vulnerability Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes A flaw in Coldcard hardware wallets, manufactured by Coinkite, was exploited to steal $70 million in Bitcoin within 41 minutes. The vulnerability stems from a deterministic PRNG used during seed generation, allowing an a… The Hacker News · Aug 1, 2026 Critical hardware walletseed generationbitcoin
threat-intel Cyber’Smile : la playlist d’été de ZATAZ est de sortie ZATAZ, a French cybersecurity news platform, has released a new music playlist called ‘Cyber’Smile’ to help users relax during their summer holidays. The playlist consists of five original tracks – Bolly’Hack, Clic and P… ZATAZ · Aug 1, 2026 Info musiccybersecurityplaylist
threat-intel Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments Balance Theory, a cybersecurity investment management platform, secured $19 million in Series A funding to help CISOs better understand and optimize their security spending. The platform uses AI and market data to stream… SecurityWeek · Aug 1, 2026 Info cybersecurityinvestmentmanagement
vulnerability Ruby on Rails Patches Critical Vulnerability A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code… SecurityWeek · Aug 1, 2026 Critical CVE-2026-66066rubyrailslibvips
supply-chain Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites Adform, an advertising technology company, suffered a supply-chain attack where attackers injected malicious JavaScript code into their tracking script, allowing them to swap cryptocurrency wallet addresses across custom… The Hacker News · Aug 1, 2026 High supply-chainjavascriptcryptocurrency
phishing Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st) A sophisticated phishing campaign is targeting users of AI solutions, particularly those utilizing services like ChatGPT. The attackers are exploiting anxieties about losing access to these valuable tools, leveraging tim… SANS Internet Storm Center · Aug 1, 2026 Medium phishingaibilling
vulnerability Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Adobe has released critical security updates for Campaign Classic and Adobe Bridge to address vulnerabilities that could allow attackers to execute arbitrary code without user interaction, potentially leading to a comple… The Hacker News · Aug 1, 2026 Critical CVE-2026-48449CVE-2026-48448CVE-2026-48395vulnerabilityarbitrary code executioncampaign classic
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
other Friday Squid Blogging: Squid Helps Discover New Marine Species This article details a technological advancement – a specialized microscope nicknamed ‘Squid’ – used on a marine research expedition to discover thirty-one new marine species in just two weeks. The device’s capabilities… Schneier on Security · Jul 31, 2026 Info scienceresearchtechnology
threat-intel Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk Chinese-speaking hackers are targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, using two new backdoors, OctLurk and SilkLurk, along with… The Hacker News · Jul 31, 2026 High AFKYTAbackdoorproxycyberattack
threat-intel CISA Issues Fresh SBOM Guidance. Did They Get It Right? CISA has released updated guidance on Software Bill of Materials (SBOMs), adding 10 new elements and refining existing ones to improve comprehensiveness. However, critics, like OWASP founder Jeff Williams, argue that the… Dark Reading · Jul 31, 2026 Medium sbomopen sourcesupply chain
threat-intel CISA warns of spike in attacks on water systems as Minnesota incidents probed The CISA is warning of a significant increase in cyberattacks targeting water systems, particularly in Minnesota, with potential links to Iran. Attacks involve modifying passwords, disconnecting PLCs, and causing boil wa… The Record · Jul 31, 2026 High IRUScritical infrastructurecyberattackiran
threat-intel Cyber Command plans Silicon Valley office to drive innovation U.S. Cyber Command is establishing a new innovation hub in Silicon Valley to foster closer collaboration between the military and the tech industry, particularly in areas like artificial intelligence, to accelerate the a… The Record · Jul 31, 2026 Medium cybersecurityartificial intelligencecyber command
threat-intel Anthropic’s Opus 5 Is Better at Resisting Prompt Injection Anthropic’s Opus 5 language model demonstrates significant improvements in resisting prompt injection attacks compared to previous models and other GPT 5.6 variants. While prompt injection remains a persistent challenge,… Schneier on Security · Jul 31, 2026 Medium prompt injectionlanguage modelsecurity
threat-intel HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm A previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family named Matryoshka were used in a spear-phishing attack targeting a law firm. The attack involved a multi-stage process… The Hacker News · Jul 31, 2026 High spear-phishinggorust
threat-intel The most famous brand in physical security got pwned by ShinyHunters ShinyHunters, a known threat actor, has exploited vulnerabilities in Joomla extensions to compromise websites, highlighting a persistent risk for open-source CMS platforms. This incident underscores the ongoing need for… The Register · Jul 31, 2026 Medium joomlavulnerabilityshinyhunters
threat-intel In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research Several cybersecurity incidents and vulnerabilities were reported this week, ranging from a data breach at the UK Department for Education to supply-chain attacks linked to North Korea. OpenAI released a new open-source… SecurityWeek · Jul 31, 2026 High UNNOsupply-chainvulnerabilitycryptanalysis
threat-intel Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Cyberattacks targeting over 30 water systems in Minnesota are under investigation, with authorities suspecting Iranian hackers are responsible. The attacks involved disrupting remote monitoring and control systems, leadi… SecurityWeek · Jul 31, 2026 High IRcritical infrastructurecyberattackiran
threat-intel Anthropic and OpenAI are competing to see whose agents can go rogue harder This article covers a range of cybersecurity and technology news, including a competition between Anthropic and OpenAI regarding the potential for AI agent 'rogue' behavior, a UK initiative to charge data centers for gri… The Register · Jul 31, 2026 Medium aicybersecurityphishing