Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • TeslaGun Primed to Blast a New Wave of Backdoor Cyberattacks

    New data from an analysis released by Prodraft Threat Intelligence demonstrates how the Evil Corp ransomware gang, also known as TA505 and UNC2165, has expanded its cyber weapon arsenal to include TeslaGun. The cyberattack panel referred to as TeslaGun has been leveraged by the group to help conduct phishing campaigns and ServHelper backdoor campaigns. The…

  • Meta Fined $400m in Ireland For Children’s Privacy Breach

    Ireland’s Data Protection Commission (DPC) has announced that it plans to fine social media platform Instagram $402 million due to mistreatment and mishandling of children’s data. The DPC found that Instagram allowed children to run business accounts that displayed the account holder’s phone number and email address. Therefore, Instagram was effectively exposing the minors’ data.…

  • FBI K-12 Ransomware Warning as LAUSD is Hit

    The FBI has warned that there may be a possible surge in ransomware attacks targeting US schools as they resume classes following the summer break. Over the holiday weekend, the FBI reported that the country’s second largest school district, the Los Angeles Unified School District (LAUSD) was compromised by threat actors. The county serves 600,000…

  • BlackCat Ransomware Linked to Italy’s Energy Services Firm Hack

    Hacking group BlackCat has been linked to recent attacks on Italy’s energy services firm GSE. According to Reuters, the notorious hacking group was behind the attack and threatened to publish if their ransom demands were not met. GSE is a state-owned energy services firm that operates critical infrastructure, making it an attractive target. According to…

  • Authorities Take Down Prolific WT1SHOP Cybercrime Marketplace

    American and Portuguese authorities have reportedly taken down a notorious cybercrime marketplace on which sellers posted troves of stolen personal information that amassed millions of dollars over the years it was active. According to the US Department of Justice, the platform was one of the largest of its kind and offered roughly six million records…

  • UK forces crypto exchanges to report suspected sanction breaches

    Crypto exchanges must report suspected sanctions breaches to UK authorities under new rules brought in amid concerns that bitcoin and other cryptoassets are being used to dodge restrictions imposed in response to Russia’s invasion of Ukraine. Official guidance was updated on 30 August to explicitly include “cryptoassets” among those that must be frozen if sanctions are…

  • Brazilian SEC is looking to change crypto regulation with new bill

    According to reports, the Brazilian Securities and Exchange Commission is looking to switch up the country’s legal framework for cryptocurrencies. The main concern is that the bill in question does not consider tokens as digital assets or securities, which means that it does not fall under SEC regulation. Subsequently, the updated position of the Brazilian…

  • Top 4 Biggest Exploits in August and How They Got Access

    According to one of the most recent reports by a data analysis platform Chainanalysis, vulnerabilities in cross-chain bridge protocols have posed the biggest security threat in the crypto industry; they now represent two-thirds of all hacks. According to a blockchain security firm SlowMist Hacked, users lost around $263 million worth of cryptocurrency to hacks in…

  • Crypto: Stablecoins scramble for safe havens as sanctions threat escalates

    A major stablecoin issuer is formulating an intricate plan to ensure it always remains beyond the reach of centralised authority after US regulators froze USDC (USDC-USD) funds without warning. The US Treasury’s Office of Foreign Assets Control, (OFAC) strong-armed USDC issuer Circle into freezing over 75,000 USDC in the wake of the Tornado Cash affair.…

  • Understanding The ‘Ethereum Merge’

    After many delays, the long-hyped ‘Ethereum Merge’ is about to happen. The first stage of the process – Bellatrix – happens today, 6 September. The second stage – Paris – completes at some point next week. At that point, the way Ethereum – the world’s second largest cryptocurrency behind Bitcoin – fundamentally works will change,…

  • EvilProxy Phishing Toolkit Spotted on Dark Web Forums

    EvilProxy, a new phishing-as-a-service has been identified for sale on dark web forums. The phishing tool is also known as Moloch. Security researchers at Resecurity were the first to identify the malicious tool for sale online. EvilProxy threat actors are reportedly using reverse proxy and cookie injection methods to effectively bypass two factor authentication, according…

  • London’s Biggest Bus Operator Hit by Cyber “Incident”

    London commuters and travelers are bracing themselves for delays after the city’s largest bus operator, Go-Ahead, revealed that it had suffered from a cybersecurity incident. The company is based in Newcastle and released a statement with the London Stock Exchange confirming that it had detected unauthorized activity on its network. Go-Ahead stated that it immediately…

  • SharkBot Malware Resurfaces on Google Play to Steal Users’ Credentials

    The SharkBot mobile malware has been spotted with new upgrades on the Google Play Store, according to the NCC Group. The Fox-IT branch of the NCC Group released a new blog post detailing the malware and the apps it is currently hiding in. According to the report, the new version of SharkBot targets the banking…

  • North Korea supplying Russia with weapons, say US reports

    Due to sanctions that limit Moscow’s ability to supply its military, Russia has been forced to buy military hardware from North Korea. The New York Times obtained declassified intelligence that shows that Russia has bought millions of artillery shells and rockets from North Korea. US officials expect that Russia will be forced to buy additional…

  • Kenya’s top court confirms William Ruto’s victory in presidential vote

    The Supreme Court in Kenya upheld the results declaring William Ruto the winner of last month’s presidential elections. Ruto won with 50.49% of the vote, his rival Raila Odinga received 48.85% of the vote, the Independent Electoral and Boundaries Commission announced in August. Four members of the commission rejected the results, sending the otherwise peaceful…

  • IRS Leaks 120,000 Taxpayers’ Personal Details

    According to recent reports and a letter from the IRS to Congress, the US Internal Revenue Service (IRS) accidentally posted sensitive taxpayer data to its website. This means that those affected could potentially be at risk for further threats, such as identity fraud. The problem with the data leak stemmed from the machine-readable Form 990-T,…

  • Watering Hole Attacks Push ScanBox Keylogger

    Researchers have discovered that a China-based threat actor referred to as APT TA423 has ramped up its efforts to distribute the ScanBox reconnaissance framework to victims. Security researchers identified a watering hole attack that was likely conducted by the malicious hacking group against domestic Australian organizations and offshore energy firms in the South China Sea.…

  • VMware looks to tap growing APAC need for multi-cloud management

    VMware has announced that its next phase of cloud development will focus on multi-cloud management and security. Businesses in the Asia-Pacific are seeking options but have a difficult time coping with the complexities of different platform management. To solve this issue, VMware is looking to step in and aid its customers with a range of…

  • Terror groups may turn to NFTs to raise funds and spread messages: WSJ

    The first known case of a nonfungible token (NFT) created and shared by a “terrorist sympathizer” has come to light, raising concerns that the immutable nature of blockchain tech could help the spread of terrorist messages and propaganda. In a Sunday article in The Wall Street Journal (WSJ), intelligence experts said the NFT could be a…

  • Binance Identifies Suspects Who Stole From KyberSwap Whales

    Binance may have helped crack last week’s $265,000 hack on decentralized exchange (DEX) platform KyberSwap. Binance CEO Changpeng Zhao said on Saturday that his exchange’s security team identified two suspects behind the attack, and that their identities have been forwarded to the KyberSwap team. On Sept. 1, KyberSwap issued an alert to notify users that a hacker…

  • Unraveling How Cybercriminals Extort Businesses Worldwide

    The paper, “An Anatomy of Crypto-Enabled Cybercrimes,” takes a detailed look at how highly sophisticated criminal organizations, mainly based in Russia and North Korea, extort money from corporations worldwide. The majority of these victimized firms are in the United States. “This was actually a difficult decision to do this paper because there’s a substantial probability that…

  • Why are crypto assets important in a divorce proceeding?

    The first decentralized digital currency Bitcoin was first released in 2009, and it has now been 13 years since then. Over the years, crypto assets have gained enormous popularity and are now widely recognized as one of the investment vehicles and payment methods despite its volatile nature. This can be seen from the price of…

  • Hackers Compromise The Youtube Channel of The South Korean Government To Promote a Crypto Scam

    On September 03, the official YouTube channel of the South Korean government was compromised by a group of hackers who used it to promote a cryptocurrency scam with the image of Elon Musk, the electric car tycoon and Dogecoin enthusiast.  According to local media outlet Yonhap News, the hackers changed the name of the government channel…

  • DeFi protocol Kyber Network suffers frontend hack, loses $265K

    Multi-chain DeFi protocol Kyber Network (KNC) revealed that it suffered an exploit on its frontend on Sept. 1, leading to a loss of $265,000 from two whale wallets. According to Kyber Network, its team “identified a malicious code in our Google Tag Manager (GTM)which inserted a false approval, allowing a hacker to transfer users’ funds to…

  • Will Regulations Benefit The Cryptocurrency Market in The Long-Run

    The crypto market exhibits a wide spectrum of opportunities for everyone including investors and regulators. The Crypto market is an ecosystem in itself pertaining to centralized and decentralized financial systems. Decentralized Finance (DeFi) allows market participants to work freely without any hindrance from single-control authorities. Whereas centralized finance is a circle where there is a…

  • This is how North Korean crypto hackers fund their regime

    North Korea has been one of the most active nations behind several of the cryptocurrency hacks taking place over the last year. In mid-August, US-based blockchain analysis company Chainalysis suggested that hackers stole more than $1.9 billion (€1.9 billion) during the first seven months of 2022. Of this total money lost in crypto hacks, the “bad…

  • Domain spoofing on the rise as cybercriminals see some crypto sites as a ‘perfect target’

    The crypto industry has become synonymous with hacks. The blockchain intelligence firm Chainalysis found that criminal hackers stole approximately $3.2 billion in 2021—a 516% increase from 2020. With governments tackling ransomware attacks, hackers are turning to different techniques. A new report from the cybersecurity company Bitdefender found that website spoofing—or attacks where cybercriminals create international domain…

  • Apple Quietly Releases Another Patch for Zero-Day RCE Bug

    Apple has released more updates to patch a remote-code execution flaw that is being actively exploited. The vulnerability was patched earlier this month in newer devices. However, the Wednesday update, iOS 12.5.6 now makes it possible to patch iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod…

  • Ragnar Locker Ransomware Targets Energy Sector, Cybereason Suggests

    Security researchers at Cybereason have released a Threat Analysis Report to highlight the details of an attack that occurred last month against Greece’s largest natural gas supplier, DESFA. The organization stated that it was hit by a cyberattack that impacted some of its systems. Threat actor group Ragnar Locker claimed responsibility for the ransomware attack…

  • New Ransomware Group BianLian Activity Exploding

    A new ransomware group named BianLian that emerged in late 2021 has become increasingly active, according to security researchers. US cybersecurity firm Redacted released a report earlier this week alleging that the threat actor has already compromised twenty victims spanning several industries, including insurance, medicine, law, and engineering. The majority of the group’s targets are…

  • Malicious Google Chrome extensions affect 1.4 million users

    According to a McAfee blog post published on Monday, malicious Google Chrome extensions are affecting more than one million users. Although extensions are popular and have a range of uses, users should be wary of which extensions they are downloading. Some of these downloads are mimicking the appearance of other legitimate extensions and could put…

  • Germany rejects new negotiations over Namibia genocide

    Six years ago, Germany and Namibia entered into negotiations about a formal apology for the colonial-era killings of tens of thousands of the Herero and Nama people. There was a draft agreement in may of 2021, however, neither governments have signed it. The document drew loud criticism from both politicians and the descendants of the…

  • Mosque blast kills at least 18 in Afghanistan

    An explosion at a mosque in Herat in western Afghanistan killed over a dozen civilians and a high-profile pro-Taliban scholar. 23 other people were wounded in the attack. No one has taken responsibility for the attack at the time.  The explosion occurred during Friday noon prayers in the Guzargah Mosque. Taliban spokesman, Zabihullah Mujahid, said…

  • Crucial hours as fuel removed from stricken ship in Gibraltar

    Teams have been rushing to pump fuel off of a grounded ship after it collided with a gas tanker off of Gibraltar and began leaking fuel oil into the sea. There was a significant leak from the OS 35 on Thursday and booms were deployed to prevent the oil spreading. 80% of the ship’s diesel…

  • Myanmar junta sentences ex-British ambassador to one year in prison over immigration charges

    The military junta in Myanmar sentenced former British ambassador Vicky Bowman to one year in prison on Friday. She and her husband were detained in Yangon last month and were accused of violating immigration laws, her husband was also sentenced to one year in prison.  Bowman’s sentencing occurred on the same day that the former…

  • Dozens of Celsius clients ask US court to recover $22.5M in crypto

    The bankrupt cryptocurrency lender Celsius Network is facing more legal issues as disgruntled clients are taking action to recover their funds after the platform froze withdrawals in June. On Wednesday, an ad hoc group of 64 custodial account holders at Celsius filed a complaint with the United States Bankruptcy Court for the Southern District of New…

  • The metaverse and Web3 could fail without identity-first security principles: Here’s how IT leaders can take action

    As the digital world takes over nearly every aspect of our work and personal lives, 2022 continues to be a foundational year for enterprise leaders to prepare their cybersecurity technology stacks for the future. IT leaders should not get lost in the hype, especially since in my experience, many still focus on old computing and security…

  • CEO of collapsed Turkish crypto exchange Thodex faces extradition from Albania following arrest

    Faruk Fatih Özer, CEO of defunct Turkish crypto exchange Thodex, has been apprehended by law enforcement officials in Albania and faces extradition to Turkey, according to a statement from Turkey’s Interior Ministry. Thodex was one of the country’s largest cryptocurrency exchanges before abruptly halting trading in April 2021, causing more than 400,000 users to lose funds.…

  • What is the Ethereum merge and how will it impact the blockchain?

    A big change is set to hit the crypto space, with a long-anticipated upgrade to the Ethereum blockchain. The upgrade, known as the Ethereum merge, will see the blockchain move from its current energy-intensive system to a more environmentally friendly mechanism. The non-profit Ethereum Foundation claims this upgrade will lead to more scalability, security and…

  • U.S. sought records on Binance CEO for crypto money laundering probe

    U.S. federal prosecutors asked Binance, the world’s largest cryptocurrency exchange, to provide extensive internal records about its anti-money laundering checks, along with communications involving its chief executive and founder Changpeng Zhao, according to a late-2020 written request seen by Reuters. The Justice Department’s money laundering section asked Binance to voluntarily hand over messages from Zhao and…

  • UK Imposes Tough New Cybersecurity Rules for Telecom Providers

    The UK’s telecommunications industry is set to introduce new security framework in October. The shift will make the UK’s telecoms security regulations some of the strongest and most thorough in the world. The UK government published a public consultation response earlier this week outlining some of the changes that have been made to the regulations…

  • Microsoft Finds Account Takeover Bug in TikTok

    Security researchers have reportedly identified a high severity vulnerability in the popular social media platform TikTok. The flaw affects the Android version of the app, and could allow attackers to remotely hijack user accounts. Microsoft first reported the vulnerability to TikTok in February 2022. After this exchange, TikTok promptly fixed the issue. The app has…

  • UN, China present opposed reports on Uighurs in Xinjiang

    The United Nations human rights office has released a report after investigating the conditions for the Uighur ethnic minority in China. The report details grave human rights abuse against the Uighurs and other ethnic minorities in Xinjiang and states that the treatment carried out by China may amount to crimes against humanity.  The 45-page report…

  • Major economies accused of ‘backsliding’ on emissions as G20 climate meet ends in failure

    Some of the major economies in the world are “backsliding” on their emissions commitments according to the UK’s climate delegate Alok Sharma on Thursday. The delegate’s comments came a day after the G20 nations failed to adopt a joint communique during a meeting for climate talks.  Th G20 ministerial meeting in Bali was held on…

  • Cosmetics giant Sephora first to be fined for violating California’s Consumer Privacy Act

    Sephora, an international cosmetics giant, has become the first company to be publicly fined for violating California’s relatively new Consumer Privacy Act. The fine was announced in a press release on Wednesday, and California Attorney General Rob Bonta mentioned the settlement. California alleges that Sephora violated the privacy act, resulting in penalties of $1.2 million.…

  • Google’s new bug bounty program targets open-source vulnerabilities

    On Tuesday, tech giant Google announced that it is launching its own bug bounty program that will focus specifically on detecting flaws in open-source software. According to Google, payouts will be anywhere from $100 to upwards of $31,000. The program is titled the Open Source Software Vulnerability Rewards Program. The payout will depend, much like…

  • Bots Represent 40% of the Average Web3 Platform Users

    In a Monday report, blockchain bot detection firm Jigger revealed that a significant portion of Web3 activity is propelled by bots. The report found out that GameFi projects are infected the most, with bots representing over 80% of the user base of some of these games. After a careful inquisition into over 60 blockchain projects in…

  • Crypto.com Sues Woman After Sending Her $10 Million by Mistake

    A woman received $10.5 million in an accidental transaction from popular cryptocurrency platform Crypto.com—and then allegedly spent it on a luxury home, according to reports. Two sisters in Melbourne, Australia, are now being chased by the courts after going on a spending spree with the cash, 7NEWS reported Tuesday. A Crypto.com representative confirmed to Decrypt that the…

  • Ukraine’s National Police Exposes Crypto Cybercrime Group Targeting Europeans

    The National Police of Ukraine (NPU) successfully took down a network of “call centers” on Tuesday that targeted Ukrainian and European Union citizens who had been victims of crypto scams. The fraudulent call center allegedly offered to help those affected by crypto scams as well as recommending investment packages in crypto, gold, oil, and other…

  • Over $1,260,000,000 Stolen From Ethereum-Dominated Crypto Sector in Q1 This Year: FBI

    The U.S. Federal Bureau of Investigation (FBI) says that one popular niche of the cryptocurrency ecosystem has become a prime target for cybercriminals. In a new press release, the agency reports that users of decentralized finance (DeFi) suffered over a billion dollars in losses during the first quarter of this year due to malicious online…

  • Cryptocurrency fraud prevention: House panel calls on regulators to explain how they’re protecting consumers

    A House oversight subcommittee asked regulators and industry leaders on Tuesday to explain what they are doing to stop cryptocurrency fraud and other scams perpetrated on consumers. Illinois Rep. Raja Krishnamoorthi, head of the Economic and Consumer Policy subcommittee, asked leaders of the Treasury Department, Securities and Exchange Commission, Commodity Futures Trading Commission, and Federal Trade…

  • Student Loan Breach Exposes 2.5M Records

    The Oklahoma Student Loan Authority (OSLA) and EdFinancial are currently in the process of notifying roughly 2.5 million loanees that their personal data was exposed in a data breach that targeted Nelnet Servicing. The organization that was targeted provides a servicing system and web portal for OSLA and EdFinancial. Nelnet revealed the breach to loan…

  • ICO Pursues Traffic Accident Data Thieves

    The Information Commissioner’s Office (ICO) has announced that it is launching criminal proceedings against eight individuals who are accused of conspiring to steal personal data. The individuals allegedly planned to target vehicle repair garages to steal data related to hundreds of thousands of individuals involved in road traffic accidents. The ICO stated that the data…

  • Air raid hits capital of Ethiopian Tigray region: Hospital chief

    An air raid has hit a neighborhood near a hospital in the capital of Ethiopia’s Tigray region. This attack occurred less than a week after the four-month-old ceasefire was broken with renewed fighting. The extent of the damage and casualties was unclear.  A spokesman for the Tigray regional government said at least three bombs had…

  • Taiwan fires live rounds at drones near outlying islands

    For the first time, Taiwan has fired warning shots towards drones that have flown over its outlying islands. Taiwan’s defense ministry said that three drones were seen flying back towards the Chinese mainland after the warning shots were fired. ​ Taipei has been complaining in recent weeks of Chinese drones flying near its islets that…

  • Iranian attackers are using Log4Shell to target organizations in Israel

    Microsoft has released a statement warning that a threat actor based in Iran dubbed Mercury is using the well-known Log4Shell flaws that lie in an application created by IT vendor SysAid. The campaign is targeting organization in Israel who are vulnerable to the flaw’s exploit. Microsoft stated with high confidence that the campaign is associated…

  • How will the Tornado Cash sanction affect DeFi?

    On August 8, US Secretary of State Antony Blinken said that the country will endorse Tornado Cash, a decentralized application on the Ethereum blockchain, that allows the anonymous transfer of bitcoin. Due to the reasoning behind it as well as how it was executed, this has angered the crypto community and may be a precursor…

  • DeFi vs. CeFi: Decentralization for the win?

    Centralized finance platforms have taken a huge credibility hit due to poor risk controls, but decentralized finance protocols haven’t escaped unscathed either. So, is DeFi or CeFi likely to emerge stronger from this current period of turmoil, or is the future likely to see some sort of hybrid of the two? In November 2021, Zhu Su,…

  • Crypto developers should work with the SEC to find common ground

    Regulators are tasked with balancing between protecting consumers and creating environments where entrepreneurs and the private sector can thrive. When markets face distortions, perhaps due to an externality or information asymmetry, regulation can play an important role. But regulation can also stifle entrepreneurship and business formation, leaving society and its people worse off. The United States…

  • Security tips to avoid crypto fraud

    The crypto market is ripe with lucrative investment prospects, but fraud and other security flaws continue to plague the sector. Therefore, learning ways to avoid crypto fraud is now imperative. How can you protect yourself from falling victim to cryptocurrency fraud? How do you keep your personal crypto information uncompromised? Investment and trading are two distinct…