exploit

Alex Labs freezes $3.9M of exploited funds sent to CEXs after hack

Alex Labs freezes $3.9M of exploited funds sent to CEXs after hack 2024-05-18 at 02:01 By Cointelegraph by Christopher Roark The team behind the Bitcoin layer-2 developer has successfully frozen some exploited crypto after the attacker tried to cash out by sending funds to exchanges. This article is an excerpt from Cointelegraph.com News View Original […]

Alex Labs freezes $3.9M of exploited funds sent to CEXs after hack Read More »

Organizations struggle to defend against ransomware

Organizations struggle to defend against ransomware 2024-05-17 at 07:01 By Help Net Security In this Help Net Security video, Jeremy Nichols, Director, Global Threat Intelligence Center at NTT Security Holdings, discusses a recent surge in ransomware incidents. After a down year in 2022, ransomware and extortion incidents increased in 2023. More than 5,000 ransomware victims

Organizations struggle to defend against ransomware Read More »

Binance develops ‘antidote’ to address poisoning scams after $68M exploit

Binance develops ‘antidote’ to address poisoning scams after $68M exploit 2024-05-16 at 14:01 By Cointelegraph by Zoltan Vardai Binance’s new algorithm has already helped detect over 13.4 million spoofed blockchain addresses on BNB and over 1.68 million on Ethereum. This article is an excerpt from Cointelegraph.com News View Original Source

Binance develops ‘antidote’ to address poisoning scams after $68M exploit Read More »

Google fixes third exploited Chrome zero-day in a week (CVE-2024-4947)

Google fixes third exploited Chrome zero-day in a week (CVE-2024-4947) 2024-05-16 at 12:01 By Zeljka Zorz For the third time in the last seven days, Google has fixed a Chrome zero-day vulnerability (CVE-2024-4947) for which an exploit exists in the wild. About CVE-2024-4947 CVE-2024-4947 is a type confusion vulnerability in V8, Chrome’s JavaScript and WebAssembly

Google fixes third exploited Chrome zero-day in a week (CVE-2024-4947) Read More »

Alex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiK

Alex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiK 2024-05-15 at 00:02 By Cointelegraph by Christopher Roark The deployer account changed an Alex contract’s implementation address, and multiple tokens were subsequently drained from its bridge. This article is an excerpt from Cointelegraph.com News View Original Source

Alex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiK Read More »

CertiK discovered $5M security flaw in Wormhole bridge on Aptos

CertiK discovered $5M security flaw in Wormhole bridge on Aptos 2024-05-13 at 23:01 By Cointelegraph by Christopher Roark A flaw in the bridge could have allowed an attacker to produce fake token transfers, but it was discovered and patched before anyone could take advantage of it. This article is an excerpt from Cointelegraph.com News View

CertiK discovered $5M security flaw in Wormhole bridge on Aptos Read More »

Rain exchange suffered $14.1M in suspicious outflows 2 weeks ago — ZachXBT

Rain exchange suffered $14.1M in suspicious outflows 2 weeks ago — ZachXBT 2024-05-13 at 20:01 By Cointelegraph by Christopher Roark Several wallets reportedly belonging to Rain sent suspicious token transfers to a new address. This article is an excerpt from Cointelegraph.com News View Original Source

Rain exchange suffered $14.1M in suspicious outflows 2 weeks ago — ZachXBT Read More »

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2024-4671)

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2024-4671) 2024-05-10 at 12:16 By Zeljka Zorz Google has fixed a Chrome zero-day vulnerability (CVE-2024-4671), an exploit for which exists in the wild. About CVE-2024-4671 CVE-2024-4671 is a use after free vulnerability in the Visuals component that can be exploited by remote attackers to trigger an exploitable heap

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2024-4671) Read More »

Bugs in Gains Network fork let traders profit 900% on every trade: Report

Bugs in Gains Network fork let traders profit 900% on every trade: Report 2024-05-10 at 00:05 By Cointelegraph by Christopher Roark An attacker could have placed a limit buy order with an arbitrarily high open price to automatically win every trade, the Zellic security platform discovered. This article is an excerpt from Cointelegraph.com News View

Bugs in Gains Network fork let traders profit 900% on every trade: Report Read More »

Kronos Research hacker shifts funds to Tornado Cash

Kronos Research hacker shifts funds to Tornado Cash 2024-05-07 at 11:01 By Cointelegraph by Prashant Jha Kronos Research was exploited for $25 million in November last year, and one of the six wallets linked to the hacker started moving funds to Tornado Cash on May 7. This article is an excerpt from Cointelegraph.com News View

Kronos Research hacker shifts funds to Tornado Cash Read More »

Hundred Finance hacker moves stolen assets a year after $7M exploit

Hundred Finance hacker moves stolen assets a year after $7M exploit 2024-05-02 at 15:01 By Cointelegraph by Ezra Reguerra The hacker holds about $4.3 million in various crypto assets in their Ethereum wallet. This article is an excerpt from Cointelegraph.com News View Original Source

Hundred Finance hacker moves stolen assets a year after $7M exploit Read More »

Pike Finance clarifies ‘USDC vulnerability’ statement on $1.6M exploit

Pike Finance clarifies ‘USDC vulnerability’ statement on $1.6M exploit 2024-05-02 at 11:01 By Cointelegraph by Ezra Reguerra Pike highlighted that the exploit occurred due to their team’s inadequate integration of third-party technologies such as the CCTP or Gelato Network’s automation services. This article is an excerpt from Cointelegraph.com News View Original Source

Pike Finance clarifies ‘USDC vulnerability’ statement on $1.6M exploit Read More »

Palo Alto firewalls: CVE-2024-3400 exploitation and PoCs for persistence after resets/upgrades

Palo Alto firewalls: CVE-2024-3400 exploitation and PoCs for persistence after resets/upgrades 2024-04-30 at 15:47 By Zeljka Zorz There are proof-of-concept techniques allowing attackers to achieve persistence on Palo Alto Networks firewalls after CVE-2024-3400 has been exploited, the company has confirmed on Monday, but they are “not aware at this time of any malicious attempts to

Palo Alto firewalls: CVE-2024-3400 exploitation and PoCs for persistence after resets/upgrades Read More »

Russian hackers’ custom tool exploits old Windows Print Spooler flaw (CVE-2022-38028)

Russian hackers’ custom tool exploits old Windows Print Spooler flaw (CVE-2022-38028) 2024-04-23 at 17:01 By Zeljka Zorz For nearly four years and perhaps even longer, Forest Blizzard (aka Fancy Bear, aka APT28) has been using a custom tool that exploits a specific vulnerability in Windows Print Spooler service (CVE-2022-38028). Dubbed GooseEgg, the tool is a

Russian hackers’ custom tool exploits old Windows Print Spooler flaw (CVE-2022-38028) Read More »

CrushFTP zero-day exploited by attackers, upgrade immediately! (CVE-2024-4040)

CrushFTP zero-day exploited by attackers, upgrade immediately! (CVE-2024-4040) 2024-04-23 at 13:01 By Zeljka Zorz A vulnerability (CVE-2024-4040) in enterprise file transfer solution CrushFTP is being exploited by attackers in a targeted fashion, according to Crowdstrike. The vulnerability allows attackers to escape their virtual file system and download system files (i.e., configuration files), but only if

CrushFTP zero-day exploited by attackers, upgrade immediately! (CVE-2024-4040) Read More »

Palo Alto firewalls: Public exploits, rising attacks, ineffective mitigation

Palo Alto firewalls: Public exploits, rising attacks, ineffective mitigation 2024-04-17 at 12:31 By Zeljka Zorz While it initially seemed that protecting Palo Alto Network firewalls from attacks leveraging CVE-2024-3400 would be as easy a disabling the devices’ telemetry, it has now been comfirmed that this mitigation is ineffectual. “Device telemetry does not need to be

Palo Alto firewalls: Public exploits, rising attacks, ineffective mitigation Read More »

CVE-2024-3400 exploited: Unit 42, Volexity share more details about the attacks

CVE-2024-3400 exploited: Unit 42, Volexity share more details about the attacks 2024-04-12 at 22:16 By Zeljka Zorz Earlier today, Palo Alto Networks revealed that a critical command injection vulnerability (CVE-2024-3400) in the company’s firewalls has been exploited in limited attacks and has urged customers with vulnerable devices to quickly implement mitigations and workarounds. Palo Alto

CVE-2024-3400 exploited: Unit 42, Volexity share more details about the attacks Read More »

Palo Alto Networks firewalls under attack, hotfixes incoming! (CVE-2024-3400)

Palo Alto Networks firewalls under attack, hotfixes incoming! (CVE-2024-3400) 2024-04-12 at 10:46 By Zeljka Zorz Attackers are exploiting a command injection vulnerability (CVE-2024-3400) affecting Palo Alto Networks’ firewalls, the company has warned, and urged customers to implement temporary mitigations and get in touch to check whether their devices have been compromised. “Palo Alto Networks is

Palo Alto Networks firewalls under attack, hotfixes incoming! (CVE-2024-3400) Read More »

Critical D-Link NAS vulnerability under active exploitation 

Critical D-Link NAS vulnerability under active exploitation  2024-04-11 at 14:31 By neetha871ad236bd Cyble Global Sensor Intelligence observed active exploitation of critical D-Link Vulnerability  Recently, the security community has raised concerns regarding the vulnerabilities found in D-Link Network Attached Storage (NAS) devices. The vulnerabilities, identified as CVE-2024-3272 and CVE-2024-3273 were disclosed initially by an individual who

Critical D-Link NAS vulnerability under active exploitation  Read More »

Scroll to Top