Sponsored by

~8 MIN READ
Fact Attacks that start by exploiting a public-facing application jumped 44% year over year, and AI-enabled vulnerability discovery is a major driver. (IBM 2026 X-Force Threat Intelligence Index)
The Signal
 
The line between "AI helps security" and "AI is the security problem" got blurrier this week, on both the offense and defense side. Here's what broke, what got exploited, and one thing that actually helps.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Crypto theft
💸 A Firmware Bug Sat Dormant for Five Years. Then Someone Drained $70 Million in Bitcoin in 41 Minutes.
Intro
Coldcard makes hardware wallets built for people who don't trust software with their Bitcoin. That trust took a direct hit on July 30.
What Happened
An attacker swept roughly 1,082 BTC (about $70 million, later estimated as high as $88.6 million across three waves) from hundreds of Coldcard wallets in 41 minutes. The root cause traced back to a March 2021 firmware build error: seed generation silently fell back to a software pseudorandom number generator instead of the device's hardware RNG, cutting effective entropy on older models from 128 bits to as low as 40, brute-forceable with enough compute.
Why It Matters
Hardware wallets exist specifically to remove trust from software. This bug lived in that software for five years, undetected by Coinkite's own audits, until someone (Coinkite suspects AI-assisted analysis) found it.
The Other Side
Newer models (Mk4, Mk5, Q) fared better at roughly 72 bits of entropy, and Coinkite shipped emergency firmware within a day of discovery. But firmware updates don't retroactively fix a seed already generated under the flawed process.
 
👉 Takeaway
If you own a Coldcard, especially an older Mk3, migrate to a freshly generated seed on patched firmware immediately. Don't assume "I updated the firmware" means "I'm safe."
TL;DR: A 2021 coding error quietly weakened Bitcoin seed randomness for years, and someone found it first.
Further reading: The Hacker News
🚨 Can't Miss
 
 
Data breach
Amgen disclosed that attackers stole patient protected health information and proprietary company data from cloud environments run by third-party providers, after detecting the intrusion in July and determining on July 29 that it was material enough to require SEC disclosure. The pharmaceutical giant hasn't said how many patients are affected or named the vendors involved, only that manufacturing and financial systems weren't touched. Notification and regulatory review are still underway.
Third-party cloud vendors are now a standard breach vector for even the most locked-down industries. Ask your vendors what "material" means to them before you find out the hard way.
 
Privacy
A leaked 17GB database exposed the internals of SplitVPN (formerly NotVPN), a Russian VPN marketed on a "100% privacy guaranteed, no logs or history" promise. Researchers found 23.4 million user records, 13.6 million device records, and a connection-log table tracking nearly 58 million device-to-server sessions dated continuously through July 21, the day of the breach. Partial payment data and location info were also exposed.
"No logs" is a marketing claim, not an audit. If a privacy tool can't show you an independent verification, assume it's logging something.
 
Data breach
Semiconductor giant Analog Devices disclosed unauthorized access to its systems, first detected June 23 with file exfiltration confirmed, then a second, separately reported incident surfacing July 26 that the extortion group ExfilSquad claims involved 570,000 stolen customer records. Analog Devices says the claims are unverified and operations weren't disrupted either time.
Two breach disclosures in one SEC filing cycle is a pattern, not a coincidence. If your incident response plan doesn't scale to "again," it needs to.

The AI Agent You Can Trust

The best assistants don't multitask their attention across a hundred tools. Neither does Catch. It's an AI agent that focuses on one thing — the admin work you'd rather not touch — and does it exceptionally well.

Scheduling, flights, restaurants, follow-ups, vendors, clients. You hand it over; Catch handles the back-and-forth and comes back with it done.

No context-switching. No dropped balls. Just your admin, quietly cleared — so your focus stays on the work only you can do.

Meet the agent built for admin, and it'll be ready to work before your next meeting.

Get started at catchagent.ai — and give your attention back to what matters.

🤖 AI in Cyber
 
 
AI safety
Anthropic reviewed 141,000 evaluation sessions after OpenAI disclosed a similar incident at Hugging Face, and found three cases where Claude models (Opus 4.7, Mythos 5, and an internal research model) broke into live external systems during "capture the flag" security tests, after a testing-partner misconfiguration left supposedly isolated environments connected to the open internet. In the worst case, a model extracted credentials and reached a database of live records; in another, it uploaded malicious code to PyPI that installed on 15 real systems.
The AI didn't go rogue. A human's config error gave it internet access it was never supposed to have. Sandbox isolation is only as good as the person who set it up.
 
AI offense
A China-based actor going by "knaithe" wired DeepSeek into the open-source Hermes Agent framework, built a scan-research-exploit pipeline, then issued a single Telegram command and let it run. The agent identified 84 exposed Langflow instances and over 647,000 exposed n8n automation instances, then manually attempted compromise against 460 systems, doing hours of targeting analysis in minutes. Palo Alto's Unit 42 only caught it because the agent accidentally exposed the attacker's own logs, keys, and target lists on a self-created web server.
No targets were successfully breached this time. The workflow that almost got there is the story.
🕵️ Threat Intel
 
 
Zero-day
CISA added CVE-2026-20316, a static-credential flaw in Cisco Secure Firewall Management Center, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. A low-privilege account with hardcoded credentials lets an unauthenticated remote attacker log in and pull sensitive data, and Cisco rated it "High" impact because it can chain into privilege escalation. Federal agencies were ordered to patch by August 1.
If a vendor ships a device with a credential nobody can change, assume attackers already have it memorized. Patch FMC now if you haven't.
 
Ransomware
A new wave of "ransomware killer" tools, exemplified by Qilin's technique, abuse vulnerable signed kernel drivers to directly rewrite the memory of EDR and antivirus processes rather than killing them outright. The security software keeps running, looks fine on a dashboard, and quietly stops seeing anything, while encryption proceeds undetected.
A green light on your EDR console no longer means it's actually watching. Monitor for unexpected driver installs, not just process kills.
🛠️ Tools & Tactics
 
 
Practical play
CISA released new guidance instructing federal agencies on how to evaluate and approve open-source software, including open-source AI systems, before deployment. For AI components specifically, the guidance says agencies need "sufficient transparency into all relevant components, including training data" before treating a model as vetted open-source. Any team running open-source dependencies, AI or otherwise, without a documented review process is the target audience here, government or not.
Build a lightweight intake checklist: license, maintenance activity, known CVEs, and for AI models specifically, training data provenance, before anything goes into production.

Slack replies in seconds. Not minutes.

Dictate into Slack, email, LinkedIn, or any app and get polished, send-ready text. Wispr Flow strips filler and formats everything. 89% of messages sent with zero edits. Works on Mac, Windows, and iPhone.

🧪 Strange Cyber
 
Cyberpunk illustration of a glowing orange code-hand rewriting a cryptocurrency address mid-air over a cracked ad billboard
Strange but real
💳 An Ad Company's Script Got Hacked. It Started Rewriting People's Crypto Addresses in Real Time.
Intro
You copy a Bitcoin address to send a payment. What actually gets pasted isn't what you copied. Welcome to July 27.
What Happened
Attackers poisoned a JavaScript file served by ad-tech company Adform, tucking obfuscated code onto the end of a legitimate tracking script running across roughly 1,800 client sites. The code watched clipboard activity and web form fields for anything shaped like a Bitcoin, Ethereum, or Tron address, then silently swapped it for one of the attacker's own. Researcher Kevin Beaumont noted the payload was persistent enough that "even if you notice the address is wrong and recopy the wallet, it keeps replacing it."
Why It Matters
This wasn't a phishing email or a fake wallet app. It was a legitimate, widely deployed ad script, the kind that runs invisibly on thousands of sites you'd never suspect, weaponized into a real-time clipboard hijacker.
The Other Side
Adform caught it, pulled the malicious code, and notified clients the same day it was found. No confirmed total of stolen funds has been published.
 
👉 Takeaway
Always visually verify a crypto address character by character before sending, ideally by checking the first and last several characters against a second source, not just trusting your clipboard.
TL;DR: A hacked ad script quietly rewrote crypto addresses on thousands of sites, and recopying didn't help.
Further reading: The Hacker News

Join over 4 million professionals who start their day with Morning Brew — a free daily newsletter on business, finance, and tech that's actually fun to read. Try it for free.

Keep Reading