Daily Recap, threat actors and campaigns continue to target cryptocurrency wallets and cloud services, with Trust Wallet theft linked to a Shai-Hulud NPM supply-chain attack and a new GlassWorm wave trojanizing wallets on macOS. Another notable round-up highlights phishing via Google Cloud email, unpatched Adobe ColdFusion server campaigns, Covenant Healthβs data breach affecting 478,000 people, and ongoing ThreatsDay Bulletin coverage of GhostAd Drain, macOS attacks, proxy botnets, and cloud exploits. #ShaiHulud #GlassWorm #TrustWallet #macOS #GoogleCloud #AdobeColdFusion #CovenantHealth #GhostAdDrain #ThreatsDayBulletin
Crypto & Wallet Threats
- Researchers link the $8.5 million Trust Wallet theft to a Shai-Hulud NPM supply-chain attack while a new GlassWorm wave is trojanizing crypto wallets on macOS, underscoring targeted wallet compromises β Trust Wallet, GlassWorm Malware, ThreatsDay Bulletin
Cloud & Server Attacks
- Attackers are abusing a Google Cloud email feature in a multi-stage phishing campaign to bypass defenses and harvest credentials β Cloud Email Abuse, ThreatsDay Bulletin
- Coordinated campaigns are actively targeting unpatched Adobe ColdFusion servers to deploy malware and gain persistence across environments β ColdFusion Campaign, ThreatsDay Bulletin
Breaches & Botnets
- A data breach at Covenant Health impacts 478,000 individuals, exposing sensitive records and patient data β Covenant Breach
- ThreatsDay Bulletin summarizes multiple active threats including the GhostAd Drain campaign, ongoing macOS attacks, and rising proxy botnets and cloud exploits across 12+ stories β ThreatsDay Bulletin
Regulation & Trends
- Chinaβs new cybersecurity law for 2026 introduces sweeping compliance and data localization changes that materially alter business obligations in the country β China Law
- Roundup of the biggest cybersecurity and cyberattack stories of 2025 highlights major incidents, trends, and lessons learned heading into 2026 β 2025 Roundup