August 2, 2026
- South Korean state-sponsored campaign abuses AnySign4PC via compromised sites. Authorities and four security firms detailed a watering-hole operation exploiting locally installed financial-security software to silently deploy SIGNBT and COPPERHEDGE backdoors with no user prompt (The Hacker News). A parallel "Operation Double Barrel" abuses WebSocket buffer overflows in two Korean financial-security products, with one intrusion chain delivering Gunra ransomware (blackorbird). · Threat Intelligence
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves