Back to Archive
THREAT INTELLIGENCE BRIEF·Sunday, August 2, 2026·AI-Powered

The most urgent threat this week is a critical remote code execution (RCE) vulnerability in the widely used Ruby on Rails framework, which requires immediate patching.

The most urgent threat this week is a critical remote code execution (RCE) vulnerability in the widely used Ruby on Rails framework, which requires immediate patching. Additionally, a maximum-severity CVSS 10.0 vulnerability was disclosed in Adobe Campaign Classic (CVE-2026-48449), though threat intelligence indicates a low exploitation probability (0.0054 EPSS score) and it is not on the CISA KEV list. Active threats include a software supply-chain attack where hackers poisoned an Adform script to steal cryptocurrency, and a firmware flaw in Coldcard hardware wallets that led to the theft of $70 million in Bitcoin, highlighting diverse real-world risks.

6 articles analysed1 CVEs mentioned

Threat Categories

🐛Vulnerabilities2
🛡️General Threat2

Article Analyses (4)

Rails patches critical Active Storage flaw with RCE potential

high

Details

A critical vulnerability in the Active Storage component of Ruby on Rails allows an unauthenticated attacker to achieve arbitrary file reads, which can be escalated to remote code execution (RCE).

Affected Systems

Ruby on Rails applications utilizing the Active Storage framework.

Potential Impact

Complete server compromise, leading to sensitive data exfiltration, application downtime, and further network intrusion.

Mitigations

Immediately apply the patches released by the Ruby on Rails project.

BleepingComputerDraft Post

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

medium
CVE-2026-48449
EPSS 0.5%

Details

Tracked as CVE-2026-48449, this vulnerability is an incorrect authorization flaw in Adobe Campaign Classic (ACC) that could allow an attacker to execute arbitrary code without any user interaction.

Affected Systems

Adobe Campaign Classic (ACC).

Potential Impact

Compromise of the enterprise marketing automation platform, potentially leading to the theft of customer data and unauthorized system control.

Mitigations

Apply the security updates provided by Adobe for CVE-2026-48449.

The Hacker NewsDraft Post

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

medium

Details

Attackers successfully executed a supply-chain attack by modifying a JavaScript file served by Adform, an advertising technology company. The malicious script was used as a browser-side tool to rewrite cryptocurrency wallet addresses on all customer websites that loaded the script.

Affected Systems

Any website that loaded the compromised Adform script on July 27, 2026.

Potential Impact

Direct financial loss for users of affected websites who performed cryptocurrency transactions. Reputational damage to companies whose sites were compromised by the third-party script.

Mitigations

Adform has removed the malicious code, notified affected clients, and reported it to authorities.

The Hacker NewsDraft Post

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

medium

Details

A firmware integration error introduced in March 2021 caused the Coldcard hardware wallet to use a weak software-based pseudorandom number generator (PRNG) for seed generation, making private keys predictable.

Affected Systems

Coldcard hardware wallets affected by the specific firmware flaw.

Potential Impact

Catastrophic and irreversible loss of cryptocurrency funds for owners of the affected devices. The flaw has been actively exploited, resulting in over $70 million in losses.

Mitigations

Review the source advisory for specific indicators of compromise and update detection rules accordingly. Maintain enhanced monitoring posture and validate exposure against your asset inventory.

The Hacker NewsDraft Post
Generated by gemini-2.5-pro