TL;DR
Adobe Campaign Classic patched a critical CVSS 10.0 code-execution flaw. Adform's ad-serving script was hijacked to steal cryptocurrency wallet addresses. Coldcard hardware wallet firmware flaw linked to $numerous Bitcoin theft in under an hour.
Executive Summary
- Adobe released security updates for a maximum-severity (CVSS 10.0) vulnerability in Campaign Classic that could enable arbitrary code execution without user interaction.
- Adform's advertising technology script was compromised in a supply-chain attack designed to intercept and redirect cryptocurrency wallet addresses from end users.
- A firmware vulnerability in Coldcard hardware wallets is suspected in the theft of 1,082.65 BTC (~$70.2 million) from 1,196 addresses in 41 minutes on July 30.
- Microsoft released updates for a record 570 security flaws as part of its Patch Tuesday cycle.
- Arch Linux disabled AUR package adoption to counter a surge in malicious package takeovers.
Top Threats Today
1. Adobe Campaign Classic CVSS 10.0 Remote Code Execution
Severity: CRITICAL Affected: Technology
Adobe has released security updates to address a maximum-severity vulnerability in Campaign Classic, its enterprise marketing automation platform, tracked as CVE-2026-48449 with a CVSS score of 10.0 [1]. The flaw could result in arbitrary code execution [1].
Sources:[1] The Hacker News
Recommended Action
- Review Adobe's security bulletin for Campaign Classic and apply updates immediately to all instances
- Verify all Campaign Classic deployments are running patched versions before resuming normal operations
- Monitor Campaign Classic logs for signs of exploitation prior to patching
2. Supply-Chain Attack: Adform Ad Script Hijacked for Cryptocurrency Theft
Severity: HIGH Affected: Technology
Attackers modified a JavaScript file served by advertising technology company Adform to rewrite cryptocurrency wallet addresses on customer websites, redirecting funds to attacker-controlled wallets [1][2]. Adform detected the incident on July 27, 2026, removed the malicious code, and notified affected clients [1].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- If your organization uses Adform ad services, audit wallet address transactions and customer notifications received on or before July 27
- Review JavaScript source integrity and implement Subresource Integrity (SRI) checks for third-party ad scripts
- Alert cryptocurrency users and payment processors to watch for anomalous wallet addresses in customer communications
3. Coldcard Firmware Flaw Linked to $70 Million Bitcoin Theft
Severity: HIGH Affected: Technology
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth approximately $70.2 million at the time [1]. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, a Bitcoin-only hardware wallet made by Canadian firm Coinkite [1]. The vulnerability is traced to a March 2021 firmware integration issue [1].
Sources:[1] The Hacker News
Recommended Action
- Coldcard users should check for firmware updates from Coinkite and apply any available patches
- Review Bitcoin address activity on affected wallets and consider transferring balances to freshly-generated, uncompromised addresses
- For new hardware wallet deployments, verify the latest firmware version is installed before accepting funds
4. Microsoft Patches Record 570 Security Flaws
Severity: HIGH Affected: Technology
Microsoft released software updates to address at least 570 security holes in Windows operating systems and other software, nearly triple the number of vulnerabilities patched in the previous month's record-breaking Patch Tuesday release [1].
Sources:[1] Krebs on Security
Recommended Action
- Prioritize testing and deployment of Microsoft security updates across Windows endpoints and server infrastructure
- Review Microsoft's vulnerability guidance to identify patches affecting your deployed software versions
- Plan extended maintenance windows if patch testing capacity is constrained
5. Arch Linux AUR Package Adoption Disabled Due to Malware Surge
Severity: MEDIUM Affected: Technology
The Arch Linux project temporarily disabled adoption of Arch User Repository (AUR) packages following a surge in malicious takeovers of existing packages [1].
Sources:[1] BleepingComputer
Recommended Action
- If you maintain Arch Linux systems using AUR packages, audit your package list for suspicious or recently-changed dependencies
- Consider alternative package sources or verify package integrity from trusted mirrors until Arch re-enables adoptions
- Monitor Arch project communications for updates on remediation and re-enablement timeline
Today’s Action Checklist
- ☐ URGENT: Apply Adobe Campaign Classic security update (CVE-2026-48449) to all instances
- ☐ URGENT: Audit third-party ad script integrity; verify Adform compromise does not affect your organization
- ☐ If using Coldcard wallets, check for firmware updates and review transaction activity for anomalies
- ☐ Plan Microsoft Patch Tuesday deployment across Windows infrastructure; prioritize high-impact CVEs
- ☐ Review Arch Linux AUR package usage and monitor project communications for remediation status