Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Fei Proposal Not to Make Whole Hack Victims’ A New Low For DeFi’

    Hacks have plagued the cryptocurrency space over the years. Hacks that happen on a protocol are the most devastating because they cause millions of losses for traders. With these hacks, there is always a question of how users will be compensated or how the protocol will recover lost funds. For instance, the Acala stablecoin was hacked…

  • Blockchain Hacks: Can They be Prevented with Smart Contract Audits?

    With the exponential growth of cryptocurrencies, NFTs and other blockchain implementations, there has never been a better time for a cybercriminal to convert a vulnerability into easy and big money. We see two different types of attacks involving cryptocurrencies. One of these is centered around the end user (the victim). The attack technique relies on…

  • Why Is Crypto Giant Tether Risking It All Over North Korea?

    If there’s any lesson crypto companies should have learned from this year so far — a mere eight months that have vaporized some $2 trillion in value — it’s that the world’s continued existence doesn’t depend on them being around. It wasn’t always this way, though. Last year, the U.S. Treasury issued a report on…

  • Illicit crypto activity more resilient than legitimate demand

    Despite the cryptosphere going through a harsh winter the sector maintains its attractiveness to one sector – illicit users. According to Chainalysis’ Mid-year Crypto Crime Update report, criminal activity appears to be more resilient in the face of price declines: Illicit volumes are down just 15% year-on-year, compared to 36% for legitimate volumes. This is…

  • How the Market, Not Government, Regulates Cryptocurrency Crimes

    While policymakers have been busy formulating sweeping changes and regulators have been busy debating jurisdiction, some participants in the cryptocurrency industry have been busy regulating the space themselves. And considering that all too often the word “regulation” follows the word “government,” we shouldn’t be too quick to overlook the fact that the market too is…

  • US Firm Pays $16m to Settle Healthcare Fraud Claims

    Optical lens maker Essilor has entered into a five-year Corporate Integrity Agreement (CIA) with the US Department of Health and Human Service Office of Inspector General and has agreed to pay $16.4 million to settle allegations that the firm payed kickbacks to eye care providers. The Department of Justice claimed that the firm paid optometrists…

  • Israeli diplomat in Turkey expects ambassador appointment “within weeks”

    The re-appointment of an ambassador to Ankara could happen within weeks, according to the Israeli charge d’affaires in Turkey. The official also reiterated that Israel is expecting the Hamas office in Istanbul will be closed down. The appointment of the ambassador may be delayed only because of elections occurring in Israel, but there is hope…

  • UK sees 80-percent energy price hike amid cost-of-living crisis

    The United Kingdom has reported an 80% increase in electricity and gas bills, worsening the cost-of-living crisis the country is already experiencing. The regulator Ofgem announced on Friday that its energy price cap will increase to an average of $4,198 a year from the current $2,331 going into the winter.  Ofgem sets its next cap…

  • 33 million affected by historic rains and floods in Pakistan

    The historic rains and floods in Pakistan have affected over 33 million people according to the country’s climate minister. Over 900 people have died since June in monsoon rains that continue to break climate records. The climate minister referred to the phenomenon as a climate-induced humanitarian disaster.  The nation has since called for international aid.…

  • World narrowly avoided radiation accident – Zelensky

    Europe faced the possibility of a radiation disaster on Thursday after the Zaporizhzhia plant in Ukraine was disconnected from Ukraine’s power grid. The Russian-occupied nuclear plant remained safe after back-up electricity kicked in.  Fires had damaged overhead power lines, cutting the plant off from the power grid. There has been increasing concern over the fighting…

  • Myanmar junta detains former UK ambassador Vicky Bowman

    The United Kingdom’s former ambassador to Myanmar has been detained by the country’s military junta. Vicky Bowman and her husband were taken into custody, according to local media outlets. The military junta has not announced the detentions.  The local media outlets all reported that Bowman could be charged under the country’s Immigration Act. British authorities…

  • UK to ‘fast track’ deportations of Albanian asylum seekers

    The United Kingdom announced new plans to fast track the deportation of Albanian asylum seekers as the government attempts to decrease the surge in people crossing the english channel in small boats. The announcement says that British immigration officers will immediately process asylum claims made by Albanians, and those with no right to remain in…

  • Beware the Crypto Stealers

    While cryptocurrencies have gone from red hot to full on meltdown in recent months, with both retail and institutional investors losing substantial sums amidst the sell-off, threat actors don’t show any signs of shying away from finding new and innovative ways to pursue this lucrative and relatively new financial category with increasingly complex and stealthy…

  • The Gap Between The Crypto Industry And Regulators Has Never Been Wider

    For the past five years, cryptocurrency entrepreneurs have been in fierce disagreement with U.S. regulators over an existential question: whether certain digital assets are securities, or investment contracts that need to be registered with the Securities and Exchange Commission. The stakes are high—if a cryptocurrency is deemed a security in a U.S. court, it basically…

  • NFTs worth $100 million stolen in past year, Elliptic says

    hieves stole over $100 million worth of non-fungible tokens in the year to July, blockchain research firm Elliptic said on Wednesday, as the fast-emerging digital asset became a new front in crypto’s hacking problem. NFTs are blockchain-based assets that represent digital files such as images, video or text. The market surged in 2021 as crypto-rich…

  • An anatomy of crypto-enabled cyber crime

    That is from the synopsis of an interesting new paper by Lin William Cong, Campbell Harvey, Daniel Rabetti and Zong-Yu Wu. It is a fairly comprehensive look at the criminal ecosystem built on top of the cryptocurrency boom, ranging from hacking, money laundering, scams, ransomware, sextortion and illegal commerce. Obviously, the data on these crimes…

  • Tether Stablecoin Brushes Off U.S. Tornado Cash Sanctions

    The company behind Tether, the world’s most popular and widely used stablecoin, wants to have its bitcoin-shaped cake and eat it too. More accurately, it has previously claimed it works with U.S. financial regulators, but at the same time mentioned it doesn’t facilitate U.S. customers, so it doesn’t have to comply with orders. Which is why…

  • India fires three officers for accidentally launching missile into Pakistan

    On Tuesday, the Indian Air Force confirmed that it had fired three officers for accidentally firing a missile into Pakistan in March.. The incident was handled relatively calmly as there were no casualties. The rivals have maintained a tense relationship over the last several years due the disputer territory of Kashmir, fighting three wars and…

  • Firewall Bug Under Active Attack Triggers CISA Warning

    The Cybersecurity and Infrastructure Security Agency has warned that a vulnerability in PAN-OS operated by Palo Alto Networks is under active attack. The agency stated that the flaw needs to be patches as soon as possible. The warning was released to the public and federal IT security teams so that all parties are aware of…

  • US Healthcare Sector Breaches 342m+ Records Since 2009

    According to new research and analysis from Comparitech, healthcare organizations in the US have suffered from almost 5000 publicly recorded data breaches since 2009. The company compiled the data to better understand how severe the security challenges facing the sector really are. The data includes breaches up to June 2022. The largest breaches over that…

  • Fighting resumes in Ethiopia despite truce – Tigray forces

    Fighting has begun between forces from Ethiopia’s northern region of Tigray and central government forces near the town of Kobo. This ends a months-long ceasefire between the two groups. In the past two days there have been large movements of militias and special forces into the area.  The ceasefire had been in place since March…

  • Japan signals return to nuclear power to stabilize energy supply

    Prime Minister of Japan, Fumio Kishida has told the government to consider developing smaller and safer nuclear reactors. This move signals a renewed emphasis on nuclear energy,  years after many of the plants in the country were shut down. Kishida also said the government would look at extending the lifespan of existing reactors in his…

  • Ex-Security Chief Accuses Twitter of Cybersecurity Negligence

    While caught up in a legal battle against Elon Musk, Twitter’s former security chief until January of this year has blown the whistle on how the social media platform handles cybersecurity. The former exec Peiter Zatko has only been off the job for about five months. Zatko accuses Twitter of severe cybersecurity mismanagement in a…

  • Ex-Apple engineer pleads guilty to stealing Apple’s car secrets

    Former Apple employee Xiolang Zhang has plead guilty to stealing trade secrets about Apple’s autonomous vehicle project last Monday in a federal court located in San Jose. Zhang was charged by the FBI in 2018 for allegedly stealing the secrets while preparing to work for Xiaopeng Motors, a Chinese electric vehicle startup. Zhang was arrested…

  • NFT Exchange SudoRare Goes Dark After $820,000 Rug Pull

    After numerous warnings that SudoRare could be a scam did the rounds on Crypto Twitter, the anonymous team behind the decentralized NFT exchange has pulled the rug. The theft has defrauded users of about $820,000 worth of ETH and other crypto tokens. According to on-chain data, the incident occurred early Tuesday, only about six hours after…

  • The SEC Treats Crypto Like the Rest of the Capital Markets

    What do car manufacturers have to do with crypto lending platforms? Consumers and investors deserve protection—that’s true of motor vehicles and investment vehicles alike. In September 1966, President Lyndon B. Johnson signed the National Traffic and Motor Vehicle Safety Act. Nearly six decades later, seat belts and other basic safety features remain standard. That’s true despite…

  • Cybersecurity Companies Are Making Millions From Hacks

    The tragedy of some has been the blessing of others in the crypto space this year. The increase in cybercrime related to the cryptocurrency industry has fueled the work of firms dedicated to evaluating and ensuring the security of companies that trade in crypto. Attacks sponsored by North Korea’s hacker army and other criminals against Western…

  • In Crypto: Google’s $1.5bn cryptocurrency investment

    Google is the world’s biggest backer of cryptocurrency and blockchain companies. The tech giant’s parent company Alphabet invested $1.5 billion into just four crypto startups since September 2021, according to a report from Blockdata. The companies backed were digital asset custody platform Fireblocks, Web3 game company Dapper Labs, Bitcoin infrastructure tool Voltage and venture capital firm Digital…

  • Crypto Exchange Coinbase Faces Class Action Lawsuit Over Alleged Lapses in Security

    Coinbase (COIN) failed to properly secure customers’ accounts, leaving them vulnerable to theft and unauthorized transfers, a putative class action lawsuit filed against the crypto exchange last week alleges. The complaint, filed in the U.S. District Court for the Northern District of Georgia, also accuses the company of causing financial harm to users by locking…

  • Samsung Working on South Korean Crypto Exchange

    Samsung’s securities company and other traditional brokerages plan to launch a crypto exchange next year. Samsung and several others could launch a crypto exchange. According to a report from NewsPim on August 22, seven South Korean securities companies under the Korea Financial Investment Association plan to open a virtual asset company. Those companies began to obtain licenses…

  • Malaysia’s ex-PM starts jail term after final appeal fails

    Najib Razak, Malaysia’s former Prime Minister, has been jailed and will begin serving a 12-year sentence after his appeal was rejected by the top court. The charges surround a corruption scandal involving a state-owned wealth fund, 1Malaysia Development Berhad. He was convicted in July 2020, but had been out on bail during the appeal process. …

  • Ring Camera Recordings Exposed Due to Vulnerability in Android App

    Security researchers at Checkmarx discovered a security vulnerability in Ring surveillance cameras earlier this year. According to the security firm, Amazon has recently published a vulnerability affecting the Android app for the surveillance cameras. The flaw exposed user data as well as video recordings. The app had been installed more than 10 million times from…

  • Kabul mosque explosion kills 21, injures dozens, police say

    In Afghanistan’s capital city of Kabul, an explosion killed 21 individuals praying inside a mosque for evening prayers. The explosion also injured 33 others. Security forces are currently investigating the incident, according to a spokesperson for the Kabul police chief. The health care organization Emergency reported that it treated dozens of the victims of the…

  • Thousands of Indian farmers return to New Delhi in fresh protests

    Massive protests have broken out across New Delhi in a renewed show of opposition against Prime Minister Narendra Modi. The protests began on Monday when thousands of farmers gathered to publicly voice their anger over unfulfilled promises made by the government concerning the population. The protests are occurring eight months after a year-long protest was…

  • Iran blames ‘procrastinating’ US for nuclear deal delays

    Iran has confirmed that it has not received a response from the United States on its latest proposals regarding the 2015 nuclear deal and blamed the US for the inaction. On Monday, foreign ministry spokesman Nasser Kanani said that Iran acted timely and responsibly in the nuclear talks, while the US is procrastinating their response. …

  • Hackers Target ATM Maker for Bitcoins

    General Bytes released a security alert on Friday concerning a zero-day bug detected in its Crypto Application Server (CAS). The Bitcoin ATM company explained how the exploit allowed hackers to steal an undisclosed amount of the digital currency. The advisory states that the attacker was able to create an admin user remotely by exploiting the…

  • CEO of Blacklisted Israeli Spyware Maker NSO Steps Down

    The CEO of Israeli spyware company NSO Group has stepped down, according to an announcement made by the company Sunday. Former CEO Shalev Hulio will be replaced by COO Yaron Shohat, who will manage the company’s reorganization in the aftermath. The company is responsible for the controversial Pegasus spyware due to its usage against activists,…

  • How to protect your crypto hot wallets from hackers

    No one likes to lose their hard-earned money from their cryptocurrency investments, however, some unforeseen events do manage to wipe out investors’ wealth from their trade wallets. One of the popular practices would be hackers luring investors into appealing offers on social media platforms making them look like clickbait in a certain cryptocurrency. Just one…

  • Ronin Hackers Have Moved The Stolen $625M to Bitcoin Network: Report

    Ronin hackers have transferred the stolen assets from Ethereum to the Bitcoin network, according to new findings by blockchain investigator and developer ₿liteZero. Recall that after the Ronin bridge hack in March, the attackers moved the $625 million worth of USDC and ETH to Ethereum-based crypto mixer Tornado Cash, making it difficult for authorities to trace…

  • 8 sneaky crypto scams on Twitter right now

    Cybersecurity analyst Serpent has revealed his picks for the most dastardly crypto and nonfungible token (NFT) scams currently active on Twitter. The analyst, who has 253,400 followers on Twitter, is the founder of artificial intelligence and community-powered crypto threat mitigation system, Sentinel. In a 19-part thread posted on Aug. 21, Serpent outlined how scammers target inexperienced crypto…

  • Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug

    Hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal cryptocurrency from customers. When customers would deposit or purchase cryptocurrency via the ATM, the funds would instead be siphoned off by the hackers. General Bytes is the manufacturer of Bitcoin ATMs that, depending on the product, allow people to purchase or sell…

  • Blockchain and Cryptocurrency CPAs—Evolution of the Profession

    The irony about needing accountants who understand digital assets is that blockchains themselves are transaction ledgers with automated record-keeping—a blockchain is a giant check register. The technical properties of blockchains means data can never be deleted, only added or read, while transactions and balances can be instantly verified with 100% certainty through the protocols themselves.…

  • iPhone Users Urged to Update to Patch 2 Zero-Days

    Apple has urged macOS, iPhone, and iPad users to immediately install updates this week that include security updates for two zero-days that are actively under attack, according to the company. The patches fix vulnerabilities that allow attackers to execute arbitrary code and take over devices. The flaws lie in the kernel and WebKit functions. The…

  • Car Dealership Hit by Major Ransomware Attack

    A UK car dealership has confirmed that it suffered from a serious ransomware attack that occurred last month and resulted in data theft and severe damage to some systems. The company is Holdcroft Motor Group, based in Trent. The organization confirmed the attack in an internal email, stating that the company was recovering from the…

  • Russia blames Ukraine for car explosion that killed Putin ally’s daughter

    A car explosion that killed the daughter of an ally of Russian President Vladimir Putin is being blamed on Ukraine by Russia. Ukraine has denied any involvement in the attack and killing of Daria Dugina. The internal security service in Russia, the FSB, said in a statement that the explosion near Moscow was carried out…

  • China-backed APT41 Group Hacked at Least 13 Victims in 2021

    Advanced persistent threat (APT) group known as APT41, Bronze Atlas, Barium, Double Dragon, and Wicked Panda, has been observed targeting at least 13 organizations spanning several countries during the 2021 calendar year. According to new information from Group-IB, the Chinese threat actor targeted organizations in Taiwan, the US, India, Vietnam, and China. The campaigns have…

  • Spy group abuses Microsoft OneDrive to steal credentials in hack-and-leak campaigns

    Microsoft has warned that a Russian threat actor that is highly persistent is targeting NATO nations with cyberattacks such as credential theft campaigns. The cyberattacks aim to compromise OneDrive accounts, steal data, and then leak selective information in order to sway public opinion and push an agenda. The group is referred to as Seaborgium and…

  • It took Somali forces more than 30 hours to end a hotel attack that killed 21 people

    On Sunday, Somali forces worked to end a deadly attack during which 21 individuals were killed and dozens more injured. The attack occurred when gunmen stormed a hotel in the capital and seized the building. It took Somali forces more than 30 hours to contain the gunmen and during this time civilians trapped in the…

  • Law Commission proposes revolutionary rules for ownership of crypto tokens and NFTs

    There is a major earthquake happening in the sphere of digital assets, which is expected to create shockwaves that will impact tech not only in the real world but also in the metaverse. These potentially revolutionary changes appear in an innocuous-looking, if lengthy, consultation paper titled “Digital Assets: Consultation paper,” published by The Law Commission of…

  • Crypto’s collapse isn’t solving the ransomware problem

    It’s going to take more than a months-long cryptocurrency free fall to squash the mounting ransomware problem, cyber incident responders and threat analysts tell Axios. Why it matters: Companies have been struggling to fight off an abundance of ransomware hackers in recent years, but recent optimism over a crypto-crash-fueled drop in attacks might be short-lived. During a…

  • Celer Network shuts down bridge over potential DNS hijacking

    Interoperability protocol Celer Network has asked its users to revoke the approval for several contracts after shutting down its cBridge over a suspected Domain Name System (DNS) hijacking. According to the project’s initial analysis, there was suspicious DNS activity around 7:00 pm UTC on Wednesday. However, at the time of writing, the platform is still…

  • Infamous Lazarus hacking group targeting Mac users with fake job listings

    Infamous North Korean hacking group Lazarus is attempting to target Apple Inc. Mac users via fake job offers. Detailed Aug. 16 by security researchers at ESET s.r.o on Twitter, the new Lazarus campaign involves phony emails impersonating Coinbase Inc. developer job listings. The fake job emails include an attachment containing malicious files that can compromise both…

  • Is Mainstream Adoption of Cryptocurrencies Imminent?

    On Wednesday, March 9, President Joe Biden released an executive order regarding cryptocurrency and how his administration intends to approach the rapidly growing industry in 2022. However, after the release of this executive order, the question remains: Is mainstream adoption of cryptocurrency imminent in the U.S.? It’s evident that Joe Biden and his administration are…

  • Google Patches Chrome’s Fifth Zero-Day of the Year

    Google has patched an insufficient validation input flaw along with 11 other security vulnerabilities. The flaw allows for arbitrary code execution and is currently under active attack, according to Google. This marks the fifth zero-day vulnerability discovered and subsequently patched in Chrome this year. The patch was released on Wednesday of this week in a…

  • Hackers Deploy Bumblebee Loader to Breach Target Networks

    Threat actors associated with the malwares IcedID, TrickBot, and BazarLoader are increasingly turning to the malware Bumblebee to breach target networks, researchers say. The network breaches are followed by post-exploitation activities that aim to collect sensitive information. On Thursday, Cybereason published an advisory about the malware Bumblebee detailing the nature of the tool and the…

  • ATMZOW JS Sniffer Campaign Linked to Hancitor Malware

    Security researchers at Group-IB have made a connection between the ATMZOW JS Sniffer campaign and the Hancitor malware downloader, claiming that the same malicious actors may be behind both threats. The connection was made earlier this week after analyzing roughly 483 websites spanning four continents that had been successfully infected by ATMZOW since 2019. Group-IB…

  • Indian company to develop Nepal hydropower plant left by China

    Nepal signed a pact with an Indian company to develop a hydroelectric power plant in the west of the country after a Chinese firm backed out years ago. Nepal’s rivers have the potential to generate over 42,000 megawatts of hydroelectric power and they have now been opened to foreign players to develop its economy and…

  • Civilians killed in northern Syria marketplace missile attack

    At least 14 civilians were killed in a rocket attack in the town of al-Bab in northern Syria. Dozens others were injured according to the opposition’s Syrian Civil Defense. The town is held by Turkey-backed opposition fighters and the attack came days after an air attack killed Syrian troops and United States- backed Kurdish fighters…

  • Billionaire Xiao Jianhua jailed for 13 years in China

    A court in Shanghai charged a Chinese-Canadian billionaire, Xiao Jianhua, and his company with embezzlement and bribery. His company, Tomorrow Holdings, was fined over $8 billion and Xiao was sentenced to 13 years in prison.  Xiao and Tomorrow Holdings were found guilty of absorbing public deposits, illegal use of funds, and breaching trust in the…

  • North Korea rejects South’s aid offer, calls President Yoon ‘really simple’

    The state media in North Korea reported on Friday that North Korea has rejected South Korea’s offer of economic support in exchange for denuclearization. Kim Yo Jong, a top official in North Korea criticized the offer. President of South Korea Yoon Suk Yeol has raised the idea of the economic cooperation deal since his inauguration…