Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

2026-08-02T07:23:58Zf6047cd8492c988b832a95feb5f239bd85c18082c3186ff31bd6091fcd6fe04b
CVE-2026-20316CVE-2026-48449CVE-2026-59726CVE-2026-66066AI-securityBYOVDactive-exploitationarbitrary-file-readcloud-securitycredential-theftcryptocurrency-theftmalvertisingmalwaremobile-securitynetwork-securityphishingrcestate-sponsoredsupply-chain-compromisethreat-actorsvulnerability-managementzero-day

What happened

Security news digest covering major vulnerabilities, active exploitation, malware campaigns, supply-chain compromises, phishing, cloud exposure, and AI-assisted attacks. Highlights include a critical Adobe Campaign Classic flaw (CVE-2026-48449), actively exploited Cisco FMC zero-day (CVE-2026-20316), critical Ruby on Rails file-read vulnerability (CVE-2026-66066), Ruflo unauthenticated RCE (CVE-2026-59726), Azure Cosmos DB cross-tenant data exposure, malicious advertising and npm supply-chain attacks, BYOVD activity, and campaigns delivering surveillance or crypto-stealing malware.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
f6047cd8492c988b832a95feb5f239bd85c18082c3186ff31bd6091fcd6fe04b
Enrichment time
2026-08-02T07:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.