~/greenteam/nerd

Sunday, August 2, 2026

Daily digest

Light news day overall — no major CVEs or breaches directly touching M365 GCC High, Nutanix, or GovCloud stacks. Coverage below leans toward broader threat intel and infrastructure trend pieces.

cybersec BleepingComputer

Rails Patches Critical Active Storage Flaw with RCE Potential

A critical vulnerability in Ruby on Rails' Active Storage framework allows an unauthenticated attacker to read arbitrary files from a Rails application, with potential escalation to remote code execution. The Rails team has released patches addressing the flaw.

Why it matters: If any internally developed or vendor-supplied Rails apps fall within CMMC scope, this needs immediate patching and documentation under RA-5 (vulnerability scanning) and SI-2 (flaw remediation) controls.

cybersec SANS ISC

Atomic MacOS (AMOS) Stealer Infection Analyzed

SANS ISC published a technical breakdown of an active Atomic MacOS Stealer (AMOS) infection, detailing the delivery mechanism and data exfiltration behavior observed in a real-world sample.

cybersec The Hacker News

Coldcard Hardware Wallet Firmware Flaw Tied to $70M Bitcoin Theft

Galaxy Research linked a rapid theft of 1,082.65 BTC (~$70.2M) from 1,196 addresses in 41 minutes on July 30 to a firmware flaw in Coinkite's Coldcard hardware wallet. A March 2021 firmware integration error caused seed generation to route through a deterministic software pseudorandom number generator rather than a proper hardware entropy source.

cybersec The Hacker News

Hackers Poison Adform Ad Script to Swap Crypto Wallet Addresses

Attackers modified a JavaScript file served by ad-tech company Adform to rewrite cryptocurrency wallet addresses copied by site visitors. Adform detected the tampering on July 27, 2026, removed the malicious code, notified clients, and reported the incident to authorities.

cybersec Ars Technica Security

Defcon 2026 Badge Doubles as an Inspectable Security Key

This year's Defcon badge includes a removable chip functioning as a FIDO2 security key, designed to let attendees physically inspect the hardware before and after use. The badge remains usable as an authentication device after the conference ends.

infrastructure The Register

Deep Dive: Nvidia's Vera CPU and Olympus Cores

The Register published a technical deep dive into Nvidia's upcoming Vera CPU, detailing its 88 custom Olympus cores, 176 threads, 1.5TB of addressable RAM, and 1.8TB/s NVLink connectivity aimed at datacenter and AI workloads.