Attackers are draining crypto wallets through “Ill Bloom,” disclosed by wallet-security firm Coinspect around July 10 — a weak-randomness flaw in how certain older or lesser-known software wallets generated their recovery phrases, producing seeds with far less entropy than a 12- or 24-word phrase implies and letting an attacker who knows the weakness reconstruct the keys directly.
Coinspect has confirmed one coordinated sweep in late May that took roughly $3.1 million from 431 wallets, plus a further $2.1 million afterward — more than $5 million total — and traced over 2,100 exposed addresses with on-chain activity across Bitcoin, Ethereum, Rootstock, Tron and Polygon. Hardware wallets and most mainstream software wallets are not affected.
The strategic read isn’t crypto-specific: this is a supply-chain-of-trust failure in a foundational primitive — randomness — that is invisible from the outside and that no amount of downstream monitoring would have caught. It’s the same argument as key-hygiene and dependency-visibility, one layer deeper, and it lands hardest when paired with the enterprise analog: entropy sources, cryptographic libraries, and hardware-security-module assumptions in your own stack.
Sources: The Hacker News, Cointelegraph, BeInCrypto, crypto.news, Coinspect
Vulnerabilities & Exposure
CISA adds two Joomla-extension flaws to its exploited-vulnerabilities catalog. Both are “unrestricted file upload” bugs in Joomla extensions that lead to remote code execution: one is unauthenticated arbitrary file upload leading to full compromise, the other requires authentication or a separate logic flaw. They were added under CISA’s risk-based patch directive. These carry low strategic weight for most security teams — they are website content-management-system plugin bugs, relevant mainly to public-web asset owners.
So what: No hours-matter emergency overnight, but the pattern holds from the week — exposure-management visibility beats raw patch velocity, and vendor severity self-assessments are not a reason to deprioritize once a bug is public.
SharePoint CVE-2026-45659 — this week’s context, not new news. The deserialization remote-code-execution flaw in SharePoint Server, which Microsoft patched in May and initially rated exploitation “less likely,” was added to CISA’s catalog July 1 with a July 4 federal deadline after confirmed in-the-wild use; reporting ties it to Warlock ransomware and the Storm-2603 threat actor. Any authenticated user with Site Member permissions can trigger it — a low bar. It’s carried here because the gap between the vendor’s initial assessment and CISA’s listing is the operational lesson.
So what: No hours-matter emergency overnight, but the pattern holds from the week — exposure-management visibility beats raw patch velocity, and vendor severity self-assessments are not a reason to deprioritize once a bug is public.
AI Impact on Security
The agent-behavioral-baseline gap is still open. Analysis from this year’s RSA Conference found that several major security vendors have all shipped agentic security-operations tooling, but none has shipped an agent behavioral baseline — the ability to know what “normal” looks like for an AI agent running with elevated privileges on an organization’s endpoints — and the gap remains unresolved a quarter later. Prompt injection stays the industry’s top-cited LLM risk, with one report citing 340% year-over-year growth. The point: everyone is racing to give agents authority; nobody has solved observability of the agent itself.
So what: This is the cleanest board-legible piece hook in the current cycle — the question of whether an organization can baseline and audit its own AI agents is central to the broader agentic-security and visibility conversation.
Cyberattacks & Breaches
Conduent breach confirmed at 62.2 million — now third-largest US healthcare breach. Conduent Business Services’ 2024-25 intrusion — network access dating to around October 2024, detected in January 2025 — has grown from early estimates of roughly 4 million to a confirmed 62,224,658 individuals in regulatory filings this cycle, exposing Social Security numbers and medical data. It ranks behind only two larger healthcare breaches on record. The durable story is the slow-motion scope creep of a single third-party business-process-outsourcing breach rippling across dozens of downstream client organizations.
So what: The week’s breach signal is concentration risk, not a new attack — one business-process outsourcer becomes a top-tier all-time breach because it sits under many clients, a reminder that trusted-insider and third-party risk extends further than most inventories account for.
BlackCat ransomware negotiator sentenced to nearly six years. A former incident-response and ransomware negotiator was sentenced to 70 months for conspiring with BlackCat/ALPHV operators to extort victims — an insider who worked the defense side of the table before crossing over. It is notable for the trust and insider-risk angle rather than its scale.
So what: The week’s breach signal is concentration risk, not a new attack — one business-process outsourcer becomes a top-tier all-time breach because it sits under many clients, a reminder that trusted-insider and third-party risk extends further than most inventories account for.
Regulatory & Policy
CISA’s risk-based patch cadence continues. The July 10 two-vulnerability batch is again the risk-based Binding Operational Directive at work: CISA keeps issuing short, per-batch remediation deadlines rather than a flat clock. There was no new directive overnight, but the operational takeaway is unchanged and compounding — catalog entries increasingly arrive with tight, specific due dates.
So what: The compliance calendar keeps compressing toward patching on a risk-based clock — the same standing argument for exposure visibility that can answer “are we affected, and by when?” in minutes.
Sources & further reading (6)
- The Hacker News — “Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets”
- Cointelegraph — “Thousands of crypto wallets at risk from Ill Bloom vulnerability, Coinspect”
- CISA — “CISA Adds Two Known Exploited Vulnerabilities to Catalog”
- The Register — “Microsoft said exploitation was ‘less likely’ … but CISA just added SharePoint RCE to KEV list”
- VentureBeat — “CrowdStrike, Cisco and Palo Alto Networks all shipped agentic SOC tools at RSAC 2026 — the agent behavioral baseline gap survived all three”
- HIPAA Journal — “Conduent Business Services Data Breach Affected More Than 62.2 Million Individuals”