« Reports in 2025 »

792 reports

2025-03-18 • KRCERT

KISA warns that vulnerable INNORIX Agent versions 9.2.18.001 through 9.2.18.538 can allow external file download and execution, creating an exploitation path that could be abused for malware delivery or follow-on compromise. Affected organizations are adv…

#Innorix
2025-03-18 • NKInternet

Connectivity to North Korea-linked AS131279 dropped on March 18, 2025 after changes to the SOA record and Route Origin Authorization for 175.45.176.0/22. The new ROA authorized AS131279 as the origin but set the maximum prefix length to /22, while the net…

#Trend
2025-03-17 • OKX

OKX says it detected a coordinated Lazarus effort to misuse its DeFi services through OKX Web3, which it characterizes as a DEX aggregator rather than a custodian of customer assets. In response, the company temporarily suspended its DEX aggregator servic…

#News #Bybit
2025-03-17 • Sygnia

Sygnia summarizes the February 2025 Bybit heist as a multi-stage compromise attributed by the FBI to TradeTraitor, also known as Lazarus Group and UNC4899. The attack began with a Safe{Wallet} developer's macOS workstation, likely compromised through soci…

#Bybit #SafeWallet
2025-03-15 • Slowmist

SlowMist analyzes a LinkedIn recruiting lure that pushed a blockchain engineer toward a Bitbucket project for a supposed Socifi game and staking platform. The repository hid a malicious payload far to the right of an otherwise normal-looking server.js lin…

#ContagiousInterview