View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Adform Supply Chain Compromise Distributes Crypto-Stealing Clipboard

๐Ÿšจ ACTIVE EXPLOITATION

  • Adform Supply Chain Compromise Distributes Crypto-Stealing Clipboard Hijacker Adform's ad platform was compromised to deliver clipboard hijacker malware stealing cryptocurrency.
    • Applies to Adform's advertising platform used by ~14,000 businesses and 30% of DSP market
    • Attackers hijacked a widely used JavaScript tracking script hosted on Adform's domain
    • Malicious script silently swaps copied crypto wallet addresses with attacker-controlled ones
    • Malware continuously monitors clipboard for Bitcoin, Ethereum, and Tron addresses
    • Data exfiltration includes victim IP, visited URL, and originating site to attacker server
    • Malicious files and infrastructure evade detection by major antivirus and threat intel platforms ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Amgen reports cloud data breach exposing patient health and proprietary info Amgen suffered a cloud data breach exposing patient and proprietary information.
    • Applies to Amgen, a biotechnology company developing medicines for serious illnesses
    • Data breach involved patient protected health information and proprietary corporate data
    • Data was stolen from multiple cloud systems operated by third-party service providers
    • Incident detected and responded to in July 2026 with forensic investigation ongoing
    • No disclosed details on attack method, affected cloud providers, or threat actor involvement ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ“‹ ADVISORIES

  • Ruby on Rails patches critical RCE vulnerability in Active Storage image processing Ruby on Rails patched a critical vulnerability allowing unauthenticated remote code execution.
    • Affects Ruby on Rails applications using Active Storage with libvips for image processing
    • Vulnerability allows unauthenticated attackers to read arbitrary files and potentially execute remote code
    • Exploited by uploading crafted image files triggering unsafe 'unfuzzed' libvips operations
    • Patched in Active Storage versions 7.2.3.2, 8.0.5.1, and 8.1.3.1; libvips should be updated to 8.13 or later
    • No evidence of exploitation in the wild as of July 30, 2026 ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ“„ Original: securityweek.com ยท ๐Ÿ‘ via SecurityWeek

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check