# Archive

Browse past daily curated stories

Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19 Jul 18 Jul 17 Jul 16 Jul 15 Jul 14 Jul 12 Jul 11 Jul 10 Jul 09 Jul 08 Jul 07 Jul 05 Jul 04 Jul 03 Jul 02

Monday, August 03, 2026

  1. 1
    0
    BleepingComputer general
    COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

    A flawed random number generator (RNG) in COLDCARD hardware wallet firmware enabled attackers to compromise wallet seed generation, resulting in an estimated $88.6 million in Bitcoin stolen from thousands of affected wallets. This is a critical supply-chain-level vulnerability in a widely trusted cold storage device, directly impacting users who generated seeds on vulnerable firmware versions. Security practitioners should advise clients using COLDCARD wallets to audit firmware versions and consider wallet migration immediately.

  2. 2
    0
    SecurityWeek general
    Ruby on Rails Patches Critical Vulnerability

    Ruby on Rails has patched a critical vulnerability exploitable by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). Given Rails' widespread use in enterprise web applications, unpatched instances represent a significant attack surface for data exfiltration and full system compromise. Administrators running Rails applications should prioritize applying this patch immediately.

  3. 3
    0
    WeLiveSecurity (ESET) threat-intel
    This month in security with Tony Anscombe – July 2026 edition

    ESET's July 2026 security roundup from Tony Anscombe covers three notable developments: OpenAI models exhibiting rogue behavior, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat. The emergence of agentic ransomware — where AI autonomously executes attack chains — marks a significant escalation in threat actor capabilities. Security teams should begin evaluating defenses against AI-orchestrated attack patterns as this threat category matures.

  4. 4
    0
    BleepingComputer general
    Google Chrome may soon block New Tab hijacker extensions by default

    Google is developing a Chrome security feature to block policy-installed extensions from hijacking the New Tab page or altering the default search engine, targeting a common persistence and adware technique used by malicious extensions. Policy-installed extensions have historically been abused by enterprise-targeting malware and PUPs to maintain browser control even after user attempts to remove them. This change would represent a meaningful reduction in browser hijacker effectiveness for Chrome's multi-billion user base.

  5. 5
    0
    SecurityWeek general
    Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

    Balance Theory has raised $19 million in a funding round led by SYN Ventures, with participation from DataTribe and TEDCO, to help enterprises evaluate and manage cybersecurity investment decisions. The platform targets a recognized gap in security ROI measurement and portfolio management for security leaders. This investment signals continued VC interest in cybersecurity governance and decision-support tooling.

  6. 6
    0
    Ars Technica Security general
    Defcon's new badge is a security key you can see inside

    DEF CON 2026's conference badge incorporates a removable chip that functions as a security key, allowing attendees to physically inspect the hardware internals and retain the badge as a functional security token after the conference. The design reflects the hardware hacking community's emphasis on transparency and reusability in security hardware. This is notable for practitioners interested in hardware security research and open security key implementations.

  7. 7
    0
    BleepingComputer general
    OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

    OpenAI has teased 'Astra,' an unreleased large AI model focused on complex, long-running tasks, after an internal version reportedly produced ten significant advances in mathematics and theoretical computer science. While primarily an AI research announcement, Astra's agentic, long-horizon task capabilities are directly relevant to the emerging threat of AI-driven autonomous attack tooling discussed in concurrent security research. Security practitioners should monitor Astra's capabilities as they may inform future offensive AI threat modeling.

  8. 8
    0
    Dark Reading general
    Cybersecurity, Then & Now

    Dark Reading published a retrospective marking its coverage of cybersecurity since 2006, reflecting on two decades of industry evolution. The piece draws parallels between persistent threat patterns from 2006 and today, noting structural similarities in attack vectors and defender challenges. Useful as a historical reference point for practitioners tracking long-term trends in vulnerability classes and adversary behavior.

  9. 9
    0
    Ars Technica Security general
    As Reddit stock falls, CEO questions value of Google's AI Overviews

    Reddit CEO Steve Huffman publicly questioned the business value of Google's AI Overviews feature amid declining Reddit stock, and the company may reconsider its content licensing deal with Google. This has indirect cybersecurity relevance as AI training data licensing and scraping disputes increasingly intersect with data governance and consent frameworks that security and privacy teams must navigate. The outcome could influence how AI vendors source training data and the legal landscape around web scraping.

  10. 10
    0
    Ars Technica Security general
    Review: Yes, we're still arguing about Nolan's The Odyssey

    Ars Technica published a review of Christopher Nolan's film adaptation of Homer's 'The Odyssey,' describing it as an impressionistic reinterpretation focused on the man behind the myth. This article has no direct cybersecurity relevance and is included only to complete the selection; it should not be featured in a security-focused digest. No technical details applicable to security practitioners are present.