Security News

Crypto audit of Threema revealed many vulnerabilities
2023-01-11 12:24

Researchers have discovered cryptographic vulnerabilities in Swiss-based secure messaging application Threema that may have allowed attackers to do things like break authentication or recover users' long-term private keys. The vulnerabilities have been fixed and Threema has since switched to a new communication protocol they designed with the help of external cryptographers.

Kinsing Crypto Malware Hits Kubernetes Clusters via Misconfigured PostgreSQL
2023-01-09 14:03

The threat actors behind the Kinsing cryptojacking operation have been spotted exploiting misconfigured and exposed PostgreSQL servers to obtain initial access to Kubernetes environments. Kinsing has a storied history of targeting containerized environments, often leveraging misconfigured open Docker daemon API ports as well as abusing newly disclosed exploits to drop cryptocurrency mining software.

RSA crypto cracked? Or perhaps not!
2023-01-06 19:59

Without meeting up first to agree on a secret encryption key. Very simply put, RSA has not one key, like a traditional door lock, but two different keys, one for locking the door and the other for unlocking it.

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]
2023-01-05 17:52

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all. Actually your passwords were encrypted, but the websites and the web services and an unstated list of other stuff that you stored, well, that *wasn't* encrypted.

GodFather Android Banking Trojan Targeting Users of Over 400 Banking and Crypto Apps
2022-12-21 09:16

An Android banking trojan known as GodFather is being used to target users of more than 400 banking and cryptocurrency apps spanning across 16 countries. This includes 215 banks, 94 crypto wallet providers, and 110 crypto exchange platforms serving users in the U.S., Turkey, Spain, Italy, Canada, and Canada, among others, Singapore-headquartered Group-IB said in a report shared with The Hacker News.

GodFather Android malware targets 400 banks, crypto exchanges
2022-12-21 08:00

An Android banking malware named 'Godfather' has been targeting users in 16 countries, attempting to steal account credentials for over 400 online banking sites and cryptocurrency exchanges. The malware generates login screens overlaid on top of the banking and crypto exchange apps' login forms when victims attempt to log in to the site, tricking the user into entering their credentials on well-crafted HTML phishing pages.

Elon Musk "Freedom Giveaway" crypto scam promoted via Twitter lists
2022-12-07 12:16

Giving Elon Musk a follow on Twitter? You might be shortlisted by scammers looking to defraud Elon's newest followers. New Musk followers are being added to a "Deal of the Year" list on Twitter that lures them into depositing small crypto amounts into the attackers' wallet with the false promise of receiving up to 5000 Bitcoin in return.

Elon Musk's Twitter followers targeted in fake crypto giveaway scam
2022-12-07 12:16

Twitter accounts giving Elon Musk a follow are being targeted in a crypto giveaway scam dubbed 'Freedom Giveaway.' [...]

SIM swapper gets 18-months for involvement in $22 million crypto heist
2022-12-03 16:15

Florida man Nicholas Truglia was sentenced to 18 months in prison on Thursday for his involvement in a fraud scheme that led to the theft of millions from cryptocurrency investor Michael Terpin. The funds were stolen following a January 2018 SIM swap attack that allowed Truglia's co-conspirators to hijack Terpin's phone number and fraudulently transfer roughly $23.8 million in cryptocurrency from his crypto wallet to an online account under Truglia's control.

Hackers use new, fake crypto app to breach networks, steal cryptocurrency
2022-12-03 15:12

The North Korean 'Lazarus' hacking group is linked to a new attack spreading fake cryptocurrency apps under the made-up brand, "BloxHolder," to install the AppleJeus malware for initial access to networks and steal crypto assets. A new report by Volexity has identified new, fake crypto programs and AppleJeus activity, with signs of evolution in the malware's infection chain and abilities.