Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Deal in sight to end Ukrainian grain blockade – Turkey

    According to Turkey, talks hoping to resume Ukrainian grain exports blocked by Russia in the Black Sea have reached a deal. This deal raises hope for an end in the blockade and standoff on the exports that left millions at a risk of starvation. Both sides have agreed on ways to ensure the safety of…

  • Ukraine’s Cyber Agency Reports Q2 Cyber-Attack Surge

    Ukraine has reported an increase in cyberattacks targeting the country’s systems in the second quarter of the year. Ukraine recently released a report from the country’s State Service of Special Communications and Information Protection describing the increase in cyberattacks. Although attacks have been steadily increasing since Russia’s invasion, the rise in the second quarter of…

  • Large-Scale Phishing Campaign Bypasses MFA

    According to researchers at Microsoft, a massive phishing campaign that can steal credentials despite the implementation of multi-factor authentication has already attempted to compromise more than 10,000 organizations. The adversary-in-the-middle style attack means that the attackers can hijack sign in sessions and access victim mailboxes to launch additional attacks against other targets. The campaign has…

  • These hackers are targeting healthcare records and IT systems with ‘Maui’ ransomware

    The Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, and the Department of the Treasury have released a joint alert about the Maui ransomware. The agencies state that the Windows executable maui.exe is designed for attackers to manually select files to be encrypted. According to the agencies, the unknown ransomware has already targeted the…

  • Snap Will Test Letting Users Showcase NFTs

    Snap is considering a plan to let its members use the app to showcase non-fungible tokens (NFTs), joining the ranks of other social media companies using digital collectibles to woo influencers to their platforms. Snap is readying a test feature that would let NFT artists showcase their designs on Snapchat as augmented reality (AR) filters, the…

  • Buggy ‘Log in With Google’ API Implementation Opens Crypto Wallets to Account Takeover

    A cryptocurrency wallet service provider serving more than 2 million users worldwide and managing about $3 billion worth of Bitcoin was found to contain API vulnerabilities tied to how external authentication logins were implemented. The bugs are fixed, but the discovery illustrates the high stakes involved in implementing APIs securely, researchers say — and the difficulties…

  • Celsius is ‘Deeply Insolvent,’ Alleges Vermont Department of Financial Regulation

    Celsius Network, the troubled crypto lender, “is deeply insolvent,” alleged the U.S. state of Vermont’s Department of Financial Regulation (DFR), noting the lender lacks the assets and liquidity to honor its obligations to account holders and other creditors. “Celsius deployed customer assets in a variety of risky and illiquid investments, trading, and lending activities,” the…

  • Experts Claim Cyber Attacks On Crypto Firms Will Rise, What’s Ahead?

    Regarding cryptocurrency cybercrimes and attacks, North Korea is a notable region with increased activities. Many groups are posing high threats through their attack on some crypto protocols. Also, a report in June disclosed that North Korea has 7 million active hackers. Many stolen funds running into millions of dollars have been traced back to the…

  • Ivory Coast asks Mali to release 49 soldiers arrested in Bamako

    Ivory Coast has asked for the release of 49 of its soldiers who have been arrested in Mali. This incident may worsen tensions between Mali’s military rulers and the other West African nations as other nations work to end activity by armed groups linked to al-Qaeda and ISIL and restore democratic rule in Mali.  The…

  • Thousands trapped by fighting in Haitian capital, aid group warns

    Thousands of haitians are trapped in Port-au-Prince without food, water or essential supply access according to Médecins Sans Frontiéres. The citizens are trapped by the fighting ongoing between rival groups for control over the neighborhood Cité Soleil.  The fighting began for this neighborhood on July 8, blocking the delivery of vital aid and preventing residents…

  • Ransomware Attack Hits French Telecoms Firm

    La Poste Mobile, a French telecommunications operator, has alerted its customers that their data may have been affected by a ransomware attack that occurred earlier this month and targeted the company’s administrative and management systems. The attack took the company’s systems offline as the organization worked to ensure that damage was minimized. A week later,…

  • Popular NFT Marketplace Phished for $540M

    A North Korean advanced persistent threat group has been linked to a cyberattack that occurred in March in which gaming platform Axie Infinity was targeted. According to security researchers, Axie Infinity suffered losses of $540 million after the attackers conducted a spear-phishing attack that allowed them access to in-game non-fungible tokens. A report was published…

  • Binance allegedly continued to serve Iranian customers, despite ban and sanctions

    Global cryptocurrency exchange Binance is under the spotlight as a report claims it continued serving Iranian clients despite a company ban and economic sanctions against the country. According to an investigative report from Reuters, individuals inside the country continued to trade on Binance after the company itself had shifted Iran onto a blacklist of jurisdictions in…

  • Can Decentralized Lending Spread the Wealth Without Centralizing?

    If you took the collateral out of decentralized lending, you’d have something not only potentially useful, but scalable into the real economy. So said the Bank for International Settlement (BIS) in June. The problem is, that requires taking the decentralization of decentralized finance (DeFi), because it would require a trusted intermediary to vet lenders. But the whole…

  • Biggest Security Concerns Around NFTs

    The first known non-fungible token was a short video clip minted on May 3, 2014. Since then, NFTs have grown rapidly from amusing trifles to serious stores of value. In 2021, a work by the artist Beeple sold for a whopping $69.3 million. That was just a portion of the estimated $40 billion valuation of…

  • Cybersecurity Threats in Crypto Exchanges Everyone Should Know

    Cybercriminals have begun coming up with ways to exploit the unexpected rise in value and importance of cryptocurrencies in their hunt for more profitable schemes. Malware that mines cryptocurrencies has become a popular way to earn money and is a viable alternative to ransomware. Cybercriminals have turned to utilize a variety of tools and strategies aimed…

  • Uniswap Under Attack: $8M Lost in ETH as Users Succumb to Phishing

    Uniswap has become the latest victim of a phishing attack, which have become a trademark scheme by crypto hackers in 2022. This time, Uniswap’s V3 liquidity pool (LP) suffered an exploit in which NFT positions worth approximately $8.1 million were illicitly acquired. To trick the pool provider into signing malicious transactions, the hacker group impersonated Uniswap’s…

  • Euro hits US dollar parity for first time in 20 years

    The euro was at a low of $1 as of 10:00 GMT on Tuesday and stock markets fell as potential central bank tightening and concerns about the health of worldwide economies made investors uneasy. The euro is the weakest it’s value has been in over 20 years. The US currency has reached two decade highs…

  • Iran plans to supply Russia with drones, US warns

    The White House National Security Adviser Jake Sullivan has said that the US has received information that suggests Iran may be planning to supply Russia with drones for its war in Ukraine, some with combat capabilities. Information also suggests that Iran is preparing to train Russian forces to use these drones.  It is unclear if…

  • India to surpass China as most populous country in 2023, UN report says

    India is expected to pass China as the most populous country in 2023. Both countries are counting over 1.4 billion residents this year and a United Nations report warned on Monday that high fertility rates may challenge economic growth. The world’s population is estimated to reach 8 billion by mid-November of 2022 could grow to…

  • To stop quantum hackers, the US just chose these four quantum-resistant encryption algorithms

    The US Department of Commerce’s National Institute of Standards and Technology recently announced four quantum-resistant cryptographic algorithms hand selected by the institute to be applied to general encryption and digital signatures. The NIST serves as the US’s standards setting body and research organization within the Department of Commerce. The algorithms have endured a six year…

  • Decentralized Finance: How DeFi Yields Are Generated

    Decentralized finance (DeFi) has ballooned into a booming industry that demonstrates some of the efficient and creative possibilities of the crypto industry. Tens of billions of dollars in crypto assets today are locked in DeFi, a significant increase from 2021. One reason it continues to grow is the appeal of “yield farming,” a strategy that leverages…

  • Cryptocurrency Is Coming to Your Credit Cards

    Cryptocurrencies are a volatile investment today, but card companies including Visa Inc. and Mastercard Inc. are betting crypto will one day be used routinely for everyday purchases from food to clothes to plane tickets—and they don’t want to be left behind when that happens. Consumers now can make payments with cryptocurrencies linked to Visa and…

  • Malicious CuteBoi cryptomining campaign detailed

    Researchers have disclosed what they say could be an attempt to kick-off a new large-scale cryptocurrency mining campaign targeting the NPM JavaScript package repository.  The malicious activity, attributed to a software supply chain threat actor dubbed CuteBoi, involves an array of 1,283 rogue modules that were published in an automated fashion from over 1,000 different…

  • Bitcoin faces Mt. Gox ‘black swan’ as trustee prepares to unlock 150000 BTC

    Bitcoin (BTC) faces a new selling threat in the near future as users of defunct exchange Mt. Gox prepare to get their BTC back. In fresh correspondence dated July 6, attorney Nobuaki Kobayashi, appointed trustee in the Mt. Gox rehabilitation process, confirmed that he was “preparing to make repayments” to account holders. Over eight years after…

  • Here’s how North Korean operatives are trying to infiltrate US crypto firms

    Devin, the founder of a cryptocurrency startup based in San Francisco, woke up one day in February to the most bizarre phone call of his life. The man on the other end, an FBI agent, told Devin that the seemingly legitimate software developer he’d hired the previous summer was a North Korean operative who’d sent tens…

  • Ukraine aims to amass ‘million-strong army’ to recapture south, says defense minister

    Ukraine wants to take back the south of the country from Russia using a million-strong army and Nato weapons, according to the defense minister. The areas around the coast of the Black Sea are vital to Ukraine’s economy.  Russia is making progress in taking territory in the eastern Donbas region, there was an attack on…

  • Sri Lanka President Gotabaya Rajapaksa confirms resignation, PM’s office says

    The Sri Lankan prime minister’s office has confirmed that Sri Lankan President Gotabaya Rajapaksa will resign. Protests over Sri Lanka’s financial crisis have worsened, with tens of thousands of protestors storming the residences of both Sri Lankan President and prime minister. The parliament Speaker has said Rajapaksa will resign on July 13.  Mr Rajapaksa has…

  • Crypto hackers are increasingly phishing for new bait on social media

    As more people enter the web3 ecosystem, there are increasing opportunities for hackers to attack. And during the second quarter, there was a significant rise in crypto-focused phishing attacks across social media sites, according to a new report. There were 290 recorded attacks during the second quarter, up 170% from 106 in the first quarter, according…

  • Navigating Contractual Relationships in the NFT Market

    Participants in the fast-moving – but legally uncertain – non-fungible token (NFT) marketplace can maximize their business opportunities and mitigate risk by delineating their specific role early and clearly defining where their obligations begin and where their responsibilities end. Understanding and defining your role, and the role of your counterparties, is critical. Here are some…

  • Cryptocurrency broker Voyager Digital files for bankruptcy

    Major cryptocurrency broker Voyager Digital Ltd. has filed for bankruptcy protection, becoming the second major company to file during the recent volatility in the crypto market after the collapse of Three Arrows Capital. The company filed for Chapter 11 bankruptcy late Tuesday, a mere week after it suspended withdrawals, deposits and trading on its platform. At…

  • PayPal and Microsoft Adopt Cryptocurrencies: What This Means for the Future

    The recent crypto market crash has sparked a wave of fear, uncertainty and doubt throughout the industry. The crash, which is now being called a stablecoin crash started with the imploded Terra LUNA which lost over 95% of its value in a matter of hours. These developments sparked a marketwide crash that saw Bitcoin hit…

  • Crema hackers retain $1.6M after giving back $8M in protocol

    Crema hacker who exploited Solana’s liquidity protocol on July 2 was allowed to keep $1.6 million in white hat incentives, but he returned most of the money. The 45,455 Solana (SOL) reward is worth around 16.7 percent of Crema’s lost $9.6 million, forcing the protocol to shut down service. The Crema staff began investigating who…

  • Aon Hack Exposed Sensitive Information of 146,000 Customers

    A British multinational financial services firm that boasts a range of risk-mitigation products has announced that it suffered from a large data breach in which information belonging to over 145,000 customers based in North America was exposed. The company reported that its systems were breached at varying times between December 29 2020 and February 26…

  • Apple Announces ‘Lockdown Mode’ to Protect Journalists and Human Rights Workers From Spyware

    On Wednesday, Apple announced a slew of new iPhone security features it calls “Lockdown Mode” aimed to protect journalists and human rights workers from spyware. Lockdown Mode will be available in the fall of this year and offer iPhone users a number of new security features, including blocking message attachment types and disabling link previews.…

  • Google Patches Chrome Zero Day Under Attack

    Google has announced that a new update to the Chrome browser fixed four vulnerabilities. The new version of Chrome will be rolled out to Windows users over the next several days to mitigate the flaws, particularly one zero-day that is being exploited by attackers. The high severity flaw is a heap buffer overflow bug that…

  • No power for up to six hours in South Africa electricity crisis

    South Africa has been experiencing rolling blackouts of up to six hours a day during a bitterly cold winter due to an unreliable power supply in the country. The state-run power company Eskom has been experiencing poor management and corruption which has caused South Africa to experience power cuts for many years, but this will…

  • Germany approves Finland and Sweden NATO membership bid

    The German lawmakers in the Bundestag ratified Sweden and Finland’s accession into NATO on Friday. The move of Sweden and Finland joining NATO must be approved by all 30 members’ parliaments. The Bundestag approved the process following Canada, Estonia, Denmark and Norway.  Finland and Sweden decided to join NATO when Russia’s invasion of Ukraine began.…

  • Hundreds of firefighters battle ‘mega-fire’ in southern France

    Over 900 firefighters have been deployed to a fire in France’s southern Gard region. The firefighters are backed by aircraft and the blaze has burned 600 hectares so far. A senior member of the fire service said there are many hard-to-reach fronts of the fire that are continuing to advance, making the fire far from…

  • Japan’s ex-leader Shinzo Abe assassinated while giving speech

    Former Prime Minister of Japan, Shinzo Abe has been assassinated during a campaign speech in the southern city of Nara in Japan. He was shot in the neck and immediately collapsed and then was rushed to the hospital. The former Prime Minister was 67 years old and was pronounced dead around 5pm local time, five…

  • Brazil could face ‘more severe’ election unrest than the US Capitol riot, official warns

    A senior elections official has warned that Brazil faces possibly dangerous unrest during the country’s presidential vote. The Superior Electoral Court Minister Edson Fachin said there is a risk of unrest more sever than the January 6th insurrection in the United States in 2021.  The elections in October are expected to pit President Jair Bolsonaro…

  • Crypto owners banned from working on US Government crypto policies

    US government officials who privately own cryptocurrencies are now banned from working on regulations and policies that could affect the value of digital assets. A new advisory notice released by the US Office of Government Ethics (OGE) on Tuesday stated that the de minimis exemption — which allows for the owners of securities who hold…

  • Money laundering within DeFi up by 263% says industry study

    Recent analysis of the DeFi sector carried out by CryptoMonday shows that money laundering in the sector has grown by 263% in the first two quarters of 2022. At press time, DeFi protocols have been conduits of up to 69% of funds associated with illicit activity, a significant upsurge from 19% in 2021. “Bad actors…

  • New Lawsuit Alleging That Solana Is A Security Could Have Big Implications For The Crypto Investment Landscape

    A class action lawsuit has been filed against Solana Labs, a for-profit company working on the development of the Solana blockchain, in a California federal court last week accusing the company and people within the ecosystem of making illegal profits and promoting its token, SOL, as an unregistered security. The outcome of the lawsuit could have…

  • How a fake job offer took down the world’s most popular crypto game

    Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector’s biggest hacks. Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to…

  • Don’t Fall for These 8 NFT Scams

    The massive growth of NFT creation, collection and sales in the past few years has led to a growth in NFT scams seeking to separate investors from their cash or cryptocurrency. In 2021, the NFT market grew by 21,000%, with $17.6 billion in sales, according to Fortune. NFTs stored in cold wallets — digital wallets…

  • Marriott Plays Down 20GB Data Breach

    Marriott International’s cybersecurity has come under criticism due to alleged irresponsibility regarding a data breach in which hackers stole 20GB of data from one of the hotel chain’s US locations. The hotel giant claimed that a threat actor was able to socially engineer an employee who worked at the BWI Airport Marriott in Baltimore. The…

  • Hack Allows Drone Takeover Via ‘ExpressLRS’ Protocol

    Security researchers have revealed that a radio control system for drones is vulnerable to remote takeover due to a weakness that lies in the mechanism that connects the transmitter and receiver. According to researchers, the protocol for radio controlled aircraft called ExpressLRS is popular among drone creators. The security vulnerability presents a major issue as…

  • North Korean Hackers Target US Health Providers With ‘Maui’ Ransomware

    The Cybersecurity and Infrastructure Security Agency recently released a new advisory that suggests nation-state threat actors are leveraging the Maui ransomware to target organizations in the healthcare sector. In particular, the government agency believes that the nation-state hacking group is sponsored by the North Korean government. The document explains that intelligence obtained by the CISA,…

  • Brazilian authorities crack down on piracy in the metaverse

    This week, Brazil’s Ministry of Justice and Public Security announced that it conducted its first search within the metaverse with the goal of tackling digital piracy and other related crimes involving the theft of intellectual property. The campaign has been named Operation 404 and is the fourth attempt on the behalf of Brazilian authorities to…

  • 21,000 alleged war crimes being investigated in Ukraine, prosecutor says

    Ukraine has stated it is investigating over 21,000 war crimes and crimes of aggression that have been allegedly committed by Russia since the start of the Kremlin’s invasion of Ukraine. Prosecutor General Iryna Venediktova has been receiving between 200 and 300 war crime reports a day.  Many of the trials will be held in absentia,…

  • UK Prime Minister Boris Johnson resigns after mutiny in his party

    Following a revolt within his Conservative Party, Boris Johnson has resigned as the UK Prime Minister. In an address to the nation, he said the country should begin to find a new prime minister now. He will not leave office until there is a replacement found, however he has appointed a Cabinet to serve alongside…

  • How to Secure NFT Assets

    If there’s any term that can describe the current NFT market, it’s the Wild West. Because the NFT space is still experimental and regulations are unclear or lax, it has attracted a flood of hackers and scammers who are on the hunt for a payday. If you own digital assets or you’re looking to dip…

  • Concerns About 401K Cryptocurrency Plans And Digital Assets

    The future of money and digital assets is a vast topic that presents numerous challenges, and it has even caused debate as to whether cryptocurrency is a prudent retirement plan investment. In its July 1, 2022 In Focus report, the Congressional Research Service nicely summarized the current developments concerning Cryptocurrency in 401(k) Retirement Plans. Of notable…

  • Hackers Stole USD 670M from DeFi Projects in Q2, Up by 50% from Q2 2021

    Hackers and fraudsters stole a total of USD 670.7m from various crypto protocols during the second quarter of the year, according to a report by major bug bounty and security services platform Immunefi. In 50 instances of both successful and semi-successful hacking attempts, decentralized finance (DeFi) projects lost USD 670,698,280 during the last quarter, said the…

  • The Worst Hacks and Breaches of 2022 So Far

    Whether the first six months of 2022 have felt interminable or fleeting—or both—massive hacks, data breaches, digital scams, and ransomware attacks continued apace throughout the first half of this complicated year. With the Covid-19 pandemic, economic instability, geopolitical unrest, and bitter human rights disputes grinding on around the world, cybersecurity vulnerabilities and digital attacks have…

  • Top 7 Automation Takeaways from Automate 2022

    More than 24,000 registered attendees descended upon Detroit earlier this month to see the latest products and innovations around the world of robotics and automation at the Automate 2022 event and trade conference. Visitors spoke with more than 600 companies displaying new solutions in the automation space, or heard from the top leaders in the…

  • Human Error Blamed for Leak of 1 Billion Records of Chinese Citizens

    Earlier this week, a Chinese government developer released a blog post regarding the China Software Developer Network. The post accidentally included the credentials to the system in which the data is stored, leading to a breach and subsequently 23 terabytes of personal data for sale on the dark web. A Chinese tech CEO has cited…

  • Software Supply Chain Attack Hits Thousands of Apps

    Security researchers at ReversingLabs have reportedly uncovered a new supply chain attack impacting software manufacturing that affects thousands of applications and websites. According to the researchers, the software is impacted due to the use of malicious npm packages and modules dating back at least six months. In addition to its investigation, ReversingLabs identified obfuscated Javascript…

  • Advanced Phishing Scams Target Middle East and Impersonate UAE Ministry of Human Resources

    A new campaign impersonating the Ministry of Human Resources of the UAE government has been uncovered by security researchers at CloudSEK. According to the security agency, the campaign is targeting corporate and government entities across several industries, including finance, travel, hospital, legal, oil, and gas. The campaign was identified via an artificial intelligence powered digital…