« 2024 »

654 reports

2024-10-15 • Allin Bits

Upon learning that his two main contributors to the LSM were directly linked to North Korea, Zaki should have immediately acted to address these concerns. Though described as a “rewrite,” their work mostly involved porting the original code for SDK compat…

#ITWorker #Cosmos
2024-10-13 • Doubleagent

DoubleAgent analyzes a newly identified Linux variant of DPRK-attributed FASTCash malware built for payment-switch environments that process card transactions. The Ubuntu 20.04 sample adds to earlier AIX and Windows FASTCash variants and appears related t…

#FASTCash
2024-10-10 • Cobo

Cobo analyzes the July 2024 WazirX incident as a Safe multisig compromise that let attackers transfer about $230 million in assets from an Indian exchange wallet. The wallet used a four-of-six approval model, with five WazirX hardware-wallet signers and o…

#WazirX
2024-10-10 • Quill Audits

QuillAudits describes the September 2024 BingX hot-wallet breach, where attackers stole about $44.7 million and moved funds across multiple blockchains to complicate tracing. The source identifies drained BingX wallet addresses, attacker-controlled Ethere…

#BingX