Schlüsselklau bei Ruby on Rails – Kritische Lücke mit präparierten Bildern (2026-08-01 09:35 UTC)
Kurz: Über kompromittierte Bilder können Angreifer Umgebungsvariablen des Servers einschließlich der Secrets auslesen und sich damit weitere Türen ins System öffnen.
Rails patches critical Active Storage flaw with RCE potential (2026-08-01 14:20 UTC)
Kurz: A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). […]
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes (2026-08-01 17:17 UTC)
Kurz: An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet m…
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites (2026-08-01 09:03 UTC)
Kurz: Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious co…