IT News Week 32/2026: Coldcard $70M Bitcoin Heist, Hotel Wi-Fi Spy Malware, Adobe CVSS 10.0
A firmware bug dormant since 2021 exploded into a $70 million Bitcoin heist, Russian state hackers turned hotel Wi-Fi into a surveillance platform, and Adobe shipped a CVSS 10.0 patch for Campaign Classic. Meanwhile, macOS developers face a new wave of Xcode supply-chain poisoning and ad-tech became a wallet-swapping weapon. Here's the analysis.
Deep Dive: Coldcard Hardware Wallet — $70M+ Bitcoin Heist
A Five-Year Firmware Time Bomb
A March 2021 firmware bug in Coldcard hardware wallets routed seed generation to a deterministic software PRNG instead of the STM32 hardware RNG. Attackers exploited this on July 30 to drain 1,196 addresses in 41 minutes, stealing approximately $70M in BTC — later escalating to $88.6M across 4,585 addresses. Coinkite shipped emergency firmware on July 31, but existing seeds remain compromised: anyone who generated a seed on affected firmware must regenerate it. The Hacker News
Assessment: Firmware-level RNG failures are catastrophic — they undermine the entire trust model of hardware wallets. Anyone with a Coldcard should regenerate seeds on updated firmware immediately and move funds to new addresses.
Deep Dive: Midnight Blizzard Hijacks Hotel Wi-Fi → Surveillance Malware
CaptiveCrunch: Fake Browser Updates via Compromised Captive Portals
Storm-2945, a sub-cluster of APT29/Midnight Blizzard (Russia's SVR), compromised hotel captive portal gateways to forge DNS responses, redirecting travelers to fake browser updates delivering CornFlake RAT — a surveillance tool with webcam/mic capture, keystroke logging, and cookie theft. The campaign also abuses the device code authentication flow for MFA bypass. Active since May across multiple countries. The Hacker News
Assessment: Hotel Wi-Fi is now a confirmed attack vector for targeted travelers. VPN on any public or semi-public network is mandatory — and organizations with traveling employees should enforce always-on VPN policies.
Deep Dive: XCSSET v40 — macOS Supply-Chain Malware Targets Developers
17 Modules, Fileless Persistence, XProtect Disabled
XCSSET v40 spreads via poisoned Xcode projects hosted on GitHub. The malware packs 17 modules including a Chrome DevTools Protocol hijack backdoor, a Telegram Desktop trojanizer, and the ability to disable XProtect and telemetry. It achieves fileless persistence via macOS defaults and uses polymorphic payloads to evade detection. Primary targets are developers in South Asia. Unit 42
Assessment: Developers remain prime targets — their toolchains trust local projects implicitly. Xcode projects from public repositories should never be used without thorough verification.
Deep Dive: Adobe Campaign Classic CVSS 10.0 — RCE Without User Interaction
Two Critical Vulns Patched in v7.4.3
CVE-2026-48449 (CVSS 10.0) allows arbitrary code execution without any user interaction. CVE-2026-48448 (CVSS 8.6) enables SQL injection leading to arbitrary file reads. Both are patched in Adobe Campaign Classic v7.4.3 build 9398. The Hacker News
Assessment: A CVSS 10.0 with no user interaction required is as critical as it gets. Organizations running Adobe Campaign Classic should patch immediately — exploitation is trivial.
Deep Dive: Adform Supply Chain Attack Swaps Crypto Wallet Addresses
Browser-Side Wallet Rewriting via Compromised Ad Script
Attackers modified a JavaScript file served by ad-tech company Adform on July 27, creating a browser-side tool that rewrites Bitcoin, Ethereum, and Tron wallet addresses in real time — including form field entries, not just clipboard contents. This affects anyone who visited a site carrying the compromised Adform script during the exposure window. The Hacker News
Assessment: Supply chain attacks via ad networks reach millions of users simultaneously. Always verify wallet addresses manually before sending funds — do not rely on copy-paste or auto-fill.
Innovation & Open Source
- DefCon: Security Key as Badge: DefCon 2026 features a removable chip that doubles as a hardware security key — a creative intersection of security culture and functional hardware.
- Kioxia PCIe 6.0 SSD — 28+ GB/s: Kioxia's PCIe 6.0 SSD achieves over 28 GB/s sequential read — aimed squarely at data center workloads.
- Seagate HAMR — 50 TB Next Year: Seagate promises 50 TB HAMR hard drives within the next year — a significant milestone for high-density storage.
- Eclipse + OWASP: Open Source Security Training: Eclipse Foundation and OWASP launch an initiative to educate open-source projects on security best practices.
Digest: Other Key News
Security
- Chinese Hackers Target Central Asian Governments: OctLurk/SilkLurk backdoors deployed against governments in Afghanistan, Kyrgyzstan, Tajikistan, and Uzbekistan — active since January 2025.
- HollowFrame Loader + Matryoshka Backdoor: Go-based loader delivers Rust malware via spear-phishing, uses GitHub for C2 infrastructure.
- Cyber Attacks on US Water Utilities Increasing: FBI and EPA warn of increasing attacks on US water treatment facilities.
- Cheap Android TV Boxes Turn Broadband Into Proxy Botnet: Budget Android TV boxes ship with pre-installed apps for ad fraud and SOCKS5 proxy operation.
AI & Enterprise
- AI Scammers Outperform Humans at Building Trust: AI chatbots are more effective at social engineering than human scammers — a troubling escalation in fraud capability.
- Anthropic Finding Bugs Faster Than Microsoft Can Fix Them: AI-powered bug discovery is outpacing Microsoft's patch tempo — a preview of the vulnerability management crisis ahead.
Infrastructure & Enterprise
- Microsoft AI Security Tools Outperform Competitors: Microsoft unveils new AI-powered security tools claiming superiority over competing platforms.
Compiled on August 9, 2026. Sources: The Hacker News, heise.de, Ars Technica, Unit 42 (Palo Alto Networks).
senn-tech