CyberNews: 02/08/2026 Edition

Published by Dunateo on 2026-08-02

Today’s roundup

  • Rails patches critical Active Storage flaw with RCE potential
  • Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
  • UK’s state investments agency hit by data breach
  • CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
  • Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
  • Summary

    A critical vulnerability has been patched in the Ruby on Rails Active Storage framework. This flaw, with RCE potential, allowed unauthenticated attackers to read arbitrary files from a Rails application and could escalate to remote code execution. Users are urged to apply the available patches immediately.

    A significant Bitcoin theft on July 30 saw attackers drain 1,196 Bitcoin addresses, amounting to approximately $70.2 million. Galaxy Research identified a firmware flaw in the Coldcard hardware wallet, manufactured by Coinkite, as the root cause. The vulnerability stemmed from a March 2021 firmware error that directed seed generation to a deterministic software pseudorandom number generator.

    The UK Government Investments (UKGI) agency, responsible for state investments, disclosed a data breach exposing sensitive management information and contact details for 51 government officials. The security lapse rendered the data publicly accessible for nearly 40 hours before being secured. The incident has prompted calls for improved internal security within the public body.

    CISA has issued an urgent advisory for utility operators to remove internet-exposed Programmable Logic Controllers (PLCs) and bolster OT security, following coordinated cyberattacks on over 30 Minnesota water utilities between July 26 and 27. The attacks, attributed by researchers to the Iranian-affiliated CyberAv3ngers, disrupted operational technology systems, knocking one water plant offline and causing boil water notices. Attackers exploited vulnerabilities like CVE-2021-22681 in Rockwell Automation devices, as well as Schneider Electric and Siemens systems, by changing passwords and IP addresses to lock out operators and stealing PLC project files for reconnaissance. The FBI confirms similar PLC-related incidents in at least seven states.

    Microsoft Threat Intelligence has unveiled extensive details on the "CaptiveCrunch" campaign, attributed to the Russian state-sponsored group Storm-2945 (Midnight Blizzard/APT29). Since May 2026, the group has been manipulating DNS and HTTP traffic on captive portal networks in hotels and conference centers worldwide. Travelers connecting to these Wi-Fi networks are redirected to malicious landing pages that deploy the CornFlake remote access Trojan (RAT) and the ChocoShell infostealer. CornFlake provides comprehensive system control, including keystroke logging, screenshot capture, and data exfiltration, while ChocoShell specifically targets Microsoft 365, Azure Active Directory, and Web Account Manager tokens, as well as Wi-Fi credentials, employing advanced techniques like Chrome DevTools Protocol for cookie extraction and device code phishing.

    Want to dig deeper?

    Cyber Groups

    APT29 IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard
    CyberAv3ngers Soldiers of Soloman
    Blizzard Russia