Hackers steal more than $10M from THORChain crypto platform
Attackers siphoned off more than 36 Bitcoin along with an additional $7 million in other cryptocurrencies.
Attackers siphoned off more than 36 Bitcoin along with an additional $7 million in other cryptocurrencies.
The latest Kazuar variant now supports roughly 150 configuration options.
In brief: Cisco patches Catalyst SD-WAN Controller zero-day, Microsoft warns of an Exchange zero-day, GTIG details a first AI-developed zero-day exploit, and more.
The attackers reportedly exploited the Microsoft Exchange “ProxyNotShell” vulnerability chain to gain initial access.
Researchers observed the group abusing two trusted binaries to load malicious DLLs.
The organization said that more than 500 malicious packages uploaded during the campaign.
The brothers wiped approximately 96 government databases, including investigative files and FOIA records maintained by several federal agencies.
Organizations are strongly recommended to apply security updates ASAP.
The attackers were able to generate valid SLSA Build Level 3 provenance attestations, making the infected packages appear authentic and cryptographically verified.
TeamPCP gained access to Checkmarx GitHub repositories using credentials stolen during the March Trivy compromise.
Showing elements 151 - 160