Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Chinese Influence Op Tries to Undermine Western Rare Earth Firms

    Security firm Mandiant claims to have discovered a new Chinese influence operation that is allegedly targeting Western rare earth producers. The campaign, named Dragonbridge, has been operating since 2019 and leverages thousands of inauthentic accounts spread across numerous social media platforms to achieve its goals of promoting Chinese interests abroad. Mandiant warns that the campaign…

  • Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug

    Russian-linked persistent threat group Fancy Bear has been identified as the actor behind a recent phishing campaign that uses nuclear war as a lure in messages to entice targets into clicking a link that exploits a one-click Microsoft flaw. The ultimate goal is to steal credentials from the Chrome, Edge, and Firefox browsers. The attacks…

  • Nigeria sells marginal oilfield licenses for $482m, ignores court

    Nigeria has made over 200 billion naira, which is equivalent to $482 million from the issuance of oil prospecting licenses. It offered 57 oil fields for bidding according to the petroleum regulator. The NUPRC, The Nigerian Upstream Petroleum Regulatory Commision, said that over two thirds of the awardees have fully paid for their licenses two…

  • 7 million in Bangladesh need aid after ‘worst floods in memory,’ Red Cross says

    Over 7 million people in Bangladesh need shelter and emergency relief after some of the worst flooding to hit South Asia in living memory. The floods have caused hundreds of thousands of homes near the Bangladesh border with India to be underwater and in some areas, entire neighborhoods are submerged.  At least 207 people in…

  • De-Centralized Autonomous Organization (DAO) For Cryptocurrency Alleged To Be A General Partnership In Sarcuni

    A number of folks got together to create a business that would take advantage of a crypocurrency protocol known as bZx that was supposed to be super-duper secure, or, as they put it, no depositor of cryptocurrency should “ever worry about … getting hacked or [anyone] stealing [their] funds.” Of course, that’s exactly what happened:…

  • The latest trends in hacker attacks and how to deal with them

    As the DeFi sector continues to attract money and users, bad actors from around the world continue to view it as an attractive target that is ripe for the picking and poorly protected. Over the last several months, I have been keeping track of some of the most notable exploits of DeFi protocols, and at least…

  • Are we helpless against attacks on blockchain bridges?

    The past few years have plagued the decentralized finance (DeFi) space with hacks, making critics of blockchain technology take a closer look at how this technology is threatening security. This year started off with a US$600 million hack on Axie Infinity’s Ronin sidechain, followed by a US$325 million attack on Solana’s Wormhole, both of which…

  • Bitcoin is the only coin the SEC Chair will call a commodity

    Monday morning, the chairman of the U.S. Securities and Exchange Commission (SEC), Gary Gensler, said on CNBC’s Squawk Box that the only token he would lump in with commodities was bitcoin. Why it matters: Gensler pointedly declined to name any cryptocurrency other than the original one, notable because the market has been operating under the assumption…

  • What is a Cryptocurrency Crime, and How Does it Affect Trading

    Cryptocurrency crime is as sinister and upsetting as most financial crimes. The crimes that are perpetrated range from ordinary theft of cryptocurrency to money laundering and market to market fraud. Investors and consumers are subject to phishing and scams, where they are instructed to send cryptocurrency to a specific location for ransom. Like all financial…

  • Pro-Russian Hacker Group Killnet Hits Critical Government Websites in Lithuania

    Security researchers have discovered a video message published by a group of Russia-affiliated hackers known as Killnet that was posted to the group’s Telegram channel. In the video, the group takes responsibility for targeting and attacking several Lithuanian government websites last week. The video confirms that the attacks were a response to sanctions imposed on…

  • Chinese Researchers Find Critical Security Flaws in CoDeSys Automation Software

    According to an advisory by Chinese cybersecurity firm NSFOCUS, its researchers have detected 11 security vulnerabilities that lie in the CoDeSys automation software that could lead to unauthorized access to company resources or denial-of-service attacks. The researchers claim that the bugs are simple to exploit and can have severe consequences, ranging from information leakage to…

  • Rival Libyan officials hold UN-led election talks in Switzerland

    Two days of talks about constitutional arrangements for elections have begun with two senior Libyan officials. This is the latest effort by the United Nations to close the gaps between the country’s rivals. The two leaders Aguila Saleh, the speaker of the country’s east-based parliament and Khaled al-Meshri, head of the government’s High Council of…

  • US watchdog is worried cyber insurance won’t cover ‘catastrophic cyberattacks’

    The US Government Accountability Office (GAO) has warned that catastrophic cyberattacks are not receiving an adequate federal response, especially in that the cyber-insurance industry falls short when it comes to certain types of major attacks. The government spending watchdog warns that although the cyber-insurance market has risen and matured over the past few years, it…

  • Non-essential petrol sales halted for two weeks in Sri Lanka

    Fuel for nonessential vehicles has been suspended in Sri Lanka as the country faces its worst economic crisis in decades. Only buses, trains and vehicles for hospital services will be allowed to use fuel for the next two weeks. Urban schools have shut and the country’s 22 million residents have been told to work from…

  • Machine NFTs: Income security in the age of automation

    The dark side of automation was once a figment of science fiction, where fears of intelligent machines taking over the world ran wild. Now, there’s a very real sense that intelligent machines pose a real threat to humankind — or at least a real threat to humankind’s earning potential. In 2021, McKinsey estimated that one-quarter of…

  • Opaque Platforms and Intertwined Protocols Pose Big Risk to Crypto

    We’re still firmly in Hard Times. Sure, my article last week about price and macro risk was published just before an eight-hour flurry when bitcoin gained 6.35%, but both hazards remain salient. This article is the second in a three-part series about the risks facing cryptocurrency markets right now. Next week we’ll look at public…

  • Managing risk in blockchain deployments

    Trail of Bits has released an operational risk assessment report on blockchain technology. As more businesses consider the innovative advantages of blockchains and, more generally, distributed ledger technologies (DLT), executives must decide whether and how to adopt them. Organizations adopting these systems must understand and mitigate the risks associated with operating a blockchain service organization,…

  • Goldman Sachs Leading Investor Group to Buy Celsius Assets: Sources

    Goldman Sachs is looking to raise $2 billion from investors to buy up distressed assets from troubled crypto lender Celsius, according to two people familiar with the matter. The proposed deal would allow investors to buy up Celsius’ assets at potentially big discounts in the event of a bankruptcy filing, the people said. Goldman Sachs…

  • Crypto Security: Protect Your Coins and NFTs From Being Stolen

    With crypto prices in free fall, crypto firms laying off thousands of workers and coins that are considered “stable” losing all their value, it’s more important than ever to secure your remaining portfolio. The current crypto crash isn’t the only way people are losing their money. There have been an increasing number of scams that give…

  • At least 4 dead, hundreds injured after collapse at stadium in Colombia

    Hundreds of people were injured and at least four people were killed after a partof a stadium in El Espinal in Colombia collapsed on Sunday. The stadium is located in Colombia’s western state of Tolima and collapsed during a bullfight.  Citizens were called to evacuate during the tragedy and authorities responded to the scene with…

  • AU expresses ‘deep shock’ over deaths at Spain-Morocco border

    Nearly two dozen people died while trying to break through a border fence between Morocco and Melilla, a Spanish enclave. The African Union expressed its shock about the tragedy and called for an immediate investigation. The chairman of the African Union Commission condemned the “degrading treatment of African Migrants.”  The violence at the attempted border…

  • MetaMask Crypto-Wallet Theft Skates Past Microsoft 365 Security

    Researchers have uncovered an email-based credential-phishing attack targeting users of MetaMask, a cryptocurrency wallet used to interact with the Ethereum blockchain. The campaign is directed at Microsoft 365 (formerly Microsoft Office 365) users and has targeted multiple organizations across the financial industry. It starts with a socially engineered email that looks like a MetaMask verification email,…

  • Time for Crypto to Make Nice With Regulators

    If you still think cryptocurrency can thrive best within the ambiguous, ill-defined, geographically varied and relatively lax regulatory system, you haven’t been paying attention. With the spectacular failures of TerraForm Labs’ LUNA/UST and Celsius, the systemic fallout from the liquidity challenges at Three Arrows Capital and the erasure of almost $2 trillion in value from…

  • On the Dangers of Cryptocurrencies and the Uselessness of Blockchain

    Earlier this month, I and others wrote a letter to Congress, basically saying that cryptocurrencies are a complete and total disaster, and urging them to regulate the space. Nothing in that letter is out of the ordinary, and is in line with what I wrote about blockchain in 2019. In response, Matthew Green has written—not…

  • Axie Infinity’s Ronin Bridge to Re-Open After $552M Hack

    Sky Mavis, the developer behind the play-to-earn video game Axie Infinity said that it’s preparing to re-open the Ronin bridge that fell victim to a $552 million hack in March. The re-opening of the Ronin bridge, which was used by players to transfer assets between the Ronin chain and the Ethereum network, is planned on…

  • Breaking: Harmony’s Horizon Bridge hacked for $100M

    The Horizon Bridge to the Harmony layer-1 blockchain has been exploited for $100 million in altcoins which are being swapped for Ether (ETH). The hack may vindicate previously raised community concerns about the robustness of the two of four multisig that reportedly secures the bridge. Starting at about 7:08 am EST until 7:26 am EST, 11 transactions…

  • Google details commercial spyware that targets both Android and iOS devices

    Google has warned its customers that an enterprise grade spyware strain is targeting both Android and iOS mobile device users in a recent Google Threat Analysis Group announcement. The spyware variant is reportedly in active circulation, according to the security team. Google has thus far identified victims in Italy and Kazakhstan. The spyware has been…

  • Yodel blames cyber incident for disruption and parcel-tracking problems

    Delivery company Yodel stated that technical issues have disrupted its deliveries and services. The company has confirmed that they are working to resolve the disruptions that were caused by a cyber incident. Yodel also confirmed that as soon as they detected the cyber incident, an investigation was launched by internal IT teams and external forensics…

  • Jordan’s King Backs ‘Middle East NATO’ With a Defined Mission

    Jordan’s King Abdullah has announced his support for an alliance of the Middle East countries similar to that of NATO. Jordan is a major US ally and both countries have been looking to defend against Iranian attacks that have hit gulf oil exporters. As a result of the pressure on the US to counter against…

  • Tunisian ex-PM Jebali arrested on suspicion of money laundering

    Former Prime Minister Hamadi Jebali of Tunisia has been arrested by Tunisian police on suspicion of money laundering. The phones of Jebali and his wife were seized and he was taken to an unknown location on Thursday. The arrest has raised opposition concerns over the human rights situation since President Kais Saied dissolved parliament last…

  • Protests force South Africa’s Eskom to widen power cuts

    In South Africa, state power company Eskom announced it may have to widen power cuts this weekend as labor protests disrupt operations. The company has been struggling to meet the demand for power in South Africa for over a decade. Eskom has been implementing rotational outages since the beginning of the week and will increase…

  • Ukrainian forces told to retreat from key eastern city

    Severodonetsk is Russia’s focus of the invasion and Ukrainian forces have been ordered to withdraw. Russian forces have almost completely encircled the city in recent days and have also begun targeting its twin city Lysychansk. Ukrainian troops have been ordered to retreat to new positions and continue their operations from there.  Severodonetsk’s infrastructure is completely…

  • Cryptocurrency Custody Concerns: Who Holds the Digital Storage Keys?

    Got Crypto? Make sure you own and have access to it in a secure digital stronghold. Having self-custody of your crypto keys and managing your digital assets can help stave off digital bankruptcy or loss through theft, warns cryptocurrency storage provider CompoSecure. Cryptocurrency is an increasingly familiar term since Bitcoin emerged in 2009. Since then, numerous cryptocurrencies…

  • NFT, DeFi and crypto hacks abound — Here’s how to double up on wallet security

    The explosiveness and high dollar value of nonfungible tokens (NFTs) seem to either distract investors from upping their operational security to avoid exploits, or hackers are simply following the money and using very complex strategies to exploit collectors’ wallets. At least, this was the case for me way back when after I fell for a classic…

  • Chainalysis introduces the Crypto Incident Response programme

    Chainalysis has launched Crypto Incident Response, a rapid response service for organisations that have been targeted by a cyber-attack or unauthorised network intrusion that involves a cryptocurrency theft or demand. The growth in the legitimate use of cryptocurrency is far outpacing the growth of criminal usage, with transactions involving illicit addresses representing just 0.15% of cryptocurrency…

  • Web3 Wallets Targeted by Chinese Hackers; “SeaFlower” Using Cloned Websites to Trick Crypto Traders

    A hacking group out of China has been identified using a rather low-tech yet effective way to steal money from Web3 wallets: distributing altered versions that have holes programmed into them. The Chinese hackers cloned the distribution sites of legitimate wallets, tricking users into downloading a compromised version. Researchers with digital advertising security firm Confiant…

  • Commonwealth countries set to meet in Rwanda and what to expect

    The heads of government from Commonwealth countries will meet in Kigali, the capital of Rwanda on Friday and Saturday. The government heads are meeting to tackle challenges including climate change and food shortages caused by the war in Ukraine.  The commonwealth is a voluntary association of 54 countries that evolved from the British Empire. The…

  • Germany takes step closer to gas rationing

    Germany has triggered the “alarm” stage of an emergency gas plan after a drop in supplies from Russia. The shortages in gas supplies have lead the country to move closer and closer to gas rationing. Germany’s economy minister Robert Habeck said Russia is using gas as a weapon to retaliate against EU sanctions. He referred…

  • Watertight Blockchain Bridge Security Critical for Cross-Chain Interoperability

    Trustless blockchain bridges will play an important role in cross-chain interoperability and in reducing the risk of hacks in the blockchain industry. This problem was brought to the fore earlier this year with a couple of major attacks on blockchain bridges—the $320 million hack on the Solana Wormhole bridge in February and the theft of…

  • How to keep your NFTs safe from scammers

    According to Wikipedia, the first known non fungible token (NFT) was created in 2014 and the first NFT project was launched in late 2015. It took a few more years and more projects for the concept to trickle into the consciousness of the general public, and then a few more for the massive investments into…

  • Congress can do better than the Howey test for crypto regulation

    Cryptocurrencies are generally not subject to federal regulation unless they are deemed to be “securities,” in which case the Securities Act of 1933 requires them to abide by disclosure requirements and antifraud regulation by the Securities and Exchange Commission (SEC) if they are offered to the public. The test the SEC uses to determine whether a…

  • To infinity and back: Inside Axie’s disastrous year

    At 1 a.m. on March 29, Jiho Zirlin, a co-founder of the Vietnamese crypto gaming company Sky Mavis, received a text from his fellow co-founder Aleksander Larsen. Zirlin, who is also the company’s head of growth, was in Los Angeles at the time, winding down for the night at his Airbnb. He was scheduled to…

  • ‘Decentralization Proves To Be an Illusion,’ BIS Says

    The recent Terra LUNA collapse and Celsius’ restrictions on withdrawals have sparked fears of a crisis in crypto lending. Economists at the Bank of International Settlements (BIS) said while on-chain collateral in DeFi lending overcomes asymmetric information, it doesn’t make the space immune from boom-bust episodes, compounded by liquidation spirals. Cryptocurrency lending platforms — where borrowers…

  • New Toddycat APT Targets MS Exchange Servers in Europe and Asia

    Researchers at Kaspersky have identified a new advanced persistent threat dubbed ToddyCat that is actively targeting Microsoft exchange servers in Europe and Asia. The threat actor is leveraging two tools that were formerly unknown to the security researchers who discovered the threat actor, referred to as Samurai backdoor and Ninja Trojan respectively. Kaspersky stated that…

  • 56 Vulnerabilities Discovered in OT Products From 10 Different Vendors

    Multiple sources have confirmed the discovery of a total of 56 vulnerabilities in OT products from 10 vendors, including popular companies Honeywell, Siemens, and Emerson. According to security researchers, most of the vulnerabilities are due to a lack of basic security mechanisms such as authentication and encryption. In addition, researchers believe that asset owners continue…

  • Phishing gang that stole millions by luring victims to fake bank websites is broken up by police

    Europol has busted a phishing and fraud ring that was reportedly responsible for the theft of several millions of euros being stolen from victims. The perpetrators engaged in illicit activities such as scams, fraud, money laundering, and phishing to achieve their financial goals. Europol has also confirmed that some of the members of the group…

  • Russia warns Lithuania of consequences over rail transit blockade

    Lithuania has been warned by Russia of serious consequences after it banned railroad transfer of goods to the Russian territory of Kaliningrad. Lithuania stated it is following the EU sanctions imposed on Russia over its invasion of Ukraine.  Kaliningrad doesn’t share a border with mainland Russia and is where Russia’s Baltic Fleet is headquartered. It…

  • More than 900 people killed after magnitude 5.9 earthquake hits eastern Afghanistan

    Over 900 people were killed and hundreds were wounded in a 5.9 magnitude earthquake that hit eastern Afghanistan Wednesday. The earthquake hit at 1:24a.m. local time and the epicenter was about 46km southwest of the city of Khost.  The quake only registered at a depth of 10 kilometers, which indicates a relatively localized impact. The…

  • Application security in cryptocurrency ecosystem

    You can often hear from me and my colleagues security engineers about the defense in depth approach to protecting the user data. Does this mean putting as many tools and security controls in your code or system as the whole market suggests? By no means. When speaking about defence in depth we mean that carefully…

  • Crypto Workers Behind Terra and Luna Are Facing a Flight Ban in South Korea

    The ongoing crypto crash has brought a lot of investors back down to earth. In the case of current and former Terraform Labs employees, it’s keeping them literally grounded. Dozens of past and present staff from the company behind two notorious crypto coins, terraUSD and Luna, have been barred from leaving South Korea, according to multiple…

  • Cloudflare outage hit crypto exchanges FTX, Bitfinex and more

    A Cloudflare outage on Tuesday knocked out numerous popular web services, including major crypto exchanges FTX, Bitfinex, and OKX, raising questions about the security of centralized crypto platforms. The CEO of OKX, which saw $1.47 billion in trading volume in the past 24 hours, tweeted asking for “web3 alternative in the future” after the company’s website…

  • Job Security a Growing Concern as Crypto Layoffs Continue

    One day after cryptocurrency firm BlockFi moved to lay off 20% of its staff, over a thousand Coinbase employees woke up to find their workplace access cut and an email informing them they were part of the 18% of staff let go due to tough industry conditions. “Although I understand that difficult decisions have to be…

  • Cryptocurrency tech is vulnerable to tampering, a DARPA analysis finds

    Whether prices are up or down, for many investors in cryptocurrency, the real appeal is that there’s nobody in charge. As the crowd chanted at the recent Bitcoin 2022 conference in Miami, it’s all about “Freedom!” By design, the system is meant to be from interference by banks, companies and governments. But a new report…

  • Kazakh Govt. Used Spyware Against Protesters

    Security company Lookout published a report last week detailing how a Kazakhstan government entity used spyware developed by Italian company RCS Lab against protestors. The government entity leveraged the enterprise grade spyware against domestic targets via brand impersonation that tricked recipients into clicking on malicious links. The spyware used has been dubbed Hermit and is…

  • Google Chrome Extensions Could Be Used to Track Users Online

    According to evidence created by a web developer known as ‘z0ccc,’ some Google Chrome extensions could be used to track users online. The developer created a website that is designed to generate a fingerprint of devices based on Google Chrome extensions installed on the browser that is visiting in order to prove his claims. The…

  • 1.5 million customers impacted by Flagstar Bank data breach

    Bleeping Computer has reported that a security incident impacting Flagstar Bank has led to the exposure of personal data belonging to roughly 1.5 million customers. The security incident reportedly occurred when an unauthorized third party gained access to the bank’s network. The security breach occurred between December 3 and December 4 of last year, according…

  • Microsoft Addresses Wi-Fi Hotspots Issues in Latest Update

    Microsoft has addressed a known issue that is currently affecting Wi-Fi hotspot features in its systems. The vulnerability has been added to its official Health Dashboard page as of this week after the company discovered that Windows 10 and 11 machines are subject to the bug. It is likely that the bug was introduced through…

  • At least 200 civilians killed in western Ethiopia, say reports and officials

    Possibly more than 200 civilians have been killed in the Oromia region of Ethiopia by the rebel group the Oromo Liberation Army on Saturday. A police officer reported that most of the victims were ethnic Amharas.  The attack was on the town of Gimbi and was connected to fighting between government forces and the OLA.…

  • South Korea launches homegrown Nuri rocket carrying satellites into orbit

    Satellites were successfully launched into orbit by South Korea on Tuesday with its homegrown Nuri rocket. This is a large step for the country’s space program after a failed launch attempt last year where the dummy satellite launched failed to reach low Earth orbit due to the third-stage engine shutting down. The three-stage rocket weighed…

  • Inverse Finance exploited again for $1.2M in flash loan oracle attack

    Just two months after losing $15.6 million in a price oracle manipulation exploit, Inverse Finance has again been hit with a flash loan exploit that saw the attackers make off with $1.26 million in Tether (USDT) and Wrapped Bitcoin (wBTC). Inverse Finance is an Ethereum-based decentralized finance (DeFi) protocol and a flash loan is a type…