Coldcard Seed Flaw: Update Firmware and Move Funds
Coldcard weak seed generation affects Mk3 and earlier Mk4, Mk5, and Q releases. Updating stops new weak seeds but does not repair an existing one. Check whether you must migrate.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 24, 2026
Coldcard weak seed generation affects Mk3 and earlier Mk4, Mk5, and Q releases. Updating stops new weak seeds but does not repair an existing one. Check whether you must migrate.
SvcHostUpdate.exe in Windows Startup matches a malicious web3-token-helper chain. Learn what the file proves, what to preserve, how to clean the PC, and which…
Cisco says attackers are exploiting a static credential in on-premises Secure FMC. Check for /var/tmp/license.tmp, install the release-specific hotfix, and rotate credentials, keys, and…
Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and credential stealer. Check lockfiles, isolate affected hosts, and rotate exposed secrets.
A network of more than 120 lookalike Walmart stores uses cloned catalogs, extreme liquor discounts, and a checkout that asks for the full card…
Dysphoria has grown to roughly 200,000 IoT bots and now uses blockchain-resolved command servers plus compromised relay nodes. Check routers, cameras, UPnP mappings, firmware,…
Operation BlueDash turns a secure-document email into a fake Teams update that installs Level RMM and ScreenConnect. Check your exposure state and remove every…
Arista confirms active exploitation of CVE-2026-16812 in VeloCloud Orchestrator On-Prem. Check affected releases, observed IPs, log clues, and the patch-versus-rebuild decision.
BlackFog analyzed MedusaHVNC, a Windows RAT that opens a browser on an invisible desktop and can use existing logged-in sessions. Check the five-stage chain,…