Last week had no single big story, but a series of reminders that in security the detail is what decides. The Coldcard hardware wallet lost roughly 88.6 million dollars because of a weak random number generator that slipped into the firmware back in 2021. The ShinyHunters group kept up its campaign against Salesforce-linked data and added more victims with tens of millions of records.
Alongside that, two critical vulnerabilities where waiting does not pay off. Adobe Campaign Classic got a patch for a CVSS 10.0 flaw that lets code run without user interaction. Rails fixed a critical hole in Active Storage that allowed file reads and potentially remote code execution. And on the road, another trick surfaced where a fake browser update over hijacked hotel Wi-Fi drops a surveillance trojan.