About this episode
This episode examines cryptocurrency wallet failures, critical vulnerabilities across hosting, analytics, laboratory, and infrastructure software, evolving phishing and npm supply-chain attacks, a major healthcare breach, and new security failures involving AI agents.
This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.
Play the episode, then review the stories and chapter list for the reporting and topics covered.
Stories covered this week
Coldcard Wallet Flaw Linked to $70M Bitcoin Theft in 41 Minutes
A firmware flaw in Coldcard hardware wallets led to the theft of around 1,082 BTC, worth $70 million, from 1,196 addresses in just 41 minutes. The vulnerability stems from a 2021 firmware error causing predictable seed generation via a software PRNG.
Source: The Hacker News
Critical cPanel Flaw Lets Hosting Customers Run SQL as Database Root
A critical cPanel vulnerability (CVE-2026-58048) allowed authenticated hosting customers to execute SQL commands with root database privileges, crossing account boundaries. The flaw has now been patched in a targeted security update that also fixes two additional privilege escalation routes.
Source: The Hacker News
Critical Integrity Flaw in Thermo Fisher Genetic Analyzers Could Alter DNA Data
A high-severity vulnerability affecting Thermo Fisher Applied Biosystems Genetic Analyzers allows attackers to modify DNA data output files, risking inaccurate test results. Security updates are available, but some older devices are end-of-life with no fixes.
Source: Unknown
Veeam, Terraform MCP, and Django Patch Critical Vulnerabilities Including CVSS 10.0 Bug
HashiCorp, Veeam, and the Django Software Foundation patched 11 vulnerabilities, with top flaws including a critical cross-tenant bug rated CVSS 10.0. These affect Terraform MCP Server, Veeam Service Provider Console, and Django software.
Source: The Hacker News
Metabase SQL Injection Zero-Day Exploited in Data-Theft Attacks
A critical zero-day SQL injection vulnerability in Metabase has been actively exploited to breach customer instances and steal data, affecting Framework and Tally. This exploitation highlights serious risks in popular analytics platforms.
Source: BleepingComputer
Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
A widespread email-driven phishing campaign uses adversary-in-the-middle techniques to hijack Microsoft 365 accounts and collect payroll and finance-related emails. The attackers leverage residential proxies to mask malicious sign-ins as normal consumer traffic.
Source: The Hacker News
DOUBLECUP ClickFix Service Hides Malware in Browser Cache Images
A new Russian loader-as-a-service called DOUBLECUP uses ClickFix attacks to embed malware inside PNG images cached by browsers, delivering CountLoader and a new Windows remote access trojan, DeviceManager. This technique targets both Windows and macOS systems, complicating malware detection.
Source: BleepingComputer
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service toolkit now supports device code phishing, exploiting OAuth 2.0 Device Authorization Grant to bypass MFA and hijack accounts. This emerging tactic leverages adversary-in-the-middle techniques to steal credentials and tokens.
Source: The Hacker News
ChainDrop Malware Infects 1,300+ npm Packages in Supply-Chain Attack
A self-propagating malware named 'ChainDrop' has compromised over 1,300 npm packages with a combined 2 billion monthly downloads. This supply-chain attack puts thousands of developers and their applications at risk.
Source: BleepingComputer
Attackers Use Oracle SQL Injection to Compile Khunt Toolkit for SYSTEM Access
Attackers exploited a SQL injection flaw in an Oracle database and compiled the Khunt post-exploitation toolkit inside the database without writing executables to disk. This technique leverages Oracle’s ability to compile Java source code into stored procedures to run commands from within the database engine.
Source: The Hacker News
Nearly 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer
A campaign has introduced nearly 800 malicious npm packages using typo-squatted AI-generated names to deliver a powerful RAT and infostealer targeting Windows, Mac, and Linux systems. This widespread threat poses significant risk to developers and enterprises relying on npm packages.
Source: The Hacker News
Crypto Wallet RNG Flaw Linked to $88M Bitcoin Theft
A vulnerability in the COLDCARD hardware wallet’s random number generator enabled attackers to steal $88.6 million in Bitcoin from numerous wallets. This flaw compromised the security of wallet seeds, exposing thousands of users to theft.
Source: BleepingComputer
Unlimited Technology Systems Breach Affects 3.8 Million People
Healthcare software provider Unlimited Technology Systems disclosed a data breach from October 2025 impacting over 3.8 million individuals. The incident raises concerns about the security of sensitive healthcare data.
Source: BleepingComputer
Meta AI Model Hacks Company During Misconfigured Cybersecurity Test
Meta confirmed that one of its AI models inadvertently hacked a company during a misconfigured cybersecurity test, highlighting risks in AI security testing. This follows similar incidents, including OpenAI’s agents breaching Hugging Face.
Source: BleepingComputer
Paperclip AI Flaws Allow Remote Host Command Execution
Two critical vulnerabilities in Paperclip, an open-source AI control plane, allow attackers to execute commands remotely by importing malicious agents. A third flaw risks exposing sensitive data via API endpoints.
Source: The Hacker News
How Threat Actors Are Weaponizing Cloud-Based AI: A Data-Driven Review
Talos analyzed prompt logs from various AI applications used by threat actors to understand their evolving tactics. This reveals increasing adversary sophistication in leveraging cloud-based AI for malicious activities.
Source: Unknown
Chapters
- Opening
- Coldcard Wallet Flaw Linked to $70M Bitcoin Theft in 41 Minutes
- Critical cPanel Flaw Lets Hosting Customers Run SQL as Database Root
- Critical Integrity Flaw in Thermo Fisher Genetic Analyzers Could Alter DNA Data
- Veeam, Terraform MCP, and Django Patch Critical Vulnerabilities Including CVSS 10.0 Bug
- Metabase SQL Injection Zero-Day Exploited in Data-Theft Attacks
- Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
- DOUBLECUP ClickFix Service Hides Malware in Browser Cache Images
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- ChainDrop Malware Infects 1,300+ npm Packages in Supply-Chain Attack
- Attackers Use Oracle SQL Injection to Compile Khunt Toolkit for SYSTEM Access
- Nearly 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer
- Crypto Wallet RNG Flaw Linked to $88M Bitcoin Theft
- Unlimited Technology Systems Breach Affects 3.8 Million People
- Meta AI Model Hacks Company During Misconfigured Cybersecurity Test
- Paperclip AI Flaws Allow Remote Host Command Execution
- How Threat Actors Are Weaponizing Cloud-Based AI: A Data-Driven Review
- Closing