Tag: crypto
-
Smashing Security podcast #482: This hacker leaked GTA 6 and launched their own cryptocurrency
A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead, they’ve launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club… First seen on grahamcluley.com Jump to article:…
-
The Problem with Hard Coded Cryptography in Modern Applications
Hard-coded cryptography creates long-term security debt. Crypto agility makes algorithms, keys and cryptographic dependencies easier to replace as standards, threats and post-quantum requirements evolve. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-problem-with-hard-coded-cryptography-in-modern-applications/
-
Kryptoagilität macht aus der Umstellung auf Post-Quanten-Kryptografie einen planbaren Dreijahresprozess
Die Umstellung auf Post-Quanten-Kryptografie ist kein spätes Technikprojekt für Spezialisten, sondern eine Managementaufgabe mit festen Fristen. Wer jetzt Krypto-Inventar, Priorisierung und Lieferantensteuerung aufsetzt, macht aus einer schwer kalkulierbaren Bedrohung einen planbaren Transformationsprozess. Der Beitrag zeigt, warum Kryptoagilität für Unternehmen wichtiger wird als die einmalige Wahl eines neuen Algorithmus und wie CIO, CISO und Einkauf die……
-
Being Right Is the Easy Part
Tags: ai, banking, business, cloud, compliance, container, control, country, crypto, cryptography, data, email, encryption, endpoint, fraud, ibm, intelligence, jobs, strategy, technologyHome Blog <!– PKWARE Blog, "Being Right Is the Easy Part" – STYLES Design tokens + .pk-article class rules. Paste into a Code Block (or move the token layer to the child theme and keep only the .pk-article rules here). tags included. –> Guest Perspective Being Right Is the Easy Part The question I asked…
-
BSidesCharm 2026 You Can’t Migrate What You Can’t See: Discovering Real Post-Quantum Crypto
Tags: cryptoPresenters: Joseph N Wilson, Anurag Swarnim Yadav Our thanks to BSidesCharm for publishing their Creators, Authors and Presenter’s outstanding BSidesCharm 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidescharm-2026-you-cant-migrate-what-you-cant-see-discovering-real-post-quantum-crypto/
-
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there’s a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There’s a chance that you have just handed a complete stranger access to your savings. First seen on bitdefender.com Jump to article:…
-
Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords
Fake Minecraft clients are delivering WeedHack malware that steals gaming sessions, browser passwords, crypto wallets and personal files from infected Windows systems. First seen on hackread.com Jump to article: hackread.com/fake-minecraft-clients-weedhack-malware-windows-passwords/
-
Fake AML Sites Trick Crypto Users Into Approving Malicious Transactions
Researchers warn of fake anti-money laundering (AML) wallet-checking sites that impersonate legitimate services and trick crypto users into approving malicious transactions or token permissions. First seen on hackread.com Jump to article: hackread.com/fake-aml-sites-crypto-approving-malicious-transactions/
-
What Happens to Your Digital Life When You Die?
Scott Wright joins Shared Security to discuss his Digital Legacy Tree framework and upcoming book, The Digital Legacy Tree. We talk about what happens to your accounts, passwords, devices, files, money, cloud storage, crypto, and online identity if you die, become incapacitated, or are suddenly unavailable, and how to plan for trusted access without… First…
-
Network of 77 Firefox extensions linked to crypto theft uncovered
First seen on scworld.com Jump to article: www.scworld.com/brief/network-of-77-firefox-extensions-linked-to-crypto-theft-uncovered
-
Someone targeted security researchers using a fake crypto conference as a lure
A hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with “significant enhancements,” including a set of 167 remote commands and expands its targeting footprint globally.Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications. First…
-
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed…
-
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/
-
Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON
A threat actor impersonating a senior executive at a well-known cryptocurrency media outlet attempted to infect a Huntress researcher with malware in the days following this year’s Black Hat and DEF CON conferences, according to new research from the security vendor. The campaign began on X (formerly Twitter), where an account impersonating the executive sent…
-
Scammers are using fake crypto AML checkers to drain your wallet
We found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet/
-
Crypto Scammer Uses Claude Code to Screen 100,000+ Phone Numbers in Phishing Operation
Rapid7 found a crypto scammer used Claude Code on more than 100,000 phone numbers in a phishing and vishing operation targeting cryptocurrency holders. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-claude-code-crypto-vishing/
-
Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan (RAT) named MacSync. The campaign abuses a legitimate Claude shared-conversation page on the claude.ai domain, demonstrating how trusted AI-hosting infrastructure can be weaponized to bypass users’ normal phishing instincts. The intrusion investigated by Huntress began…
-
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below – ubnuler ubnlder ri18nr reaker rakier orakw joxn First seen…
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident. First seen on therecord.media Jump to article: therecord.media/safepal-crypto-hardware-breach
-
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident. First seen on therecord.media Jump to article: therecord.media/safepal-crypto-hardware-breach
-
North Korean remote IT staffer worked for US government agency, says FBI
The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/11/north-korean-remote-it-staffer-worked-for-us-government-agency-says-fbi/
-
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver’s license and a New York…
-
Fake The Odyssey Downloads Are Hiding Password-Stealing Malware
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information. The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-the-odyssey-fake-downloads-lumma-stealer/

