Weekly review

ThreatNoir Weekend Brief — August 2

2026-08-02Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — August 2, 2026

August 2, 2026 opens with critical security developments spanning cryptocurrency infrastructure, enterprise software frameworks, and nation-state threat operations. Today's threat landscape underscores the urgency of firmware integrity, immediate patching protocols, and awareness of sophisticated supply-chain attacks targeting travelers and corporate users.

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in just 41 minutes on July 30, 2026, making off with 1,082.65 BTC valued at approximately $70.2 million at the time of the theft. Galaxy Research conducted forensic analysis and traced the attack to a firmware vulnerability in Coldcard, a Bitcoin-only hardware wallet manufactured by Canadian firm Coinkite. The root cause stems from a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator (PRNG) rather than a cryptographically secure entropy source. This weakness in entropy generation fundamentally compromised the security guarantees that hardware wallets are designed to provide. Source: Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Rails Patches Critical Active Storage Flaw with RCE Potential

A critical vulnerability in the Active Storage framework of Ruby on Rails has been patched following discovery of a flaw that permits unauthenticated attackers to read arbitrary files from affected Rails applications. The vulnerability, tracked as CVE-2026-66066, carries the potential for escalation to remote code execution (RCE) under certain conditions. This flaw affects a widely-used component in the Rails ecosystem, making timely patching essential for organizations deploying Rails-based applications. Source: Rails patches critical Active Storage flaw with RCE potential

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates addressing a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform. The flaw, identified as CVE-2026-48449, carries a perfect CVSS score of 10.0 and stems from incorrect authorization controls that enable arbitrary code execution without requiring user interaction. Adobe simultaneously patched nine additional related vulnerabilities tracked as CVE-2026-48448, CVE-2026-48395, CVE-2026-48396, CVE-2026-48390, CVE-2026-48391, CVE-2026-48374, CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394. Organizations operating Campaign Classic deployments should prioritize immediate application of these security updates. Source: Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Microsoft researchers have documented a sophisticated attack operation designated CaptiveCrunch, attributed to the threat actor Storm-2945, an operational sub-cluster of Midnight Blizzard (also known as APT29). The campaign exploits compromised hotel Wi-Fi networks to serve fake browser updates that deliver CornFlake, a remote access trojan capable of capturing webcam images, recording microphone audio, and logging keystrokes. The malware arsenal also includes ChocoShell and employs a range of post-exploitation techniques including credential harvesting, cloud storage exfiltration, and browser credential theft. This operation demonstrates the persistent threat posed by nation-state actors targeting business travelers through compromised hospitality infrastructure. Source: Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Today's threat intelligence reinforces the critical importance of cryptographic integrity in hardware security, timely vulnerability patching across the software supply chain, and heightened vigilance when connecting to public networks, particularly in hotel and hospitality environments where nation-state actors continue to conduct sophisticated surveillance operations.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
CVE10
  • Critical vulnerability in Adobe Bridge leading to arbitrary code execution.
  • Critical vulnerability in Adobe Bridge leading to arbitrary code execution.
  • Critical vulnerability in Adobe Bridge leading to privilege escalation.
  • Critical vulnerability in Adobe Bridge leading to arbitrary code execution.
  • Critical vulnerability in Adobe Bridge leading to arbitrary code execution.
  • Critical vulnerability in Adobe Bridge leading to arbitrary code execution.
  • Critical vulnerability in Adobe Bridge leading to arbitrary code execution.
  • Critical vulnerability in Adobe Campaign Classic allowing arbitrary code execution.
  • High-severity SQL injection vulnerability in Adobe Campaign Classic allowing arbitrary file reads.
  • Critical vulnerability in Adobe Bridge leading to arbitrary code execution.
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
MITRE ATT&CK13
  • Application Layer Protocol: Web Protocols (used for redirection).
  • Input Capture: Keylogging (capability of CornFlake).
  • Screen Capture (capability of CornFlake).
  • Clipboard Data (capability of CornFlake).
  • Credentials from Password Stores: Browser Stored Data (capability of CornFlake).
  • OS Credential Dumping: Web Accounts (targeted by ChocoShell).
  • Application Layer Protocol: DNS (used for redirection).
  • Steal Web Session Cookie (capability of CornFlake).
  • Valid Accounts: Cloud Accounts (targeted by ChocoShell).
  • Valid Accounts: Domain Accounts (implied by token theft).
  • Valid Accounts: Local Accounts (implied by persistence).
  • Command and Scripting Interpreter: PowerShell (used by ChocoShell).
  • Subvert Trust Controls: Mark-of-the-Web Bypass (implied by fake updates).
Malware2
  • CornFlake
    Remote Access Trojan (RAT) used in the campaign.
  • ChocoShell
    In-memory PowerShell stealer used in the campaign.