๐ต๏ธ RESEARCH & DEEP DIVES
- Coldcard Bitcoin Wallet Hacked for $70M; Russia Behind Recent Hotel WiFi Attacks
Coldcard Bitcoin wallets were hacked resulting in $70 million stolen.- Applies to Coldcard Bitcoin hardware wallet users
- Attack resulted in theft of $70 million worth of Bitcoin
- Russia identified as actor behind recent hotel WiFi network hacks
๐ Coverage: risky.biz ยท ๐ via Risky Business News
๐ CVEs & KEV
- CVE-2026-18585 โ GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow
- CVE-2026-18584 โ GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization
- CVE-2026-18583 โ mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-bounds
- CVE-2026-6695 โ Gimp: remote code execution via crafted paa file
- CVE-2026-6694 โ Gimp file-png plugin: denial of service via oversized apng trns chunk
- CVE-2026-13586 โ PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) in Bouncy Castle
- CVE-2026-13506 โ Lazy ASN.1 sequence forcing resets nesting-depth guard in Bouncy Castle for Java
- CVE-2026-12860 โ RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path in Bouncy Castle
- CVE-2026-12852 โ MLS wire decoder allocates attacker-declared opaque length before bounds check
- CVE-2026-12817 โ OpenPGP AEAD decryption skips final tag on chunk-aligned data in Bouncy Castle
- CVE-2026-12816 โ IESEngine stream-mode MAC forgery via length-dependent KDF split in Bouncy Castle
- CVE-2026-12803 โ KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD attack)
- CVE-2026-12802 โ CMS AuthEnvelopedData fails to enforce tag-length on decryption in Bouncy Castle
- CVE-2026-14682 โ Possible OOM from unbounded up-front allocation on a definite-length read in Bouncy Castle