High
2026-08-05 18:08Z · last 4h · 47 findings
· glm-5.2:cloud
Threat Brief — 2026-08-05 — COLDCARD fears weaponised, critical patches land
Executive summary. Attackers are now exploiting public anxiety around the COLDCARD wallet breach to push ScreenConnect RATs via phishing — a social-engineering pivot from the original technical vulnerability. Coinkite has physically destroyed hundreds of hardware wallets in response to the $100M+ theft, and stolen-BTC addresses have become an impromptu blockchain message board. Meanwhile, critical patches from Veeam (CVSS 10.0 cross-tenant), Django, and HashiCorp Terraform MCP demand immediate attention, and Samsung has moved to ban TV apps caught turning devices into proxy nodes.
Top items
- COLDCARD phishing campaign deploys ScreenConnect RAT. A new phishing wave leverages the widely publicised COLDCARD wallet vulnerability and suspected $88.6M Bitcoin theft as a lure, tricking users into installing ConnectWise ScreenConnect remote access software. This is a distinct social-engineering development on top of the original key-generation flaw story first reported 2026-08-01. (src: BleepingComputer)
- Coinkite destroys hundreds of COLDCARD wallets; stolen BTC addresses become message board. Coinkite found that safely updating firmware on compromised devices was infeasible and physically destroyed hundreds of units. Separately, victims and opportunists are paying small sums to embed messages to the hacker directly in the blockchain at the addresses holding the stolen 594 BTC. These are new developments in the ongoing theft story first reported 2026-08-01. (src: SecurityLab; Xakep)
- Veeam, Terraform MCP, and Django ship critical patches led by CVSS 10.0 cross-tenant bug. An unauthenticated flaw in Veeam Service Provider Console allows cross-tenant access; HashiCorp Terraform MCP Server and Django also received critical fixes. Patch immediately — the Veeam bug is particularly dangerous for MSP environments. (src: The Hacker News)
- Samsung bans TV apps that silently turn devices into proxy nodes. Following research by Mnemonic showing popular Samsung TV apps were routing users' devices through proxy networks (first reported 2026-07-28), Samsung has now banned these apps from its platform — a concrete platform-level response to the TV proxy-abuse problem. (src: Xakep; SecurityLab)
- "Poison Claude" sells discounted Claude access while logging every customer prompt. Researchers identified a specific underground service offering illicit Claude API access at a discount, with the operator exfiltrating all customer prompts. This is a new concrete threat-actor service developing the broader LLMjacking trend first reported 2026-08-04. (src: The Hacker News)
Themes
- Breach news recycled as lures: The COLDCARD phishing campaign illustrates a tightening feedback loop where disclosure of a major theft immediately becomes phishing bait — defenders should expect attacker campaigns to mirror headline vulnerabilities within hours.
- Supply-chain pressure intensifies: Between the ChainDrop npm worm (1,300+ packages), trojanized npm packages using Ethereum for C2, and now Veeam's cross-tenant flaw, the software supply chain remains the dominant attack surface.
- Consumer IoT as silent infrastructure abuse: Samsung's app ban response confirms TV and set-top-box proxy abuse is now significant enough for platform owners to act, not just researchers to warn.
