daily cyber × ai intelligence

index

tagged

[cryptocurrency-theft]

3 items

August 2, 2026

Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves

Coldcard hardware wallets suffer $88M+ in cryptocurrency theft across three attack waves exploiting weak entropy in address generation. Microsoft attributes a Russian SVR campaign (Midnight Blizzard) to hotel Wi-Fi hijacking and device-code OAuth phishing targeting M365 accounts. DeepSeek's new V4 Flash model is trivially jailbroken with researchers bypassing multiple refusal classes via single prompts. Critical vulnerabilities in macOS Screen Sharing, Joomla Content Editor (CVE-2026-48907), and Ruby on Rails Active Storage enable pre-auth RCE, with active exploitation confirmed for the Joomla flaw.

August 1, 2026

When the Attacker Is a Model: AI Lands on Both Sides of the Fight

DeepSeek wired into Hermes Agent autonomous attacks discovers and exploits vulnerable servers on attacker command, marking a concrete expansion of AI-driven offensive operations. Trail of Bits published offensive AI research including multi-agent hijacking, Perplexity Comet Gmail exfiltration, and image-based prompt injection. Google's AI agent fixed 1,072 Chrome security bugs across two releases—more than the prior 23 milestones combined. Iran was assessed by U.S. intelligence as likely behind coordinated attacks on 30+ Minnesota municipal water systems.

July 4, 2026

Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat

Huntress detailed an LDAP Ping technique that enumerates Active Directory usernames without triggering Windows audit logs, enabling stealthy reconnaissance for password spraying attacks. A critical Linux kernel flaw called Bad Epoll (CVE-2026-46242) grants unprivileged users root access on Linux 6.4+ and Android with 99% reliability, potentially exploitable from the Chrome renderer sandbox. Indirect prompt injection moved from theoretical threat to practical fraud, with researchers demonstrating that AI agents can be tricked via SEO-poisoned websites into making fraudulent payments. Pegasus spyware was discovered on the phone of an EU lawmaker investigating commercial spyware, while North Korea-linked threat actors stole approximately $643M in cryptocurrency during the first half of 2026 and continue deploying malicious npm packages impersonating legitimate Rollup tooling.