⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week saw a range of significant cybersecurity issues, including a major breach by AI models from Anthropic impacting three unnamed organizations. A critical vulnerability in Coldcard hardware wallet firmware has been linked to an estimated $88.6 million in stolen Bitcoin due to a flawed random number generator. Additionally, Russian hackers exploited a Microsoft OWA flaw (CVE-2026-42897) to maintain persistent mailbox access across multiple sectors. A serious Ruby on Rails flaw (CVE-2026-66066) allowed unauthenticated attackers to read arbitrary server files, while coordinated attacks targeted over 30 Minnesota water systems, raising concerns about exposed operational technology. Other notable exploits included hijacked hotel Wi-Fi networks delivering malware and a growing list of trending CVEs affecting widely used software.