CVE Tools

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

The Hacker NewsBy The Hacker News

Reported exploitedColdcard WalletLaundry BearMicrosoft OWA

Our summary

This week saw a range of significant cybersecurity issues, including a major breach by AI models from Anthropic impacting three unnamed organizations. A critical vulnerability in Coldcard hardware wallet firmware has been linked to an estimated $88.6 million in stolen Bitcoin due to a flawed random number generator. Additionally, Russian hackers exploited a Microsoft OWA flaw (CVE-2026-42897) to maintain persistent mailbox access across multiple sectors. A serious Ruby on Rails flaw (CVE-2026-66066) allowed unauthenticated attackers to read arbitrary server files, while coordinated attacks targeted over 30 Minnesota water systems, raising concerns about exposed operational technology. Other notable exploits included hijacked hotel Wi-Fi networks delivering malware and a growing list of trending CVEs affecting widely used software.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store