CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

Coldcard Wallet Flaw, Adobe Campaign CVSS 10.0 Vulnerability, and Adform Script Hijack

Today's briefing covers a $70 million Bitcoin theft via a Coldcard flaw, critical updates for Adobe Campaign Classic and Rails, supply chain poisoning at Adform, and hotel Wi-Fi attacks.

Critical infrastructure and endpoint integrity are under active pressure across enterprise platforms and cryptocurrency ecosystems. High-severity software vulnerabilities are putting core applications at immediate risk, while compromised supply chains and network infrastructure are being used to manipulate web sessions and deliver espionage malware.

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained over 1,000 Bitcoin addresses, stealing $70.2 million due to a firmware flaw in Coinkite's Coldcard hardware wallets. A March 2021 code error routed seed generation to a deterministic software PRNG instead of the hardware RNG, enabling attackers to offline-reproduce candidate seed streams.

Why it matters
Coldcard wallet owners with seeds created on vulnerable firmware are exposed to total loss of assets. Installing updated firmware stops future weak seed generation but does not fix existing compromised seeds.
What to do
Update Coldcard hardware wallet firmware to the latest release, generate a brand-new seed, and transfer all assets to the newly generated addresses immediately.
  • Coinkite
  • Coldcard
  • firmware
Read the original

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).

Why it matters
Organizations running Rails applications that utilize Active Storage are vulnerable to confidential data exposure and full server compromise without needing authentication.
  • Rails
  • RCE
  • vulnerability
Read the original

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe patched two critical vulnerabilities in Campaign Classic (ACC) v7, including CVE-2026-48449 (CVSS 10.0), an incorrect authorization flaw allowing remote code execution without user interaction, and CVE-2026-48448 (CVSS 8.6), a SQL injection flaw permitting arbitrary file reads.

Why it matters
Enterprise marketing teams using Adobe Campaign Classic on Windows or Linux face complete system takeover or sensitive file theft via unauthenticated exploitation.
  • Adobe
Read the original

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers compromised a JavaScript file (trackpoint-async.js) hosted by adtech provider Adform to execute a supply-chain attack. The poisoned script injected client-side code on customer websites to modify cryptocurrency addresses pasted into clipboard or form fields to redirect funds.

  • Adform
  • crypto
  • JavaScript
Read the original

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Microsoft identified a cyber espionage operation named CaptiveCrunch (Storm-2945/Midnight Blizzard) that hijacks hotel Wi-Fi captive portals. By altering DNS responses on the gateway, attackers direct guests to fake updates that install the CornFlake RAT to record audio, webcams, and keys.

  • CornFlake
  • RAT
Read the original

Key takeaways

  • Coinkite released emergency firmware for Coldcard hardware wallets; users must patch and generate new seed phrases to secure funds.
  • Patch Adobe Campaign Classic to v7 7.4.3 build 9398 to remediate maximum-severity vulnerability CVE-2026-48449.
  • Clear browser caches for sites using Adform's trackpoint-async.js script to remove malicious wallet-address rewriting code.
  • Coldcard
  • Coinkite
  • CVE202648449
  • Adform
  • CornFlake