Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A firmware flaw in Coldcard hardware wallets allowed an attacker to drain 1,196 Bitcoin addresses in 41 minutes, stealing about $70.2 million. The flaw caused seed generation to use a deterministic pseudorandom number generator instead of the hardware random number generator.
A firmware flaw in Coldcard hardware wallets allowed an attacker to drain 1,196 Bitcoin addresses in 41 minutes, stealing about $70.2 million. The flaw caused seed generation to use a deterministic pseudorandom number generator instead of the hardware random number generator.
A critical vulnerability in Rails' Active Storage framework allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution. Users should apply the patch immediately.
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).
Attackers modified Adform's JavaScript to rewrite cryptocurrency wallet addresses on customer sites. The supply-chain compromise affected users on July 27, 2026, and Adform recommends clearing browser cache and verifying addresses.
Attackers compromised a JavaScript file, trackpoint-async.js, served by advertising technology company Adform, injecting malicious code that altered cryptocurrency wallet addresses on websites using the script. The incident was detected on July 27, 2026, and Adform promptly removed the malicious code, notified affected clients, and reported the breach to authorities.