DAILY BRIEFING
Coldcard Wallet Flaw, Adobe Campaign CVSS 10.0 Vulnerability, and Adform Script Hijack
Today's briefing covers a $70 million Bitcoin theft via a Coldcard flaw, critical updates for Adobe Campaign Classic and Rails, supply chain poisoning at Adform, and hotel Wi-Fi attacks.
5 stories2 min read

Critical infrastructure and endpoint integrity are under active pressure across enterprise platforms and cryptocurrency ecosystems. High-severity software vulnerabilities are putting core applications at immediate risk, while compromised supply chains and network infrastructure are being used to manipulate web sessions and deliver espionage malware.
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker drained over 1,000 Bitcoin addresses, stealing $70.2 million due to a firmware flaw in Coinkite's Coldcard hardware wallets. A March 2021 code error routed seed generation to a deterministic software PRNG instead of the hardware RNG, enabling attackers to offline-reproduce candidate seed streams.
- Why it matters
- Coldcard wallet owners with seeds created on vulnerable firmware are exposed to total loss of assets. Installing updated firmware stops future weak seed generation but does not fix existing compromised seeds.
- What to do
- Update Coldcard hardware wallet firmware to the latest release, generate a brand-new seed, and transfer all assets to the newly generated addresses immediately.
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).
- Why it matters
- Organizations running Rails applications that utilize Active Storage are vulnerable to confidential data exposure and full server compromise without needing authentication.
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe patched two critical vulnerabilities in Campaign Classic (ACC) v7, including CVE-2026-48449 (CVSS 10.0), an incorrect authorization flaw allowing remote code execution without user interaction, and CVE-2026-48448 (CVSS 8.6), a SQL injection flaw permitting arbitrary file reads.
- Why it matters
- Enterprise marketing teams using Adobe Campaign Classic on Windows or Linux face complete system takeover or sensitive file theft via unauthenticated exploitation.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers compromised a JavaScript file (trackpoint-async.js) hosted by adtech provider Adform to execute a supply-chain attack. The poisoned script injected client-side code on customer websites to modify cryptocurrency addresses pasted into clipboard or form fields to redirect funds.
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft identified a cyber espionage operation named CaptiveCrunch (Storm-2945/Midnight Blizzard) that hijacks hotel Wi-Fi captive portals. By altering DNS responses on the gateway, attackers direct guests to fake updates that install the CornFlake RAT to record audio, webcams, and keys.
Key takeaways
- Coinkite released emergency firmware for Coldcard hardware wallets; users must patch and generate new seed phrases to secure funds.
- Patch Adobe Campaign Classic to v7 7.4.3 build 9398 to remediate maximum-severity vulnerability CVE-2026-48449.
- Clear browser caches for sites using Adform's trackpoint-async.js script to remove malicious wallet-address rewriting code.