๐จ ACTIVE EXPLOITATION
- Adform Supply Chain Compromise Distributes Crypto-Stealing Clipboard Hijacker
Adform's ad platform was compromised to deliver clipboard hijacker malware stealing cryptocurrency.
- Applies to Adform's advertising platform used by ~14,000 businesses and 30% of DSP market
- Attackers hijacked a widely used JavaScript tracking script hosted on Adform's domain
- Malicious script silently swaps copied crypto wallet addresses with attacker-controlled ones
- Malware continuously monitors clipboard for Bitcoin, Ethereum, and Tron addresses
- Data exfiltration includes victim IP, visited URL, and originating site to attacker server
- Malicious files and infrastructure evade detection by major antivirus and threat intel platforms ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
- Amgen reports cloud data breach exposing patient health and proprietary info
Amgen suffered a cloud data breach exposing patient and proprietary information.
- Applies to Amgen, a biotechnology company developing medicines for serious illnesses
- Data breach involved patient protected health information and proprietary corporate data
- Data was stolen from multiple cloud systems operated by third-party service providers
- Incident detected and responded to in July 2026 with forensic investigation ongoing
- No disclosed details on attack method, affected cloud providers, or threat actor involvement ๐ Coverage: bleepingcomputer.com ยท ๐ via r/cybersecurity
๐ ADVISORIES
- Ruby on Rails patches critical RCE vulnerability in Active Storage image processing
Ruby on Rails patched a critical vulnerability allowing unauthenticated remote code execution.
- Affects Ruby on Rails applications using Active Storage with libvips for image processing
- Vulnerability allows unauthenticated attackers to read arbitrary files and potentially execute remote code
- Exploited by uploading crafted image files triggering unsafe 'unfuzzed' libvips operations
- Patched in Active Storage versions 7.2.3.2, 8.0.5.1, and 8.1.3.1; libvips should be updated to 8.13 or later
- No evidence of exploitation in the wild as of July 30, 2026 ๐ Coverage: securityweek.com ยท ๐ Original: securityweek.com ยท ๐ via SecurityWeek