« Reports in 2020 »

204 reports

2020-06-18 • 1inch Network

A critical bug in three newly deployed Bancor Network smart contracts caused direct-swap users to grant infinite ERC-20 approvals to a vulnerable contract, allowing approved tokens to be withdrawn from their wallets. Bancor and suspected white hats began …

#Bancor
2020-06-17 • ESET

ESET described Operation In(ter)ception, targeted attacks against aerospace and military companies in Europe and the Middle East observed from September to December 2019. The attackers used fake LinkedIn recruiter personas and bogus job offers to deliver …

#Inception #T1082 #T1140 #T1005 #T1036 #T1027 #T1071 #T1204 #T1053 #T1059 #T1078 #T1220 #T1114 #T1087 #T1018 #T1106 #T1048 #T1070 #T1047 #T1012 #T1110 #T1085 #T1116 #T1050 #T1086 #T1537 #T1117 #T1002 #T1035 #T1194
2020-05-30 • Dragos

However, while COVELLITE is also linked to broader Lazarus activity, this group leveraged substantially different capabilities and infrastructure to pursue a target set that does not overlap with observed WASSONITE activity. WASSONITE Since 2018 Dragos id…

#WASSONITE #KKNPP
2020-05-29 • Ahnlab

ASEC correlates several malicious Hangul document clusters using COVID-19, real estate, and renewable-energy themes and concludes they likely came from the same maker group based on overlapping EPS and payload characteristics. The documents abuse Encapsul…

#Phishing
2020-05-27 • Cylynx

Cylynx traces the November 2019 Upbit theft in which 342,000 ETH was moved from the South Korean exchange’s hot wallet to an attacker-controlled wallet later referenced in a U.S. Justice Department case involving Chinese money launderers and North Korean …

#Cryptocurrency #Upbit