVE-2026-24304, CVE-2026-50422, CVE-2026-47301)
  • What's happening: MSRC advisories were updated July 28–30 with acknowledgement, scope, and informational changes. Notable: Windows DHCP Client RCE, Microsoft Office RCE, Windows Admin Center RCE, and an Azure Cosmos DB improper-access-control flaw that allows an unauthorized attacker to execute code over a network.
  • Fix: Apply the Microsoft security updates referenced in each advisory (see source).

4G and 5G core networks β€” 84 flaws including session hijacking (no CVEs published)

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: See source
  • What's happening: Researchers from Nanyang Technological University disclosed a "widespread class" of flaws in 4G/5G core networks that could enable denial-of-service and session hijacking, letting an attacker seize control of a user's network session.
  • Fix: Contact your core network vendor for fixes and mitigation guidance (see source).

4. Home / SOHO Impact

  • Update Google Chrome to 151 now (and Edge to the latest build): Chrome 149–151 fixed 1,442 vulnerabilities β€” the browser is your biggest attack surface this week.
  • Coldcard users: even with current firmware, check Coinkite's guidance β€” a March 2021 seed-generation defect is tied to a $70M wallet sweep. Move funds to a wallet generated on patched firmware.
  • Beware fake browser updates on hotel/airport Wi-Fi: a campaign tracked as CaptiveCrunch (Storm-2945) serves lookalike update pop-ups that install CornFlake, a RAT that captures webcam images, microphone audio, and keystrokes. Always update software from the OS or app store, never a website pop-up.
  • Skip cheap no-name Android TV boxes: some ship with apps (the "Fuyao" operation) that disguise the box as a Samsung/Huawei/Xiaomi/Vivo phone, click ads, and route your home broadband through a proxy.
  • Crypto users: if you copied a crypto address from any website on July 27, re-check it before sending β€” a poisoned Adform ad script was swapping addresses in the browser.
  • Mac users who develop with Xcode: be alert β€” XCSSET v40 malware targets developers via Xcode; only use projects and tooling from trusted sources.

5. Enterprise Impact

  • Patch Adobe Campaign Classic (CVE-2026-48449, CVSS 10.0) immediately β€” remote, interaction-free code execution in an enterprise marketing platform; audit the environment for post-compromise activity.
  • Apply the Microsoft security updates tied to these advisories β€” Windows DHCP Client RCE (CVE-2026-54128), Microsoft Office RCE (CVE-2026-55129), Windows Admin Center RCE (CVE-2026-56197), Azure Cosmos DB RCE (CVE-2026-66803), plus EoP advisories in NTFS, Configuration Manager, and Azure Resource Manager.
  • Treat device-code phishing as an identity emergency: abuse of the OAuth 2.0 device authorization grant has become industrial-scale token theft β€” restrict device-code sign-in where possible and require phishing-resistant MFA.
  • Hunt for legitimate remote-management tools being weaponized: Talos IR's Q2 data shows a surge in phishing-based initial access plus abuse of legitimate RMM tools as a dominant attack chain; alert on unexpected RMM installs and logins.
  • ICS/OT teams: a likely Iran-backed actor targeted more than 30 community water systems in Minnesota β€” segment control networks, enforce MFA on remote access, and review internet-facing OT exposure.
  • Mobile/telecom teams: review 4G/5G core deployments against the disclosed 84 flaws (DoS and session hijacking) and press core vendors for patching status.
  • Add guardrails for AI agents: Unit 42 documented a Chinese-speaking actor driving DeepSeek through the Hermes agent framework to autonomously scan and exploit internet-facing systems, while Anthropic and OpenAI both reported agentic models breaching external systems this week β€” sandbox agent runtimes and monitor their network egress.
  • macOS developer fleets: XCSSET v40 targets developers via Xcode β€” enforce endpoint detection on developer machines and verify Xcode project provenance.

6. What To Patch First

  1. Coldcard hardware wallet β€” patched firmware (no CVE) β€” exploited: $70M Bitcoin theft; migrate funds after updating.
  2. Adobe Campaign Classic β€” CVE-2026-48449 β€” critical (CVSS 10.0), RCE without user interaction.
  3. Google Chrome 151 / Microsoft Edge latest β€” 370 fixes, 1,442 across Chrome 149–151 incl. CVE-2026-13028/13030/13032/13037 β€” widely deployed browsers.
  4. Windows DHCP Client β€” CVE-2026-54128 β€” RCE (see MSRC for patch).
  5. Microsoft Office β€” CVE-2026-55129 β€” RCE (see MSRC for patch).
  6. Windows Admin Center β€” CVE-2026-56197 β€” RCE (see MSRC for patch).
  7. Azure Cosmos DB β€” CVE-2026-66803 β€” RCE via improper access control (see MSRC for patch).
  8. 4G/5G core network vendor updates β€” 84 flaws incl. session hijacking β€” contact vendors.

Sources

More from News