Tag: crypto
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD Storm-3168: Agentic-driven cloud attacks using compromised service principals Don’t Call Us, We’ll Call Your APIs – TraderTraitor Backdoors Resurface on Victim With No Crypto Ties…
-
Microsoft’s X account hacked in crypto pumpdump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/
-
Tren de Aragua ATM Jackpotting Network Linked to $40.7 Million in U.S. Losses
The U.S. Treasury Department has sanctioned a Tren de Aragua (TdA)-linked financial network accused of using malware-driven ATM jackpotting attacks to steal an estimated $40.73 million from U.S. financial institutions. The September 30 action adds eight individuals, two Mexico-based companies, and seven TRON cryptocurrency addresses to the Office of Foreign Assets Control’s (OFAC) Specially Designated…
-
Metamask discloses security incident affecting its infrastructure
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/
-
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure.”We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors,” the software cryptocurrency wallet maker said. “At this time, we have identified no immediate threat to MetaMask wallets.”MetaMask First…
-
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.”Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker First seen on thehackernews.com Jump to…
-
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure.”We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors,” the software cryptocurrency wallet maker said. “At this time, we have identified no immediate threat to MetaMask wallets.”MetaMask First…
-
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure.”We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors,” the software cryptocurrency wallet maker said. “At this time, we have identified no immediate threat to MetaMask wallets.”MetaMask First…
-
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
-
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
-
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
-
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
-
SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access trojan and steal high-value data. The investigation found no evidence that the software vendor distributed a trojanized build or that the incident stemmed from a supply-chain compromise. Instead, attackers appear to have modified an existing…
-
Vietnamese man charged in $16 million ‘pig butchering’ crypto scam
A Vietnamese national was charged with money laundering for his role in a massive “pig butchering” scam, which defrauded a victim out of $16 million worth of cryptocurrency. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam/
-
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget’s wallet system.Exchanges keep…
-
âš¡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work…
-
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/
-
Lieferdienst: Flink-Kunden werden von Hackern erpresst
Der Lieferdienst Flink ist gehackt worden. Nun werden seine Kunden erpresst und sollen in Krypto bezahlen. Flink selbst lehnt sämtliche Lösegeldzahlungen ab. First seen on golem.de Jump to article: www.golem.de/news/lieferdienst-flink-kunden-werden-von-hackern-erpresst-2609-213466.html
-
Lieferdienst: Flink-Kunden werden von Hackern erpresst
Der Lieferdienst Flink ist gehackt worden. Nun werden seine Kunden erpresst und sollen in Krypto bezahlen. Flink selbst lehnt sämtliche Lösegeldzahlungen ab. First seen on golem.de Jump to article: www.golem.de/news/lieferdienst-flink-kunden-werden-von-hackern-erpresst-2609-213466.html
-
The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act
Tags: access, advisory, ai, application-security, breach, crypto, cyber, korea, malware, north-koreaThis weekly roundup covers a brazen breach claim against the FBI’s recruitment portal, a multinational advisory exposing North Korea’s fake-recruiter malware operation, a sweeping EU proposal to reshape children’s access to social media, a conversation on application security in the age of AI agents, a short-lived Discord ban in the Philippines, and a multimillion-dollar hot-wallet…
-
Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses. First seen on therecord.media Jump to article: therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft
-
ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment…
-
North Korean hackers suspected in $351M crypto theft, the largest so far this year
The $351 million theft from crypto exchange Bitget is the latest in a string of high profile hacks targeting the crypto sector. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/
-
Attackers build “silent” cryptominer on victim’s machine and give themselves away
Security researchers at Huntress have uncovered an unusual attack in which a threat actor compiled a cryptocurrency miner directly on a victim’s computer, rather than simply dropping a ready-made one, and in doing so generated so much activity that the intrusion stood out. The incident began in early September 2026 with the exploitation of CVE-2025-4632,…
-
Wurden Sie aufgefordert, an einem Bitcoin-Geldautomaten zu bezahlen? Lesen Sie zuerst dies hier
Tags: cryptoBetrugsmaschen an Krypto-Geldautomaten folgen oft einem vorhersehbaren Muster. Hier erfahren Sie, wie Sie diese erkennen und was Sie tun können, wenn Sie bereits darauf hereingefallen sind First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/scams/wurden-sie-aufgefordert-an-einem-bitcoin-geldautomaten-zu-bezahlen-lesen-sie-zuerst-dies-hier/
-
Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains
Crypto casino Duelbits has shut down its platform after attackers took roughly $7 million from several of its wallets. In the Duelbits crypto hack, the stolen assets were moved across four blockchains, and most of them were then converted into Ether. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/duelbits-crypto-hack-7m-stolen-casino-offline/
-
MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/
-
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/

