senn-tech
IT News
Week 2026-W322026-08-09

IT News Week 32/2026: Coldcard $70M Bitcoin Heist, Hotel Wi-Fi Spy Malware, Adobe CVSS 10.0

SecurityAICloudSupply ChainCrypto

A firmware bug dormant since 2021 exploded into a $70 million Bitcoin heist, Russian state hackers turned hotel Wi-Fi into a surveillance platform, and Adobe shipped a CVSS 10.0 patch for Campaign Classic. Meanwhile, macOS developers face a new wave of Xcode supply-chain poisoning and ad-tech became a wallet-swapping weapon. Here's the analysis.

Coldcard: from firmware bug to a $70M theftPRNG flawdormant since 2021Predictable seedsdeterministicDerivationother keysDrainover $70M
The flaw sat unnoticed in firmware for five years — the theft itself took 41 minutes. (Quelle: The Hacker News on the Coldcard incident)

Deep Dive: Coldcard Hardware Wallet — $70M+ Bitcoin Heist

A Five-Year Firmware Time Bomb

A March 2021 firmware bug in Coldcard hardware wallets routed seed generation to a deterministic software PRNG instead of the STM32 hardware RNG. Attackers exploited this on July 30 to drain 1,196 addresses in 41 minutes, stealing approximately $70M in BTC — later escalating to $88.6M across 4,585 addresses. Coinkite shipped emergency firmware on July 31, but existing seeds remain compromised: anyone who generated a seed on affected firmware must regenerate it. The Hacker News

Assessment: Firmware-level RNG failures are catastrophic — they undermine the entire trust model of hardware wallets. Anyone with a Coldcard should regenerate seeds on updated firmware immediately and move funds to new addresses.


Deep Dive: Midnight Blizzard Hijacks Hotel Wi-Fi → Surveillance Malware

CaptiveCrunch: Fake Browser Updates via Compromised Captive Portals

Storm-2945, a sub-cluster of APT29/Midnight Blizzard (Russia's SVR), compromised hotel captive portal gateways to forge DNS responses, redirecting travelers to fake browser updates delivering CornFlake RAT — a surveillance tool with webcam/mic capture, keystroke logging, and cookie theft. The campaign also abuses the device code authentication flow for MFA bypass. Active since May across multiple countries. The Hacker News

Assessment: Hotel Wi-Fi is now a confirmed attack vector for targeted travelers. VPN on any public or semi-public network is mandatory — and organizations with traveling employees should enforce always-on VPN policies.


Deep Dive: XCSSET v40 — macOS Supply-Chain Malware Targets Developers

17 Modules, Fileless Persistence, XProtect Disabled

XCSSET v40 spreads via poisoned Xcode projects hosted on GitHub. The malware packs 17 modules including a Chrome DevTools Protocol hijack backdoor, a Telegram Desktop trojanizer, and the ability to disable XProtect and telemetry. It achieves fileless persistence via macOS defaults and uses polymorphic payloads to evade detection. Primary targets are developers in South Asia. Unit 42

Assessment: Developers remain prime targets — their toolchains trust local projects implicitly. Xcode projects from public repositories should never be used without thorough verification.


Deep Dive: Adobe Campaign Classic CVSS 10.0 — RCE Without User Interaction

Two Critical Vulns Patched in v7.4.3

CVE-2026-48449 (CVSS 10.0) allows arbitrary code execution without any user interaction. CVE-2026-48448 (CVSS 8.6) enables SQL injection leading to arbitrary file reads. Both are patched in Adobe Campaign Classic v7.4.3 build 9398. The Hacker News

Assessment: A CVSS 10.0 with no user interaction required is as critical as it gets. Organizations running Adobe Campaign Classic should patch immediately — exploitation is trivial.


Deep Dive: Adform Supply Chain Attack Swaps Crypto Wallet Addresses

Browser-Side Wallet Rewriting via Compromised Ad Script

Attackers modified a JavaScript file served by ad-tech company Adform on July 27, creating a browser-side tool that rewrites Bitcoin, Ethereum, and Tron wallet addresses in real time — including form field entries, not just clipboard contents. This affects anyone who visited a site carrying the compromised Adform script during the exposure window. The Hacker News

Assessment: Supply chain attacks via ad networks reach millions of users simultaneously. Always verify wallet addresses manually before sending funds — do not rely on copy-paste or auto-fill.


Innovation & Open Source


Digest: Other Key News

Security

AI & Enterprise

Infrastructure & Enterprise


Compiled on August 9, 2026. Sources: The Hacker News, heise.de, Ars Technica, Unit 42 (Palo Alto Networks).