# Threat Intel Brief — August 3, 2026
TL;DR
- COLDCARD hardware wallet firmware flaw enabled theft of approximately $70–88 million in Bitcoin through compromised random number generation; emergency patches released but existing seeds remain vulnerable.
- Adobe Campaign Classic CVE-2026-48449 (CVSS 10.0) allows unauthenticated remote code execution without user interaction; patches available.
- Cisco Secure Firewall Management Center under active exploitation; immediate patching required to prevent perimeter compromise.
- Storm-2945 (Midnight Blizzard sub-cluster) hijacking hotel Wi-Fi networks to deploy CornFlake surveillance RAT via fake browser updates.
- Critical VMware vCenter and Ruby on Rails Active Storage vulnerabilities require urgent remediation across enterprise environments.
Critical Threats
COLDCARD Hardware Wallet RNG Vulnerability
What happened
A firmware integration error dating to March 2021 in COLDCARD hardware wallets (Coinkite) routed cryptographic seed generation to a deterministic software pseudorandom number generator instead of proper hardware randomization. This reduced effective entropy from 128 bits to approximately 40–72 bits depending on device model. On July 30, 2026, an unidentified attacker exploited this weakness to drain 1,082.65 BTC (approximately $70.2 million) from 1,196 addresses in 41 minutes. Total estimated losses across all affected wallets may reach $88.6 million.
Affected devices: Mk2/Mk3 firmware 4.0.1–4.1.9, Mk4/Mk5 before 5.6.0, Q devices before 1.5.0Q. The vulnerability affects seeds generated on compromised firmware versions, not the current firmware itself. TAPSIGNER, OPENDIME, and SATSCARD products are not affected.
Impact
Attackers with knowledge of device UID, timer state, and RNG-call history can reconstruct wallet seeds offline and systematically drain funds without physical access to devices. Emergency firmware patches (4.2.0+, 5.6.0+, 1.5.0Q+) have been released, but updating firmware does not repair existing seeds. Users must generate new seeds on patched firmware and migrate all holdings. Organizations using COLDCARD for cryptocurrency custody face immediate theft risk and must assume compromise of all wallets whose seeds were generated on vulnerable firmware versions.
Recommendations
- Immediately identify all COLDCARD devices and determine the firmware version active when each seed was created (not current version).
- Update to firmware 4.2.0+ (Mk2/Mk3), 5.6.0+ (Mk4/Mk5), 1.5.0Q+ (Q), or 6.6.0X/6.6.0QX (Edge builds).
- Generate new seeds on patched firmware and transfer all Bitcoin holdings to new wallets—do not restore old seeds to updated firmware.
- Monitor blockchain transaction history for affected addresses; watch for 30 sat/vB, no-change transaction patterns indicative of sweeps.
- Seeds created with at least 50 fair dice rolls or protected by strong unique BIP-39 passphrases require individual risk assessment but should still prioritize migration.
---
Adobe Campaign Classic Maximum Severity RCE (CVE-2026-48449)
What happened
Adobe released emergency security updates for Campaign Classic v7, addressing CVE-2026-48449 (CVSS 10.0), an incorrect authorization vulnerability enabling arbitrary code execution without user interaction. A secondary SQL injection flaw (CVE-2026-48448, CVSS 8.6) allows arbitrary file system reads. Campaign Classic is an enterprise marketing automation platform handling customer data and campaign operations.
Affected versions: Adobe Campaign Classic v7 prior to 7.4.3 build 9398 on Windows and Linux.
Impact
Maximum severity flaw allows unauthenticated attackers to execute arbitrary code in the context of the current user without requiring user interaction. The SQL injection vulnerability enables unauthorized access to configuration files, credentials, and sensitive customer data. Adobe states it is not aware of active exploitation at time of advisory publication, but the severity and ease of exploitation make this a priority target for both APT groups and ransomware operators.
Recommendations
- Immediately upgrade Adobe Campaign Classic v7 to version 7.4.3 build 9398 or later on all Windows and Linux instances.
- Audit Campaign Classic access logs for unauthorized code execution attempts or unusual SQL queries prior to patching.
- Review user authorization configurations to identify privilege misconfigurations that could be exploited.
- If immediate patching is not feasible, implement network segmentation to restrict Campaign Classic access to trusted internal networks only.
- Monitor application logs and system process execution for anomalous activity post-patching.
---
Cisco Secure Firewall Management Center — Active Exploitation
What happened
CERT.BE issued a critical warning regarding an actively exploited vulnerability in Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific CVE identifier and affected versions have not yet been publicly disclosed. The vulnerability is confirmed to be under active exploitation in the wild.
Impact
Cisco Secure Firewall Management Center controls firewall policy and configuration across enterprise security infrastructure, making it a high-value target. Successful exploitation could allow attackers to manipulate firewall rules, disable security controls, pivot to managed devices, or gain persistent access to the network perimeter. Organizations using Cisco Secure Firewall Management Center face immediate risk of compromise.
Recommendations
- Immediately check Cisco Security Advisories portal for emergency patches and apply without delay.
- Restrict management interface access to Cisco Secure Firewall Management Center to trusted networks only; disable internet-facing management if enabled.
- Review authentication logs and administrative access logs on all Management Center instances for suspicious activity or unauthorized access attempts.
- Monitor Cisco's security advisory feed and CERT.BE updates for CVE assignment and additional technical details.
- If patching cannot be completed immediately, consider temporarily isolating Management Center from untrusted networks until remediation is complete.
---
Ruby on Rails Active Storage RCE Vulnerability
What happened
A critical vulnerability in the Ruby on Rails Active Storage framework allows unauthenticated attackers to read arbitrary files from Rails applications and potentially achieve remote code execution. The Rails team has released patches addressing the vulnerability. Specific vulnerable versions and CVE identifier have not been publicly disclosed in available data.
Impact
All internet-facing Rails applications using Active Storage are at risk. Unauthenticated attackers can read arbitrary files, potentially exposing credentials, configuration files, and sensitive data. Escalation to remote code execution is possible, enabling full system compromise. The vulnerability is critical severity but exploitation status in the wild is unknown.
Recommendations
- Identify all Ruby on Rails applications using Active Storage framework in your environment.
- Apply the latest Rails security patches immediately to all affected applications.
- Review application logs for suspicious file access patterns or unauthorized requests to Active Storage endpoints.
- Implement web application firewall rules to monitor and block anomalous requests to Active Storage routes until patching is complete.
- Conduct post-patch security review to verify no unauthorized file access or code execution occurred prior to remediation.
---
VMware vCenter Critical Vulnerabilities
What happened
CERT.BE issued an urgent warning regarding multiple critical vulnerabilities in the vCenter component of VMware products. Specific CVE identifiers and affected versions have not been disclosed in the advisory. vCenter Server is the centralized management platform for VMware virtualization infrastructure.
Impact
Compromise of vCenter Server could grant attackers control over entire virtual environments, including all hosted VMs, storage, and network configurations. Critical impact for organizations running VMware-based data centers. Specific CVSS scores and exploitation status are not available in current advisory, but the urgency of the warning suggests high severity and potential for widespread impact.
Recommendations
- Check VMware Security Advisories (VMSA) portal immediately for specific CVE details and affected vCenter versions.
- Identify all vCenter Server instances in your environment and verify current patch levels.
- Apply VMware-provided patches for vCenter Server as soon as available, prioritizing internet-facing instances.
- Review vCenter access logs for suspicious authentication attempts or unusual administrative activity.
- Implement network segmentation to restrict vCenter management access to authorized jump hosts only.
Threat Actor Activity
Storm-2945 (Midnight Blizzard) — CaptiveCrunch Campaign
Microsoft researchers identified a campaign called CaptiveCrunch attributed to Storm-2945, an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear). The U.S. and U.K. governments assess with high confidence that APT29 is part of Russia's Foreign Intelligence Service (SVR).
Campaign Overview
Since early May 2026, Storm-2945 has compromised hotel captive portal gateways to conduct DNS spoofing attacks, redirecting automatic connectivity checks to fake browser or OS update pages. Victims are tricked via ClickFix social engineering into executing attacker-supplied commands in Windows utilities, deploying CornFlake RAT.
CornFlake RAT Capabilities
- Establishes persistence through Registry Run keys and scheduled tasks with watchdog mechanisms
- Captures webcam images, microphone audio, and keystrokes
- Harvests browser cookies (including Chrome App-Bound Encryption), saved passwords, and clipboard contents
- Performs idle-triggered screenshots and removable media scanning
- Deploys ChocoShell stealer to harvest Microsoft 365, Azure AD, and Web Account Manager tokens
Since July 16, 2026, the campaign has incorporated Microsoft device code authentication flow abuse to obtain MFA-satisfied access tokens.
Targeting
Storm-2945 specifically targets the hospitality sector, compromising hotel Wi-Fi networks across multiple countries. The targeting pattern suggests strategic interest in travelers for espionage purposes consistent with SVR intelligence collection priorities. Microsoft identified common equipment and management systems across affected networks, suggesting potential supply chain or service provider compromise affecting multiple hospitality properties simultaneously.
Defensive Measures
- Deploy always-on, full-tunnel VPN solutions for traveling employees to route DNS queries through corporate resolvers before venue gateways can intercept them.
- Block Microsoft device code authentication flow via Conditional Access policies in environments where it is not operationally required.
- Implement endpoint detection rules for suspicious service creation matching CornFlake indicators: svchost32 service with display name 'Cloud Sync Service' and executable path %APPDATA%\svchost32\svchost32.exe.
- Monitor for unauthorized access to Token Broker cache .tbres files and unusual PowerShell execution targeting credential stores.
- Establish user awareness training instructing travelers to reject all software updates, certificates, or security utilities offered through captive portals and public Wi-Fi networks.
Geopolitical Context
European Critical Infrastructure Warnings
CERT.BE's coordinated advisories on Cisco Secure Firewall Management Center, VMware vCenter, and Adobe Campaign Classic vulnerabilities reflect heightened threat awareness among NATO and EU member states. Belgium's role as host to NATO and EU headquarters amplifies the strategic significance of infrastructure security warnings, as compromise of enterprise security appliances could enable lateral movement into sensitive governmental and alliance networks.
The emphasis on immediate patching is consistent with ongoing cyber operations linked to state-aligned actors targeting Western infrastructure. While no specific attribution is provided in the advisories, critical vulnerabilities in enterprise security and virtualization platforms are high-value targets for intelligence services and state-aligned APT groups historically linked to Russian, Chinese, and Iranian interests.
The advisories underscore Europe's dependency on U.S.-based technology vendors for critical security functions—a strategic vulnerability driving EU initiatives toward digital sovereignty and supply chain diversification. For critical infrastructure operators across Europe, the warnings reinforce the urgency of vulnerability management programs and defense-in-depth strategies that assume perimeter compromise.
Cryptocurrency Infrastructure Vulnerabilities
The COLDCARD firmware flaw highlights systemic vulnerabilities in cryptocurrency infrastructure that transcend traditional state-based threat models. The incident demonstrates how supply-chain weaknesses in widely deployed security hardware can create concentrated points of failure in decentralized financial systems. While no state actor attribution has been established, the technical sophistication required suggests either advanced criminal actors or state-adjacent capabilities.
The incident occurs against a backdrop of increasing state interest in cryptocurrency regulation and control. Regulatory authorities in Canada (Coinkite's home jurisdiction), the EU (advancing Markets in Crypto-Assets regulation), and other major jurisdictions may cite the incident to justify stricter hardware wallet certification and supply-chain security mandates. For emerging markets where hardware wallets serve as alternatives to unstable banking systems, the incident may erode trust in self-custody models and strengthen arguments for centralized exchange custody—a shift that aligns with state preferences for surveillance and control.
Recommended Actions
Immediate (0–24 hours)
1. COLDCARD users: Immediately move all funds from affected wallets to new wallets with seeds generated on patched firmware or alternative hardware.
2. Adobe Campaign Classic: Upgrade to version 7.4.3 build 9398 or later on all instances.
3. Cisco Secure Firewall Management Center: Check Cisco Security Advisories and apply emergency patches; restrict management interface access to trusted networks.
4. VMware vCenter: Check VMSA portal for patches and apply to all instances, prioritizing internet-facing deployments.
5. Ruby on Rails Active Storage: Apply latest Rails security patches to all applications using Active Storage.
Short-term (24–72 hours)
1. Traveling employees: Deploy always-on VPN solutions and block Microsoft device code authentication flow via Conditional Access policies.
2. COLDCARD migration: After firmware update, generate new seeds, verify backups, test with small transactions, then migrate remaining funds.
3. Audit logs: Review access logs for Adobe Campaign Classic, Cisco Management Center, VMware vCenter, and Rails applications for suspicious activity prior to patching.
4. Endpoint detection: Implement detection rules for CornFlake RAT indicators (svchost32 service, Token Broker cache access, unusual PowerShell execution).
5. Web application firewalls: Deploy WAF rules to monitor and block anomalous requests to Rails Active Storage routes.
This week
1. Vulnerability management review: Assess patch deployment timelines for critical vendor advisories and accelerate processes where gaps exist.
2. Third-party JavaScript: Review and harden policies for external script inclusion; implement Subresource Integrity (SRI) hashes and Content Security Policy (CSP) headers.
3. User awareness training: Brief traveling employees on risks of captive portal-delivered updates and fake security prompts.
4. Blockchain monitoring: Organizations holding cryptocurrency should implement continuous monitoring of wallet addresses for unauthorized transactions.
5. Network segmentation: Review and strengthen segmentation controls isolating management interfaces for security appliances and virtualization platforms.
Watch List
- Adform supply chain incident: On July 27, 2026, attackers compromised Adform's trackpoint-async.js file to inject cryptocurrency wallet-swapping malware. Organizations embedding Adform scripts should verify the malicious version is no longer served, instruct users to clear browser cache, and review third-party JavaScript inclusion policies.
- CVE assignments pending: Multiple critical vulnerabilities (Cisco Secure Firewall Management Center, VMware vCenter, Rails Active Storage) lack public CVE identifiers; monitor vendor advisories for technical details and proof-of-concept publication.
- COLDCARD additional sweeps: If significant portions of affected users fail to migrate, additional Bitcoin sweeps targeting remaining exposed wallets are likely in coming weeks.
- Storm-2945 expansion: Monitor for CaptiveCrunch campaign expansion beyond hospitality sector or geographic spread; watch for additional fake update delivery mechanisms.
Sources
- BleepingComputer: COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
- BleepingComputer: Rails patches critical Active Storage flaw with RCE potential
- The Hacker News: Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- The Hacker News: Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
- The Hacker News: Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
- The Hacker News: Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
- CERT.BE: Warning: Actively exploited vulnerability in Cisco Secure Firewall Management Center, Patch Immediately!
- CERT.BE: Warning: Multiple critical vulnerabilities in the vCenter component of many VMware products, Patch Immediately!
- CERT.BE: Warning: 1 critical and 1 high vulnerability in Adobe Campaign Classic that can lead to arbitrary code execution and file system read, Patch Immediately!
---
*This brief synthesizes open-source threat intelligence for defensive planning. Organizations should correlate these findings with internal telemetry and threat models to prioritize response activities.*
