SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, August 02, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Coldcard Wallet Flaw Leads to $70M Theft | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 9 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by critical vulnerabilities and sophisticated delivery vectors, including a maximum-severity CVSS 10.0 flaw in Adobe Campaign Classic and a critical RCE vulnerability in the Ruby on Rails Active Storage framework. Additionally, threat actors are actively exploiting hardware wallet firmware flaws and hijacking hotel Wi-Fi networks to deliver surveillance malware like the CornFlake RAT. Organizations must prioritize patching web frameworks and enterprise software while enforcing strict network access controls for remote workers. |
|
■ CRITICAL STORIES Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft A firmware vulnerability in Coldcard hardware wallets allowed attackers to drain $70.2 million across 1,196 Bitcoin addresses in just 41 minutes, highlighting severe risks in hardware-based crypto storage. |
Adobe Campaign Classic CVSS 10.0 Flaw Allows Zero-Interaction RCE A maximum-severity vulnerability (CVE-2026-484) in Adobe Campaign Classic enables unauthenticated arbitrary code execution without any user interaction, posing a severe threat to enterprise marketing platforms. |
Ruby on Rails Patches Critical Active Storage Flaw with RCE Potential A critical vulnerability in the Rails Active Storage framework allows unauthenticated attackers to read arbitrary files and potentially escalate to remote code execution (RCE). |
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake RAT Threat actors are hijacking hotel Wi-Fi networks to serve fake browser updates that install 'CornFlake' surveillance malware, capable of capturing keystrokes, webcam, and microphone data. |
|
■ CVEs IDENTIFIED CVE-2026-484 Adobe Campaign Classic (ACC) — Arbitrary code execution without user interaction |
[CVE-TBD] Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential remote code execution (RCE) |
[CVE-TBD] Coinkite Coldcard Firmware — Firmware flaw allowing unauthorized draining of cryptocurrency wallets |
[CVE-TBD] Adform JavaScript — Script poisoning leading to cryptocurrency wallet address swapping |
|
■ THREAT ACTORS Hijacked hotel Wi-Fi to distribute CornFlake RAT via fake browser updates |
Exploited Coldcard firmware flaw to steal $70.2 million in Bitcoin |
Poisoned Adform JavaScript to swap cryptocurrency wallet addresses |
|
|
|
■ ATT&CK TTPs | T1195.001 | | Supply Chain Compromise: Compromise Software Dependencies and Tools | Poisoned Adform JavaScript distributed to customer sites to swap crypto addresses |
| T1557.002 | | Adversary-in-the-Middle: Wi-Fi | Hijacked hotel Wi-Fi networks to serve fake browser updates |
| T1566 | | Phishing | AMOS stealer distribution and campaigns targeting AI solutions providers like ChatGPT |
| T1190 | | Exploit Public-Facing Application | Exploitation of Adobe Campaign Classic (CVE-2026-484) and Ruby on Rails Active Storage flaws |
| T1125 | | Video Capture | CornFlake RAT capturing webcam images from infected hosts |
| T1056.001 | | Keylogging | CornFlake RAT capturing keystrokes on infected hosts |
|
■ PATCH PRIORITY CRITICAL — Adobe Campaign Classic (ACC) — Zero-interaction arbitrary code execution vulnerability (CVE-2026-484) — [THN] |
CRITICAL — Ruby on Rails (Active Storage) — Unauthenticated arbitrary file read and potential RCE — [BC] / [SW] |
CRITICAL — Coinkite Coldcard — Firmware flaw leading to massive cryptocurrency theft — [THN] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Adobe Campaign Classic immediately to address the CVSS 10.0 vulnerability (CVE-2026-484) to prevent zero-interaction arbitrary code execution. |
| 2 | [P1] Update Ruby on Rails installations to the latest patched version to mitigate the critical Active Storage file read and RCE vulnerability. |
| 3 | [P1] Update Coinkite Coldcard hardware wallet firmware to the latest secure version to protect against the critical wallet-draining vulnerability. |
| 4 | [P2] Implement robust endpoint protection on macOS devices to detect and block Atomic MacOS Stealer (AMOS) infections. |
| 5 | [P2] Enforce VPN usage on public and hotel Wi-Fi networks to mitigate Adversary-in-the-Middle attacks distributing the CornFlake RAT. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |