Security researchers at Rapid7 have identified North Korean-linked actors embedding a backdoor within the source code of HAProxy. The malware was discovered running at the network edge of two South Korean companies, allowing attackers to mask command-and-control traffic while the load balancer continued to function normally.
By integrating the malicious code into the software itself, the threat actors successfully bypassed traditional detection methods. The backdoor enabled data theft and unauthorized access without disrupting the legitimate network traffic handled by the load balancer.
When the infrastructure itself is compromised, how do you verify your edge?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
OpenAI has confirmed that its new GPT-6 Astra model has achieved a 'Critical level' of cybersecurity proficiency. According to BleepingComputer, the model is capable of identifying zero-day vulnerabilities, marking a significant leap in AI-driven offensive and defensive capabilities.
The deployment comes with a warning from the developer: the model's advanced reasoning makes it significantly harder to monitor and control than previous iterations. This creates a dual-edged reality where the AI can patch flaws faster but may also be used to discover them more effectively.
Can safety protocols keep pace with autonomous zero-day discovery? 🛡️
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
A major security breach at Liquid Network resulted in the theft of $320 million worth of Bitcoin. The incident targeted the sidechain protocol, causing immediate liquidity concerns across the ecosystem.
Following the exploit, developers deployed a critical patch to secure the network. According to reports, the majority of the stolen assets have since been returned to their original addresses.
A massive heist neutralized by a rapid patch, but the vulnerability remains a warning.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Morpho has expanded its fixed-rate Midnight markets to the Ethereum network, introducing new USDC markets backed by WBTC and cbBTC. The expansion aims to provide more predictable yield options for users within the Morpho ecosystem.
Despite the rollout, approximately $5 billion currently held in Morpho Vaults is unable to participate in Midnight. This liquidity remains sidelined pending a decision from the DAO.
Will the DAO move fast enough to unlock that $5 billion?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
The extortion group ShinyHunters has claimed responsibility for breaching Florida's 'DAVID' database, an online platform used by the Department of Motor Vehicles. According to reports from BleepingComputer, the hackers allege they successfully exfiltrated over 200,000 driver records.
The stolen data reportedly contains sensitive information regarding motorists across the state. While the group has made these claims, official confirmation regarding the scope of the breach and the integrity of the DAVID system is still pending.
A massive leak of state-held driver data is a major privacy failure.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Researchers at UC California have demonstrated a WeChat worm capable of taking over accounts through incoming calls. The exploit functions even if the victim never answers the phone or touches the device, provided the caller is already present in the victim's contact list.
The vulnerability allows the worm to spread autonomously across the platform. According to security reports, Tencent has since moved to block the exploit to prevent widespread account hijacking.
A zero-click exploit that turns your contact list into a threat vector.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Malone Lam has pleaded guilty to leading an international social engineering operation that successfully siphoned $245 million in cryptocurrency. The scheme relied on sophisticated manipulation tactics to target victims and bypass security measures.
According to court filings, the operation functioned as a coordinated racketeering enterprise. Lam's involvement marks a significant milestone in the legal crackdown on large-scale crypto-based social engineering rings.
A massive haul for a single social engineering operation.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Attackers are successfully breaching F5 BIG-IP Access Policy Manager (APM) devices to install a sophisticated Linux rootkit. According to BleepingComputer, the malware intercepts PHP file loading to inject a fileless web shell directly into the system's memory.
By operating entirely in memory, the rootkit avoids writing malicious code to the disk, making it significantly harder for traditional security tools to detect the intrusion.
Memory-only persistence is becoming the new standard for high-end breaches.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Malone Lam has pleaded guilty to federal charges following a massive $245 million cryptocurrency theft. The indictment, which surfaced in September 2024, followed law enforcement investigations into Lam's sudden, unexplained wealth.
According to reports, Lam used the stolen funds to finance an extravagant lifestyle, including private jets, luxury cars, and vacations in the Hamptons. The case highlights the increasing use of RICO statutes to prosecute large-scale digital asset crimes.
The era of treating crypto heists as victimless crimes is officially over.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
🚨 ALERT: Chrome V8 zero-day exploited in the wild allows code execution
Google has released emergency patches for 230 security vulnerabilities following the discovery of an active exploit in the Chrome browser. The flaw, identified as CVE-2026-87491, is an out-of-bounds write bug within the V8 JavaScript and WebAssembly engine.
While the vulnerability is classified as medium-severity, it allows attackers to execute code within the browser's sandbox. Google's update aims to close this gap before widespread exploitation occurs.
Is your browser up to date?
@edited
Google has released emergency patches for 230 security vulnerabilities following the discovery of an active exploit in the Chrome browser. The flaw, identified as CVE-2026-87491, is an out-of-bounds write bug within the V8 JavaScript and WebAssembly engine.
While the vulnerability is classified as medium-severity, it allows attackers to execute code within the browser's sandbox. Google's update aims to close this gap before widespread exploitation occurs.
Is your browser up to date?
@edited
🚨 ALERT: Critical flaw in Alby Hub could allow remote takeover of Bitcoin wallets
Bitcoin wallet provider Alby has issued a warning regarding a critical vulnerability in Alby Hub, its self-hosted Lightning wallet. The flaw, affecting versions v1.7.0 through v1.7.x, could allow attackers to seize control of a wallet and drain its funds.
The risk is specifically tied to users who have made their Hub reachable from the internet. Because Alby Hub is self-hosted on personal computers or servers, the exposure depends entirely on the user's network configuration.
Self-hosting offers privacy, but it also shifts the entire security burden to you.
@edited
Bitcoin wallet provider Alby has issued a warning regarding a critical vulnerability in Alby Hub, its self-hosted Lightning wallet. The flaw, affecting versions v1.7.0 through v1.7.x, could allow attackers to seize control of a wallet and drain its funds.
The risk is specifically tied to users who have made their Hub reachable from the internet. Because Alby Hub is self-hosted on personal computers or servers, the exposure depends entirely on the user's network configuration.
Self-hosting offers privacy, but it also shifts the entire security burden to you.
@edited
🚨 ALERT: Chinese-language group hijacks Brazilian government servers for phishing
Cybercriminals have compromised several Brazilian government and educational servers to build a sophisticated reverse-proxy network. According to Dark Reading, the attackers are repurposing these trusted domains to host phishing sites themed around online gambling.
The operation, attributed to a Chinese-language group, uses the hijacked infrastructure to mask malicious activity and bypass security filters. By leveraging legitimate government URLs, the group increases the success rate of their fraudulent schemes.
Using state infrastructure to host scams is a massive breach of trust.
@edited
Cybercriminals have compromised several Brazilian government and educational servers to build a sophisticated reverse-proxy network. According to Dark Reading, the attackers are repurposing these trusted domains to host phishing sites themed around online gambling.
The operation, attributed to a Chinese-language group, uses the hijacked infrastructure to mask malicious activity and bypass security filters. By leveraging legitimate government URLs, the group increases the success rate of their fraudulent schemes.
Using state infrastructure to host scams is a massive breach of trust.
@edited
💰 BIG MONEY: Hunter Biden's LAPTOP Coin Creates A Crypto Millionaire and a $200,000 Bagholder
Hunter Biden's LAPTOP coin peaked at $199.51 two minutes in. One trader made $1.18M, another lost $200K. The post Hunter Biden's LAPTOP Coin Creates A Crypto Millionaire and a $200,000 Bagholder appeared first on BeInCrypto .
Worth watching as more details come out.
@edited
Hunter Biden's LAPTOP coin peaked at $199.51 two minutes in. One trader made $1.18M, another lost $200K. The post Hunter Biden's LAPTOP Coin Creates A Crypto Millionaire and a $200,000 Bagholder appeared first on BeInCrypto .
Worth watching as more details come out.
@edited
💰 BIG MONEY: Hunter Biden's LAPTOP token crashes 99% in three hours
The $LAPTOP token, launched on Base this Wednesday, saw a massive price collapse shortly after its debut. After opening at $247.55, the token traded as low as $1.90 within a three-hour window.
With a one billion supply, the token's valuation has plummeted to roughly match the $TRUMP token. Both assets currently sit near a $2 billion fully diluted valuation, though LAPTOP's market cap remains the larger of the two.
A massive liquidity event or a classic memecoin fade?
@edited
The $LAPTOP token, launched on Base this Wednesday, saw a massive price collapse shortly after its debut. After opening at $247.55, the token traded as low as $1.90 within a three-hour window.
With a one billion supply, the token's valuation has plummeted to roughly match the $TRUMP token. Both assets currently sit near a $2 billion fully diluted valuation, though LAPTOP's market cap remains the larger of the two.
A massive liquidity event or a classic memecoin fade?
@edited
💰 BIG MONEY: US crackdown on $24 billion crypto black market triggers laundering exodus
The DOJ has seized several Telegram channels and two wallets as part of a massive strike against a $24 billion crypto black market. The operation also saw OFAC sanction Xinbi and the developers behind SafeW and XinbiPay.
The crackdown is reportedly sending rival money launderers running for exits as authorities tighten the net on these high-value illicit networks.
With the heat rising, will the next wave of laundering move to even more obscure chains?
@edited
The DOJ has seized several Telegram channels and two wallets as part of a massive strike against a $24 billion crypto black market. The operation also saw OFAC sanction Xinbi and the developers behind SafeW and XinbiPay.
The crackdown is reportedly sending rival money launderers running for exits as authorities tighten the net on these high-value illicit networks.
With the heat rising, will the next wave of laundering move to even more obscure chains?
@edited
⚠️ JUST IN: Telegram Usernames Banned
📱Telegram has banned a stack of premium usernames including @aaaa, @bbbb, @cccc, @dddd and more.
⭐️The whole set is worth around 7–8 figures. This follows a US DOJ freeze of over $52 million in crypto tied to Xinbi Guarantee, the owner of these names — a Chinese Telegram marketplace linked to $24.2 billion in transactions since 2022.
🚮Banned usernames:
@aaaa @bbbb @cccc @dddd @eeee @ffff @gggg @hhhh @iiii @jjjj @kkkk @llll @mmmm @nnnn @oooo @pppp @qqqq @rrrr @tttt @uuuu @vvvv @wwww @yyyy @zzzz
@edited
📱Telegram has banned a stack of premium usernames including @aaaa, @bbbb, @cccc, @dddd and more.
⭐️The whole set is worth around 7–8 figures. This follows a US DOJ freeze of over $52 million in crypto tied to Xinbi Guarantee, the owner of these names — a Chinese Telegram marketplace linked to $24.2 billion in transactions since 2022.
🚮Banned usernames:
@aaaa @bbbb @cccc @dddd @eeee @ffff @gggg @hhhh @iiii @jjjj @kkkk @llll @mmmm @nnnn @oooo @pppp @qqqq @rrrr @tttt @uuuu @vvvv @wwww @yyyy @zzzz
@edited
🚨 ALERT: Indonesian banking users targeted by Android app-cloning campaign
The GoldFactory threat group is exploiting Android Work Profile features to deliver the Gigabud Trojan. The campaign targets users through cloned banking applications designed to intercept credentials and financial data.
Separately, the Mantax Otax group is also active in the region, spreading distinct malware through similar mobile-focused tactics.
Is the Android Work Profile becoming a prime target for mobile exploits?
@edited
The GoldFactory threat group is exploiting Android Work Profile features to deliver the Gigabud Trojan. The campaign targets users through cloned banking applications designed to intercept credentials and financial data.
Separately, the Mantax Otax group is also active in the region, spreading distinct malware through similar mobile-focused tactics.
Is the Android Work Profile becoming a prime target for mobile exploits?
@edited
Microsoft has released a massive security update addressing 974 flaws across its software ecosystem. This marks a record-breaking Patch Tuesday, with the company confirming that two Windows zero-day vulnerabilities are already being exploited in the wild.
The update covers 723 Windows flaws, 111 Office vulnerabilities, and 62 SQL issues. Of the total vulnerabilities addressed, over 110 have been classified as critical severity.
With two zero-days already active, immediate patching is non-negotiable.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
Cybercriminals have compromised several Brazilian government and educational servers to build a sophisticated reverse-proxy network. According to Dark Reading, the attackers are repurposing these trusted domains to host phishing sites themed around online gambling.
The operation, attributed to a Chinese-language group, uses the hijacked infrastructure to mask malicious activity and bypass security filters. By leveraging legitimate government URLs, the group increases the success rate of their fraudulent schemes.
Using state infrastructure to host scams is a massive breach of trust.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
A Ukrainian national has received a four-year prison sentence in the United States for his involvement in the Conti ransomware operation. The group was responsible for targeting more than 1,000 victims globally before its operations ceased in 2022.
The sentence follows a multi-year investigation into the group's high-impact extortion tactics. Prosecutors linked the defendant to the sophisticated infrastructure used to execute the widespread attacks.
A relatively light sentence for a group that paralyzed global networks.
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM
A new wave of Android-based cyberattacks is combining traditional malware with ransomware tactics to target mobile users globally. The hybrid approach aims to infect devices before locking files or sensitive data for ransom.
Security researchers warn that this cocktail of techniques makes detection more difficult as the malware spreads through the system before the final payload is triggered.
Is your mobile OS ready for this dual-threat approach?
@edited
Please open Telegram to view this post
VIEW IN TELEGRAM