DAILY BRIEFING
Adobe Campaign Classic CVSS 10.0, Adform Script Compromised, Hotel Wi-Fi Hijacked
Today's briefing covers critical Adobe fixes, supply chain tampering at Adform, hotel network hijacking, cloud data theft at Amgen, and suspended package adoption in Arch Linux's AUR.
5 stories2 min read

Enterprise infrastructure and third-party services face immediate operational threats today. Adobe issued patches for a maximum-severity flaw in Campaign Classic, while an adtech supply chain compromise at Adform led to inline cryptocurrency wallet address swapping across partner websites.
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe released security patches addressing a maximum-severity vulnerability (CVE-2026-48449) and a high-severity SQL injection flaw (CVE-2026-48448) in Adobe Campaign Classic. The flaws allow remote execution of arbitrary code without user interaction and unauthorized arbitrary file system reads.
- Why it matters
- Organizations running unpatched Adobe Campaign Classic servers face unauthenticated, zero-click remote code execution and sensitive file disclosure.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers compromised the trackpoint-async.js script served by adtech company Adform, modifying it to dynamically replace copied or typed Bitcoin, Ethereum, and Tron wallet addresses with adversary-controlled addresses. Adform removed the malicious code on July 27, 2026, and urged users to clear browser caches.
- What to do
- Clear browser caches across endpoints and manually verify all target cryptocurrency wallet addresses before executing transactions.
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Threat actor Storm-2945 hijacked hotel captive portal gateways acting as DNS resolvers to redirect user web traffic to fake browser update pages. The campaign, dubbed CaptiveCrunch, uses ClickFix social engineering tricks to infect Windows endpoints with the CornFlake RAT for audio, video, and keystroke surveillance.
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical giant Amgen confirmed a data breach resulting from unauthorized access to corporate data and patient health records hosted across multiple third-party cloud service providers.
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project temporarily suspended the package adoption feature within the Arch User Repository (AUR) to halt an ongoing wave of malicious package takeovers targeting orphaned maintainer slots.
- What to do
- Review and pin current AUR package dependencies and audit build scripts for recently adopted or updated third-party software.
Key takeaways
- Patch Adobe Campaign Classic to version v7: 7.4.3 build 9398 to resolve CVE-2026-48449 and CVE-2026-48448.
- Instruct users who visited sites hosting Adform's trackpoint-async.js on July 27, 2026, to clear their browser caches and verify wallet addresses.
- Arch Linux has temporarily disabled package adoption in the AUR following a flood of malicious package takeovers.