Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • How We Might Overcome DeFi’s Pitfalls

    Satoshi Nakamoto imagined a trustless, transparent financial system without the need for intermediaries like banks mediating everyday transactions. Nakamoto’s philosophy reached its zenith with the emergence of smart contracts and decentralized finance (DeFi). The DeFi sector grew significantly, and its total volume locked (TVL) surpassed $250 billion in 2021. Despite turbulent market conditions, DeFi’s TVL hovered…

  • NSA: Sanctions on Russia Having a Positive Effect on Ransomware Attacks, Attempts Down Due to Difficulty Collecting Ransom Payments

    National Security Agency (NSA) director of cybersecurity Rob Joyce told attendees of a recent UK security conference that ransomware attacks are down in roughly the last two months, and that trend can be traced directly to sanctions placed on Russia. Criminals that operate out of the country are struggling to find ways to cash out…

  • What Leaders Need To Know About Blockchain

    If you’re anywhere near the tech or financial space, you’ve likely been hearing terms like DeFi, blockchain, and smart contracts more and more frequently. Ever since cryptocurrencies and other decentralized technologies came on the scene, they’ve been the subject of much speculation and debate among engineers and business leaders. Some tech thinkers suggest that blockchain is…

  • India’s SpiceJet Strands Planes After Being Hit By Ransomware Attack

    SpiceJet, an India-based airline, was forced to delay numerous flights on Wednesday after being hit by a ransomware attack that occurred on Tuesday. The company released a post to Twitter confirming that its operations had been impacted by the cybersecurity incident. On Thursday, morning flight departures were still suffering from the effects of the cyberattack,…

  • Cybergang Claims REvil is Back, Executes DDoS Attacks

    According to researchers at Akamai, actors claiming to be the REvil ransomware group is targeting one of its customers with a Layer 7 attack. The group has also demanded an extortion payment in Bitcoin from Akami’s client. The defunct REvil ransomware gang went dark in July 2021 after several law enforcement operations agains cybercrime syndicates.…

  • Latest DRC violence has displaced more than 72,000 people

    The eastern Democratic Republic of the Congo has seen fighting between the army and M23 rebels this past week. The conflict in this week alone has forced over 72,000 people to flee their homes, according to the United Nations.  The rebels, M23, claim to represent ethnic Tutsis in the region of the eastern DRC and…

  • China and Russia veto new UN sanctions on North Korea for first time since 2006

    In a move that was referred to as dangerous and disappointing, Russia and China vetoed a United Nations Security council resolution to increase sanctions on North Korea that was drafted by the United States. The vote is concerning because it could fuel Pyongyang’s nuclear program to develop nuclear missile systems.  North Korea has completed more…

  • Critical Flaws in Popular ICS Platform Can Trigger RCE

    Cisco Talos has reportedly uncovered eight vulnerabilities in the Open Automation Software, a popular industrial control system (ICS) platform. Two of the flaws are categorized as critical, meaning that they pose a risk for infrastructure networks and should be addressed immediately. Exploiting the flaws could lead to remote code execution or denial of service and…

  • Ed tech wrongfully tracked school children during pandemic says Human Rights Watch

    According to Human Rights Watch (HRW), students who were required to use government-endorsed education technology, also referred to as ed tech, during the Covid-19 pandemic may have been subject to a variety of harmful cyber practices, such as keystroke monitoring and data collection. In addition, the HRW alleges that the data collected from the students’…

  • A lesson from the Ukraine war: Secure our semiconductor supply chains

    There are many lessons emerging from Russia’s invasion of Ukraine, and others yet to be discerned. One insight that the war has reinforced concerns the tremendous strategic value of semiconductors. These tiny silicon chips offer a huge warfighting advantage for the Ukrainians — but also should remind the United States of the urgent need to…

  • Everything You Need to Know About Crypto Insurance

    Cryptocurrency is the most exciting and unpredictable financial frontier in today’s world. The opportunities for crypto-based businesses are enormous, but so are the attendant risks. Protecting you from these downfalls is what crypto insurance is all about. Although it will safeguard your business from cybercriminals, it will also give your customers valuable peace of mind.…

  • ‘More Systemic Risk’—The Stablecoin Fallout Could Be Just Starting As The Price Of Bitcoin, Ethereum, Terra’s Luna, Solana, Cardano, XRP Sink

    The crypto market is covered in red again. This week the price of bitcoin price fell 2.4% and Ethereum’s price is down 5.0%. Cardano ADA fell 9.8%, XRP XRP lost 6.14%, and Solana slumped 12.4%. Meanwhile, the price of BNB BNB rose 7.4%. The waters are still murky after the mid-month roiling of the crypto…

  • Could quantum computing bring down Bitcoin and end the age of crypto?

    Quantum computers will eventually break much of today’s encryption, and that includes the signing algorithm of Bitcoin and other cryptocurrencies. Approximately one-quarter of the Bitcoin ($168bn) in circulation in 2022 is vulnerable to quantum attack, according to a study by Deloitte. Cybersecurity specialist Itan Barmes led the vulnerability study of the Bitcoin blockchain. He found the…

  • Sen. Gary Peters Issues Report on Use of Cryptocurrency in Ransomware Attacks

    Sen. Gary Peters, D-Mich., chairman of the Senate Homeland Security and Governmental Affairs Committee, has released a report saying the federal government lacks sufficient information on ransomware attacks and the use of cryptocurrency in ransom payments. The report also found that current reporting of such attacks is fragmented across federal agencies and that lack of comprehensive…

  • U.S. Cybersecurity Agency ‘Strongly Urges’ You Patch These 75 Actively Exploited Flaws

    The US Cybersecurity and Infrastructure Security Agency (CISA) has identified 75 security vulnerabilities that pose a significant risk to its list of flaws that should be patched immediately. All of the vulnerabilities are known to be actively exploited, heightening the risk of an attack. For organizations, there are risks of attack exposure from the vulnerabilities…

  • Multi-Continental Operation Leads to Arrest of Cybercrime Gang Leader

    Interpol has announced that the organization was able to track down and apprehend the suspected leader of a transnational cybercrime syndicate. The 37-year-old individual was arrested in Nigeria and is believed to have lead major phishing campaigns, business email compromise schemes, and other malicious behavior that targeted companies and individuals. The operation was conducted by…

  • World Bank boss warns over global recession due to Ukraine War: What To Do About it

    There were already multiple reports of slowing economies due to Covid then the war in Ukraine caused more disruption. Here is an overview of a world bank view by BBC: The head of the World Bank has warned that the increase in price of food, energy, and fertilizer as a result of Russia’s invasion of…

  • Google Chrome 102 arrives with 32 security fixes, one critical

    Google has released a new version of Chrome, Chrome 102, that contains 32 security fixes applying to Windows, Mac, and Linux devices. The vulnerabilities were allegedly reported to Google by external researchers and consist of one critical flaw, eight high severity, nine medium severity, and seven low severity. In addition to these flaws, Google has…

  • China plays for influence in South Pacific with security proposal and diplomatic tour

    China has proposed a regional security deal with some Pacific Island nations. This move is occurring amid United States concern about Beijing expanding its reach in the region. The draft calls for an increase in cooperation in policing, cybersecurity, security, and economic development.  The deal is expected to be discussed at the China-Pacific Island Countries…

  • IBM Develops AI-Powered z16 to Help Thwart Quantum Cyber Attacks

    On April 5, IBM unveiled IBM z16, the company’s next-generation system with an integrated on-chip artificial intelligence (AI) accelerator to deliver latency-optimized inferencing. With this innovation, clients will be able to analyze real-time transactions at scale. IBM z16 is even more valuable for mission-critical workloads such as credit card, health care and financial transactions. Inference is…

  • Do Kwon’s plan to rebirth the Terra blockchain gets approved

    The governance vote on Do Kwon’s proposal to relaunch the Terra blockchain and create LUNA 2.0 tokens has passed. This will result in the creation of a new blockchain that will airdrop tokens proportionally to those affected, following the sudden collapse of the TerraUSD (UST) algorithmic stablecoin. In total, 65.5% of the total votes supported Kwon’s…

  • How to build an economically viable, inclusive and safe metaverse

    During the COVID-19 pandemic, an increasing number of people have relied on media and technology to inform, entertain and educate themselves, do business, and socialize. But the shift in usage patterns does not automatically mean that everyone understands what the metaverse is. Fewer than one in five (16%) of Americans can define the term: some…

  • OECD releases public consultation document on crypto tax reporting in effort to increase transparency

    The Organisation for Economic Co-operation and Development (OECD) has released a public consultation document, Crypto-Asset Reporting Framework and Amendments to the Common Reporting Standard. The document responds to a request from the G20 to develop a framework to assist in the automatic exchange of information related to cryptoassets, arising from concerns about the rapid adoption…

  • Crypto Hacks Aren’t a Niche Concern; They Impact Wider Society

    The attack against the Ronin Network in March was quickly speculated to be one of the largest cryptocurrency hacks of all time. Approximately $540 million was stolen from the cryptocurrency and NFT games company in a combination of USDC and Etherium, with $400 million of the stolen funds owned by customers playing the game Axie…

  • JPMorgan Says Bitcoin Is Undervalued By 28%, Says Cryptocurrencies Are Now A ‘Preferred Alternative Asset’

    Despite the crypto slump, banking giant JPMorgan says bitcoin is massively undervalued. Maintaining its estimate of bitcoin’s fair value at $38,000, the bank today reiterated the assessment it gave the asset in February when the cryptocurrency was trading around $43,400. This price is approximately 28% higher than its current level of $29,757. In a note to…

  • Iran Used Secret U.N. Records to Evade Nuclear Probes

    A new report alleges that Iran secured access to secret UN atomic agency reports and used them to evade nuclear probes by circulating the documents among top officials, who were then able to prepare cover stories and falsify records. Middle East Intelligence officials and documents reviewed by the Wall Street Journal support the theory that…

  • Four missing miners found dead in Burkina Faso

    Four missing miners in Burkina Faso have been found dead, according to the country’s government officials. After 39 days of intense search on behalf of rescue workers in the region, the bodies of the miners were recovered. The individuals went missing after floodwaters filled a Canadian-owned mine in Perkoa. Perkoa is located in the Sanguie…

  • Senate Report says US Government Lacks Comprehensive Data on Ransomware

    According to a new Senate report by the US Senate Committee on Homeland Security and Governmental Affairs, the US lacks comprehensive data regarding ransomware attacks. This includes details such as financial losses both in ransom payments and to companies while suffering from the attack and attempting to remedy the effects. The report presented findings that…

  • North Korea fires missiles hours after Biden leaves Asia

    Three ballistic missiles were fired by North Korea early Wednesday morning according to South Korea’s military. The three missiles were fired in the  course of an hour from the Sunan area in Pyongyang. The incident occurred only one day after US President Joe Biden left the region after vowing to deter North Korea.  North Korea…

  • Fronton IOT Botnet Packs Disinformation Punch

    Cybersecurity researchers claim that the Fronton botnet boasts a far larger arsenal of abilities than just launching a DDoS attack. Researchers allege that the botnet can track social media trends and launch suitable propaganda in addition to its cyberattack skills. A new look at the botnet reveals that the criminal tool may have been using…

  • At least five killed after a building collapses in Iran, leaving 80 people trapped

    When a 10-story building collapsed in the city of Abadan in the Iranian province of Khuzestan on Monday, 27 people were injured and five people were killed.80 people remain trapped under the rubble of the collapsed building according to the Red Crescent. The cause of the collapse is under investigation and the owner of the…

  • Zoom patches XMPP vulnerability chain that could lead to remote code execution

    Zoom users have been advised to update their software to the latest version, 5.10.0, to fix a number of flaws detected by Google Project Zero researchers. According to the researcher who discovered the holes, Ivan Fratric, user interaction is not required for an attacker to successfully leverage the flaws. The only ability the attacher needs…

  • Conti Ransomware Operation Shut Down After Brand Becomes Toxic

    The Conti ransomware operation has undergone some significant organizational structure changes in the past months after the brand became toxic due to its affiliation with the Russian government. The Conti operation has been highly successful, helping cybercriminals make billions of dollars after breaching the systems of hundreds of major organizations. While it appeared to be very…

  • Whistleblower claims DoKwon, Kanav Kariya and Sam Bankman-Fried were involved in Terra’s LUNA and UST collapse

    Whistleblowers from the Terra community have made allegations that some of the most prominent figures in the cryptocurrency industry, like FTX CEO Samuel Bankman-Fried and Jump Crypto CEO Kanav Kariya, were responsible for TerraUSD’s (UST) colossal crash and de-peg. Whistleblowers in the Terra community have come forward with details of an insider deal that destroyed stablecoin…

  • These are the flaws that let hackers attack blockchain and DeFi projects

    The number of decentralized finance (DeFi) and blockchain projects grew massively during the past year, but their increased popularity has also piqued the interest of cyberattackers – who managed to steal at least an estimated $1.8 billion in 2021. The blockchain is a digital ledger that records transactions in a way that is difficult to…

  • The Great Reassessment: The Supply Chain Edition

    The logistics landscape is changing. Like the employment market in the pandemic, the need to unexpectedly adjust creates the opportunity to re-think. Sometimes the change is tactical – a reversible reaction – and things return to normal. Other times it leads to be a more structural change. Anticipating the forward shape of the supply chain means…

  • 6 Things You Need To Know About Crypto

    Despite being around for roughly 13 years and currently in the midst of a market crash, crypto feels like it’s still in a goldrush phase. As hopeful investors pile in with dreams of making big money, many still lack any real knowledge about what they’re getting into. A survey by software developer Oxford Risk last year…

  • US Car Giant General Motors Hit by Cyber-Attack Exposing Car Owners’ Personal Info

    General Motors, a US based automobile manufacturer, has announced that it suffered from a credential stuffing attack last month that ultimately exposed customer information. In addition, the attack allowed hackers to redeem rewards points and gain gift cards. General Motors stated that they detected the malicious activity between April 11 and 29 of this year,…

  • DR Congo military accused of shelling civilians in Rwanda

    Rwanda’s military has accused forces from the Democratic Republic of the Congo of cross-border shelling and wounding several civilians. Regional monitors have been asked to investigate as the shelling struck areas in Musanze district Monday morning.  The Expanded Joint Verification Mechanism is a group of military experts from the International Conference on the Great Lakes…

  • New phishing technique lures users with fake chatbot

    Trustwave has released a new report in which the company provides details regarding an emerging phishing technique through which attackers aim to steal credit card data from internet users. The initial contact method for the phishing scam is via email, like the majority of phishing campaigns. In particular, this campaign impersonates shipping company DHL and…

  • Turkey’s Erdogan says he will no longer talk to Greek PM

    Turkish President Recep Tayyip Erdogan has accused the Greek Prime Minister Kyriakos Mitsotakis of antagonizing Turkey and has said he will stop talking to the Greek leader as a result. The Turkish President also said he would cancel a meeting between the two countries after he said Mitsotakis recommended to US officials to not seel…

  • Executions spiked in Iran in Saudi Arabia in 2021

    Amnesty International says there was a concerning rise in executions in 2021 as Covid-19 restrictions were lifted. There were spikes seen in Iran and Saudi Arabia in the year of 2021. At least 579 executions were carried out in 18 countries, reflecting a 20% increase to 2020 and Iran accounted for 314 of these executions.…

  • Credit card skimmers are switching techniques to hide their attacks

    Microsoft has reported that card-skimming malware that aim to steal bank card details are increasingly turning towards utilizing malicious PHP script on web servers to manipulate payment pages. This enables the attacker to bypass browser defenses triggered by JavaScript code. Microsoft says that its researchers have observed the shift in tactics to Magecart malware that…

  • Crypto needs rules to rein in volatility

    Have we just seen a cryptocurrency meltdown or just another blip in a highly-volatile global coin market in urgent need of a regulatory reboot? Over $500 billion (£400bn) of crypto value was wiped out in less than a fortnight resembling the dot-com boom of 20 years ago. And we all know what happened then. At…

  • Multiple NFT Projects Attacked After Commonly-Used “Mee6” Discord Bot Hacked

    A Discord bot widely used by NFT projects, most notably the very popular (and very recently breached) game Axie Infinity, was compromised leading to scam messages being passed to users. A hack of the “Mee6” bot used to moderate Discord channels led to scam messages being passed in these communities, with the hackers posing as…

  • Broadcom, VMware deal could be announced by Thursday, sources say

    CNBC’s David Faber reported Monday that Broadcom had been gearing up to announce its acquisition of VMware as soon as Thursday, but the news could come sooner after several reports said the two companies were in talks. Some material terms still need to be finalized, and a deal could fall through, Faber said on CNBC’s “Squawk…

  • Bill Gates Explains Why He Doesn’t Own Any Cryptocurrency

    Microsoft cofounder Bill Gates isn’t a fan of cryptocurrency. Gates, now fourth-richest person in the world with a net worth of $125 billion, said during a Thursday Ask Me Anything exchange on Reddit that he doesn’t own any digital currency. “I like investing in things that have valuable output. The value of companies is based on how…

  • CIOs Stress Supply Chains, Efficiency as Recession Risks Rise

    Amid threats of recession, chief information officers say they are prioritizing technology that drives efficiency, mitigates ongoing supply-chain struggles and contributes quickly to the bottom line. Tech leaders at Walgreens Boots Alliance Inc., Carhartt Inc. and other companies say they are monitoring a number of factors, including the financial markets, inflation and supply-chain uncertainties as they…

  • U.N. Human Rights Chief Kicks Off Closely Watched China Trip

    This weekend, the United Nations High Commissioner for Human Rights Michelle Bachelet begun a six-day visit to China to investigate alleged violations of human rights. Bachelet’s visit will be closely monitored by Western officials and rights activists worried that China could somehow meddle in her findings and hide violations in the treatment of Muslims in…

  • Iran vows revenge after Revolutionary Guards colonel is assassinated

    Following a deadly attack against a high ranking official in the Islamic Revolution Guard Corps (IRGC), Iran’s President has promised to take revenge. Colonel Sayad Khodai was killed on Sunday in Tehran while he was sitting in his car outside of his home. Iranian officials reported that two gunmen on motorbikes opened fire at the…

  • Ransomware Hackers Steal Personal Data of 500,000 Students and Staff in Chicago

    According to Chicago Public Schools, more than half a million students and staff had their personal information leaked in a ransomware attack that occurred last December. However, the breach was not reported until April. The district stated that a vendor Battelle for Kids notified the school system of the breach in late April after a…

  • DoJ Says White Hat Hackers Will No Longer Face Prosecution

    The US Department of Justice (DoJ) recently announced that it will not prosecute “good faith” hackers in a historic policy shift. Up until this point, even white hat hackers could be prosecuted under the Computer Fraud and Abuse Act (CFAA), even when done to improve cybersecurity. The DoJ identified good-faith hacking as accessing devices solely…

  • Germany is keen to pursue gas projects with Senegal, says Scholz on first African tour

    Chancellor Olaf Scholz of Germany said the country wants to pursue gas and renewable energy projects with Senegal. The Chancellor announced this on Sunday during his frist trip to Africa as the war in Ukraine has created rising energy and food prices. The three-day tour began in Senegal, which has billions of cubic meters of…

  • Russian assault on key Donbas city intensifies

    Russia has been intensifying attacks in eastern Ukraine as they attempt to secure the Donbas region. Severodonetsk is the largest city under Ukraine rule in the Luhansk province and it has come under heavy artillery and missile fire from Moscow’s troops. Officials said on Sunday, Russian troops were repelled after trying to enter the city…

  • Pro-Russian Hackers Hit Critical Government Websites in Italy

    According to Italy’s Postal Police, pro-Russian hackers have launched a campaign targeting the websites of Italian institutions and government ministries. The cyberattacks were confirmed by law enforcement on Friday and are believed to have begun Thursday evening. Roughly 50 different institutions reported suspicious activity or cyberattacks, including the superior council of the judiciary, the customs…

  • Explosive DeFi: Where we are and where we’re heading

    The entire cryptocurrency space continues to evolve rapidly, having surpassed $3 trillion market capitalization for the first time in 2021. Further, global blockchain spending has surged 7 times over the past four years to an estimated $6.6 billion in 2021, and is projected to more than triple by 2024. That’s impressive given the seeds of…

  • Bitcoin Miners Face Shrinking Profitability Amid Crypto Crash

    As bitcoin enters a new bear market, the mining sector is feeling the pain. Specifically, miners are seeing their profit margins dwindle as Bitcoin’s price falls and Bitcoin’s mining difficulty continues to rise. Bitcoin mining revenue potential, defined as its hashprice, has fallen some 68% from its 2021 peak and 58% from 2021’s average. Two things…

  • Collapse of Luna cryptocurrency leads to $11 million exploit on Venus Protocol

    Venus Protocol, a decentralized money market, announced on Thursday evening that about $11 million had been lost due to people exploiting the historic collapse of the Luna cryptocurrency and its sister stablecoin UST. The team behind the Venus Protocol released a statement confirming suspicions that had been floating around for hours about the potential mishandling of…

  • Cyberattacks quietly launched by Russia before its invasion of Ukraine may have been more damaging than intended

    Russia is known for its potent cyber-warfare capabilities. So it is no surprise that Moscow launched cyberattacks against Ukrainian targets in the lead up to its invasion in late February. Russian hackers went after a variety of Ukrainian targets in the private and public sectors, but one cyber weapon aimed at a specific military target…

  • 380K Kubernetes API Servers Exposed to Public Internet

    According to the Shadowserver Foundation, who first discovered the security incident, more than 380,000 of 450,000 Kubernetes servers hosting the open-source container-orchestration engine for managing cloud deployments are vulnerable to third party access. The popular engine for managing cloud deployments is therefore an easy target, providing a broad attack surface for threat actors. The exposed…