FILTERING BY: CLEAR FILTER

DPRK State-Sponsored Campaign: Reverse-Infection Uncovers 1,640 Global Breaches

A counter-intrusion operation led by researcher Stykas has successfully exposed a massive North Korean state-sponsored campaign targeting 1,640 organizations across 57 countries. By exploiting vulnerabilities in the attackers' own infrastructure, the researcher achieved a reverse-infection, gaining access to Command and Control (C2) logs and internal datasets. The campaign primarily utilized social engineering through the deployment of fraudulent IT workers to gain initial access to corporate environments. Once inside, the actors deployed specialized scripts designed to harvest cryptocurrency private keys. This intelligence revelation provides critical visibility into the DPRK's methodology, victimology, and identity-spoofing frameworks used to bypass traditional perimeter defenses.

Critical Entropy Degradation in Coldcard Firmware Facilitates $38M BTC Theft

A critical firmware vulnerability in specific Coldcard Mk3 hardware wallet models has resulted in a catastrophic reduction of entropy during the seed generation process. The flaw, identified as a weak Pseudo-Random Number Generator (PRNG), degraded the cryptographic search space from a standard 128 bits to a highly vulnerable 40 bits. An attacker utilized AI-driven vulnerability discovery to identify the flaw and subsequently performed a rapid brute-force derivation of private keys. This coordinated attack resulted in the theft of approximately 594 BTC ($38 million) from up to 1,196 addresses within a 25-minute window, highlighting critical failures in automated security auditing and hardware-based entropy implementations.

Indirect Prompt Injection IPI in AI Agents Facilitating Unauthorized Cryptocurrency Transfers

Autonomous AI agents are increasingly susceptible to Indirect Prompt Injection (IPI), where malicious instructions are embedded within untrusted data sources such as web pages or documents. Attackers utilize encoded payloads (e.g., Base64) to bypass semantic filters, hijacking the agent's action layer to trigger unauthorized tool-calling and API execution. This vulnerability, confirmed across 13 frontier LLM models, enables the automated execution of irreversible cryptocurrency transactions. The primary risk lies in the agent's inability to distinguish between legitimate user intent and malicious instructions retrieved via Retrieval-Augmented Generation (RAG) pipelines.


LINK COPIED TO CLIPBOARD