Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Ukraine Shutters Major Russian Bot Farm

    Ukrainian law enforcement has reportedly dismantled a bot farm leveraged by Russian special services. The bot farm was used to spread disinformation and propaganda in the country via social media platforms. The Secret Service of Ukraine (SSU) stated that the bot farm spun content that destabilized the country. Most of this content is believed to…

  • CFTC Would Become Primary Crypto Regulator Under New Senate Committee Plan

    The Senate Agriculture Committee, which oversees the Commodity Futures Trading Commission, introduced a bipartisan bill Wednesday that would grant the CFTC “exclusive jurisdiction” over cryptocurrency trades that meet commodities law. The Digital Commodities Consumer Protection Act of 2022, sponsored by Senators Debbie Stabenow (D-Mich.), John Boozman (R-Ark.), Cory Booker (D-N.J.) and John Thune (R-S.D.), would…

  • Web3’s complexity a challenge for security as adoption of ‘the new internet’ grows

    Web3 — or the new internet — is growing more mainstream recently. Despite the crypto crash, internet giants have continually invested in Web3 over the past few months. Meta started testing NFTs on Facebook with selected creators; eBay acquired leading NFT marketplace KnownOrigin; Mastercard opened its payment network to Web3. While the new internet revolutionizes industries and…

  • 69% of Stolen Tokens in 2022 was From Cross-Chain Bridge

    According to a study released on August 2 by blockchain analytics firm Chainalysis, there have been 13 separate token bridge violations (Crypto Hacks) this year, the most recent being the $190 million Nomad Bridge hack. According to their calculations, 13 different hacks have resulted in the Cross-chain bridge attacks accounting for 69% of the cash…

  • Nearly $5M Swiped From Self-Proclaimed ‘World’s Most Secure’ Exchange ZB.com

    ZB.com, a cryptocurrency exchange that stopped accepting deposit and withdrawal requests on August 2, has had roughly $4.8 million taken from its hot wallet in a probable attack. Nearly $5 million has been drained from digital asset exchange ZB.com’s hot wallet in a likely hack. Security firm PeckShield made the announcement Wednesday on Twitter, posting…

  • Is Solana Initiating Recovery Plan After Major Hack?

    The global digital asset industry woke to another hacking incident in just two days. This time Solana (SOL) network came on the radar of the hackers. SOL prices have dropped by over 5% since the news broke out. As per reports, around $8 million have been removed from more than 7500 Solana based wallets. The list…

  • NSF Invests $25.4M into Cybersecurity and Privacy Research Projects

    The National Science Foundation (NSF) announced on Monday that it plans to invest $25.4 million to support research and projects related to cybersecurity and privacy. The investment is part of the Secure Trustworthy Cyberspace program, which aims to improve cybersecurity and privacy practices to best serve the economy and citizens. The awardees will be organizations…

  • Google Patches Critical Android Bluetooth Flaw in August Security Bulletin

    On Monday, Google published its monthly security bulletin, releasing the latest available patches for Android devices. In this month’s update, a total of 37 vulnerabilities were patched. One of these patches is a critical security flaw that lies in the System component. If exploited by malicious actors, the flaw could lead to remote code execution…

  • US Indicts Russian Accused of Promoting California’s Secession

    US authorities have indicted a Russian national who is accused of running a campaign to cause discord and interfere in elections. The campaign took place in California and was orchestrated by at lest three Russian officials. The campaign ran from December 2014 to March 2022, according to authorities. The individual indicted is Moscow resident Aleksandr…

  • IAEA says Zaporizhzhia nuclear plant out of control

    According to the head of the UN’s nuclear agency, the large nuclear power plant that was occupied by Russia during the invasion of Ukraine is out of control. Rafael Grossi called for the plant to be inspected and for necessary repairs to be made. This nuclear plant is the largest in Europe and is dangerously…

  • China fires missiles near Taiwan in live-fire drills as PLA encircles island

    Multiple missiles were fired towards waters near northeastern and southwestern Taiwan on Thursday by China. Beijing is making good on its promise that Taipei will pay a price after hosting US House Speaker Nancy Pelosi. The Eastern Theater Command from the Chinese military said all missiles hit their target accurately. The live-fire training mission was…

  • Will DeFi mark the beginning of the end of centralised finance, or mark its value?

    Defy. To openly resist. DeFi. The contraction commonly used for decentralised finance. The buzzword used to describe the financial ecosystem getting plenty of mainstream traction sounds similar to the verb used to describe a refusal to obey. And from the outset, DeFi has been all about a defiance of the established hierarchy of banks, brokers and other…

  • The 10 Most Common NFT Scams and Techniques to Avoid Them

    Essentially, there are two types of NFT buyers in the market. The first one is aware of the legitimacy and the working mechanism of NFTs. In contrast, the second one is less proficient at NFTs but still considers them good investments. Undoubtedly, the chances of falling for NFT scams is higher for the second one…

  • Robinhood’s Crypto Unit Fined $30 Million by New York’s Top Financial Regulator

    The New York State Department of Financial Services imposed a $30 million fine on the cryptocurrency trading unit of online brokerage Robinhood Markets Inc. for alleged violations of anti-money-laundering and cybersecurity regulations, in the department’s first crypto enforcement action. The New York State financial regulator said Tuesday that Robinhood Crypto LLC failed to maintain and certify…

  • Lawmakers propose rules to regulate battered cryptocurrencies

    A bipartisan group of senators on Wednesday proposed a bill to regulate cryptocurrencies, the latest attempt by Congress to formulate ideas on how to oversee a multibillion-dollar industry that has been racked by collapsing prices and lenders halting operations. The regulations offered by Senate Agriculture Committee chair Debbie Stabenow and top Republican member John Boozman would…

  • Ongoing solana attack targets thousands of crypto wallets, costing users more than $5 million so far

    Nearly 8,000 digital wallets have been drained of just over $5.2 million in digital coins including solana’s sol token and USD Coin (USDC), according to blockchain analytics firm Elliptic. The Twitter account Solana Status confirmed the attack, noting that as of Wednesday morning, approximately 7,767 wallets have been affected by the exploit. Elliptic’s estimate is…

  • DDoS Attacks Pepper Taiwanese Government Sites

    According to the foreign ministry of Taiwan, the websites of the ministry and presidential office were hit by multiple distributed denial of service (DDoS) attacks, resulting in intermittent outages across several government websites. The attacks occurred after the arrival of senior US lawmaker Nancy Pelosi. The visit has angered Beijing, which claims Taiwan as its…

  • 7 password-stealing Android apps removed from Google Play

    Security researchers at Trend Micro reported that seventeen malicious apps designed to infect Android users have been removed from the Google Play Store. The apps used banking malware and have been dubbed DawDropper. The malware campaign leverages four types of banking trojans, Octo, TeaBot, Hydra, and Ermac. The attack type has been described as a…

  • Malicious Npm Packages Tapped Again to Target Discord Users

    Security researchers at Kaspersky recently uncovered a LofyLife campaign that steals tokens and infects client files, allowing them to monitor certain user actions such as logins, password changes, and payment methods. The campaign targets Discord users via the node package manager (NPM) repository. In addition to the aforementioned capabilities, the attacker can also steal information…

  • Bangladesh turns to ADB, World Bank for funds

    The government of Bangladesh has sought assistance from both the World Bank and Asian Development Bank to increase its foreign exchange reserves. The government wrote letters to both entities requesting $1 billion to help the economy. The economy in Bangladesh has been struggling since the effects of the war in Ukraine along with energy price…

  • US warns of possible retaliation over al-Qaeda death

    The United States government has urged its citizens to be vigilant against anti-American violence abroad after the al-Qaeda leader Ayman al-Zawahiri was killed. His death could prompt supporters of al-Qaeda or other terror groups to target US personnel and facilities according to the state department.  The state department gave a worldwide caution update after the…

  • North Korean fraudsters suspected of copying people’s LinkedIn and Indeed profiles in a bid to land jobs at U.S. crypto firms

    North Korean hackers are raiding job sites like LinkedIn and Indeed and stealing tidbits of information from real profiles to build plagiarized resumes and land jobs at U.S. cryptocurrency firms, according to security analysts. Security researchers at Mandiant Inc. told Bloomberg that fraudsters were attempting to secure employment at these companies as part of a bigger…

  • Threat Actors Merging Malicious Activity With Cryptocurrency Show How the Attack Landscape is Developing in Decentralized Finance

    Widespread implementation of decentralized finance (DeFi) systems since 2020 has created new fertile ground for a variety of threat actors to shift the development of cyberattack tactics, techniques, and procedures (TTPs). The number of threat actors participating in DeFi activity has grown substantially over the past two years. Current threat actor activity is incentivized by…

  • Binance US Delists Cryptocurrency SEC Claimed Is a Security

    Binance’s U.S. subsidiary announced that it will shutter trading for Flexa’s AMP token after the U.S. Securities and Exchange Commission (SEC) identified the asset as security. “We operate in a rapidly evolving industry and our listing and delisting processes are designed to be responsive to market and regulatory developments,” Binance US said in a blog post…

  • Cryptocurrency fraud scheme busted by US securities agency

    US authorities have busted a huge cryptocurrency pyramid scheme, charging 11 people for their role in defrauding retail investors for more than $300m worldwide. The US Securities and Exchange Commission (SEC) announced the charges Monday, which relate to a Ponzi scheme called Forsage that had operated for more than two years. The agency charged the alleged…

  • Hackers drain nearly $200 million from crypto startup in ‘free-for-all’ attack

    Hackers drained almost $200 million in cryptocurrency from Nomad, a tool that lets users swap tokens from one blockchain to another, in yet another attack highlighting weaknesses in the decentralized finance space. Nomad acknowledged the exploit in a tweet late Monday. “We are aware of the incident involving the Nomad token bridge,” the startup said. “We are…

  • Congress Warns of US Court Records System Breach

    Last week, Congress warned the public that the US justice system’s public document management system was compromised in a cyberattack. The news was revealed at a hearing on oversight of the Justice Department on Thursday of last week. Chairman of the House Judiciary Committee Jerold Nadler confirmed that three hostile actors had gained access to…

  • Nigeria adds 10.5 million young voters ahead of 2023 election

    Iver 10 million new voters, most of them young, have been added to Nigeria’s election register ahead of a presidential election next February. In February, a new president will be elected along with members of the Senate, House of representatives and Governors.  The Independent National Electoral Commission ended a year-long exercise on Sunday that had…

  • Al-Qaeda leader killed in US drone strike

    The leader of al-Qaeda, Ayman al-Zawahiri, has been killed in a drone strike in Afghanistan carried out by the United States. The counter-terrorism operation was carried out by the CIA in the Afghan capital of Kabul on Sunday,  Ayman al-Zawahiri plotted the 9/11 attacks with Osama Bin Laden and he was one of America’s most…

  • The IRS Is Working On A New Tax Form To Capture Your Crypto Activity

    The Infrastructure Act passed by the U.S. Congress in 2021 brought cryptocurrency exchanges under the controversial “broker” definition and subjected them to the IRS information reporting regime. As a result, starting January 1, cryptocurrency exchanges will be required to report their customers’ annual cryptocurrency gains and losses to the Internal Revenue Service, similar to stock…

  • Philosophically, It Doesn’t Matter Whether Cryptos Are Securities; Practically, It Does

    I promised Twitter I would write about proof-of-stake and proof-of-work for this newsletter, but my computer (which kept restarting uncontrollably for a couple of days) and my immune system (which gave into a rhinovirus that deposited wet cement into my head) had other ideas. Since a proper proof-of-stake and proof-of-work piece deserves a lot of…

  • Axie Infinity CEO Denies Accusation of Insider Trading

    Trung Nguyen – Co-Founder and CEO of Axie Infinity – said the accusations against him of being engaged in insider trading are “baseless and false.” However, he admitted transferring $3 million worth of AXS to “ensure that short-sellers would not be able to front-run the news.” In March this year, Ronin Bridge – an Ethereum sidechain…

  • The rise of fake cryptocurrency apps and how to avoid them

    Scammers have been taking advantage of blockchain’s decentralized and immutable nature to swindle crypto investors since the advent of the technology. And, according to the latest FBI fraud report, fraudsters are using fake crypto apps to steal money from unsuspecting crypto investors. It highlights that American investors have lost approximately $42.7 million to swindlers through…

  • Nearly 75% of retailers plan to accept cryptocurrency payments within the next 2 years

    From Starbucks to Lamborghinis, consumers are using cryptocurrency to pay for a variety of goods — and retailers are taking notice. Nearly 75% of retailers plan to accept either cryptocurrency or stablecoin payments within the next two years, according to a June survey conducted by Deloitte titled “Merchants getting ready for crypto.” Deloitte polled a sample of…

  • FCC Warns of Rising Robotext Scams

    The Federal Communications Commission (FCC) has reported increases in complaints due to scam robotexts. According to the organization, the amount of scam texts from robocall and robotext blocking services are increasing alongside the scam texts themselves. The FCC tracks consumer complaints, and found that the number of complaints have risen from 5700 in 2019 to…

  • Microsoft warns of stealthy backdoors used to target Exchange Servers

    Microsoft’s Internet Information Service (IIS) web server has reported an uptick in malware native to the server leveraged to install backdoors or steal credentials. Microsoft stated that the malware is hard to detected, meaning that IT teams might have trouble identifying the malicious IIS extensions. The IIS extensions are historically not as popular as web…

  • First grain ship leaves Ukraine under Russia deal

    The first ship carrying grain has left a Ukrainian port since the early days of the Russian invasion. The ship left the southern port of Odesa on Monday morning. The two sides of the war had made a deal recently to resume grain shipments after Ukraine had been blockaded by Russia since February.  This agreement…

  • UN brigade in Congo opened fire at border post, killing two

    On Sunday, soldiers returning from leave to a UN intervention brigade in the Democratic Republic of Congo opened fire at a border post and killed at least two people and injured 15. This is the latest incident involving the peacekeeping mission in Congo, known as MONUSCO, which has come under pressure from days of protests.…

  • Crypto’s nightmare scenario is here

    While Coinbase’s problems with the SEC have flared up just in the past week, they represent the exact scenario that has been keeping crypto executives up at night for far longer. In fact, Coinbase spokeswoman Lisa Johnson told me the company had been working for several months on the lengthy petition it filed with the agency…

  • Solana-based Nirvana loses $3.5M to flash loan exploit; tokens tank 90%

    Solana-based DeFi protocol, Nirvana Finance lost $3.5 million to a flash loan attack on July 28. The attack resulted in Nirvana’s native token ANA losing 85% of its value. The token’s price fell from $8.97 to as low as $0.81 within hours of the attack before rebounding to its current value of $1.26, CoinGecko data revealed. The…

  • Proof of Work vs. Proof of Stake: Ethereum’s Recent Price Surge Shows Why the Difference Matters

    Ethereum’s price surged by more than 40% in mid-July following an announcement by the second-largest blockchain. If you didn’t catch it at the time, you might wonder what kind of announcement has such power to send the price of ethereum surging. It all comes down to the difference between proof of stake and proof of work…

  • Hackers Force a $4B Question: Can DeFi Ever Be Safe?

    Yet another decentralized lending and algorithmic stablecoin protocol was hacked yesterday, with $3.5 million stolen from its treasury via what appears for now to be a one-off exploit. As a result, Nirvana Finance’s NIRV stablecoin lost its peg — it’s at 15 cents as of this writing, and the ANA token used to maintain it…

  • Bitcoin and Ethereum up over 10% amid recession fears

    Bitcoin is trending upward, currently trading at around $23,703. In the last 24 hours, the largest cryptocurrency by market value popped over 10%, according to CoinGecko, reacting positively after the U.S. Federal Reserve raised interest rates on Wednesday. Ethereum is also in the green, up 16% in the same timeframe. Ether (ETH) is currently trading…

  • Impeach President Buhari over Nigeria’s mounting security issues, opposition senators urge

    Ten months before the end of his second term in office, President Muhammad Buhari is being pushed to be impeached by opposition Senators. The Senate minority leader announced on Wednesday that the opposition Senators are pushing for impeachment due to the country’s increasing security issues.  Nigerians will vote in February 2023 for a new president…

  • Spain inflation highest since 1984; new record for eurozone area

    Consumer prices in Spain have risen at the fastest rate since September of 1984. Inflation in the countries using the euro currency has reached a new record. Prices increased 10.8% this month in Spain after increased 10.2% in June. Spain is battling the inflation that has occurred in many countries in Europe due to the…

  • China signals it could miss economic growth target

    China may miss its annual economic growth target due to Covid restrictions weigh on the country’s economy. The ruling Communist Party’s top policy making body, the Politburo, announced on Thursday that it aims to keep economic growth in a reasonable range, however, did not mention the official growth target of 5.5% that had previously been…

  • Russia says 40 Ukrainian prisoners killed in blast

    According to the Russian Defense Ministry, 40 Ukrainian prisoners-of-war were killed when Ukraine shelled a prison in separatist-held Donetsk. In the rocket strike, 75 others were also injured. The strike was on a prison camp in Olenivka.  Ukraine has accused Russia of shelling the prison and claimed that Moscow was hoping to cover up evidence…

  • Mali military says 15 soldiers, three civilians killed in separate ‘terrorist’ attacks

    On Wednesday, Mali suffered from three separate terrorist attacks in which security forces reportedly killed scores of attackers. The attacks targeted towns and military outposts. During the incidents, six soldiers were killed and another 25 were injured. in addition, Malian soldiers killed 48 attackers and destroyed three vehicles containing weapons and ammunition. One of the…

  • Ransomware Group Demands £500,000 From School

    A UK institution in Bedfordshire named the Wooton Upper School has been hit with a ransomware attack in which the attackers demanded over $500,000 in payment. The attack is believed to be the work of the notorious Hive ransomware group. The attack impacted two schools, both of which members of the Wooton Academy Trust. According…

  • European Police Arrest 100 Suspects in BEC Crackdown

    A recent announcement from the European police revealed that the security force conducted two major operations against business email compromise (BEC) fraudsters, leading to the arrests of almost 100 suspects. Although the campaigns were only recently made public, the crackdowns occurred in November of 2021. The police campaigns have been named Operation Wine Cellar and…

  • Google delays removal of third-party cookies in Chrome through 2024

    Google has reportedly delayed its plans to rid Chrome of third-party cookies. The implementation was set to occur in the second half of 2024, according to a blog posted by Google on Wednesday. Google’s reasoning for the delay was that more testing was necessary to improve privacy while giving businesses the tools that they require…

  • Kraken, a U.S. Crypto Exchange, Is Suspected of Violating Sanctions

    Kraken, one of the world’s largest cryptocurrency exchanges, is under federal investigation, suspected of violating U.S. sanctions by allowing users in Iran and elsewhere to buy and sell digital tokens, according to five people affiliated with the company or with knowledge of the inquiry. The Treasury Department’s Office of Foreign Assets Control has been investigating Kraken…

  • Reading the Not-So-Subtle Tea Leaves: What the SEC Is Likely to Do Next in Crypto, and How Crypto Participants Should Prepare

    It is highly likely, and hardly a surprise, that in the near future the U.S. Securities and Exchange Commission (“SEC”) will increase the number of enforcement actions it brings against crypto industry participants. It is widely known in the crypto industry that the SEC’s Division of Enforcement has been investigating a number of high-profile crypto…

  • DeFi Has Become Crypto Crime’s Main Arena, Crystal Blockchain Says

    More than $14.5 billion in crypto has been lost to hacks and scams since 2011, and DeFi (decentralized finance) is attackers’ new favorite target, says analytics firm Crystal Blockchain. In the past 11 years, there have been 167 hacks of DeFi protocols and 123 security breaches on centralized exchanges, according to Crystal’s new report. While…

  • Spree of multimillion dollar hacks creates booming business for blockchain security experts

    Even as cryptocurrency markets face economic turbulence, there’s one segment of blockchain-based industries where business is booming: blockchain security. A boutique industry of auditing firms formed over the past few years to deal with the emerging technology now boasts up to a year-long wait time to even begin working with customers and a growing list of…

  • US Senators Push Bill to Make Small Crypto Transactions Tax-Free

    Prominent U.S. senators are trying to free Americans from tracking taxes every time cryptocurrencies change hands, introducing a bill that would exempt them from reporting any transactions up to $50 or any trade in which they earn less than $50. Sen. Patrick Toomey (R-Pa.) joined with Kyrsten Sinema (D-Ariz.) to push the exemption from tax…

  • Novel Malware Hijacks Facebook Business Accounts

    A recently discovered malware dubbed Ducktail has been linked to Vietnamese threat actors. researchers from WithSecure released a report on Tuesday detailing the campaign in which the attackers use LinkedIn to steal data and admin privileges. The campaign appears to be motivated by financial gain. and has been active since late 2021. The malware uses…

  • Cyber-Criminal Offers 5.4m Twitter Users’ Data

    A seller by the nickname ‘devil’ has created a dark web database containing the personal information of 5.4 Twitter users’ data. The information is listed for sale on a popular criminal forum, according to security researchers. The seller claims to have exploited a vulnerability in Twitter systems reported in January, and Twitter is still investigating…

  • Social Media Accounts Hijacked to Post Indecent Images

    Police in the UK have warned about a surge in social media hacking incidents in which the attackers flood the victims’ accounts with indecent images of children. The shocking campaign does not appear to have any financial motivation behind it, as the victims did not receive a ransom demand. In some instances, the attackers uploaded…

  • Google Chrome security update fixes ‘high risk’ flaws

    The Cybersecurity and Infrastructure Security Agency (CISA) has urged IT administrators and users to implement recent updates released by Google as soon as possible to avoid the risk of an attacker leveraging several flaws that were patched in the update. Google released security updates for the Chrome browser on Mac, Windows, and Linux devices. The…