Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • DDoS Attacks Pepper Taiwanese Government Sites

    According to the foreign ministry of Taiwan, the websites of the ministry and presidential office were hit by multiple distributed denial of service (DDoS) attacks, resulting in intermittent outages across several government websites. The attacks occurred after the arrival of senior US lawmaker Nancy Pelosi. The visit has angered Beijing, which claims Taiwan as its…

  • 7 password-stealing Android apps removed from Google Play

    Security researchers at Trend Micro reported that seventeen malicious apps designed to infect Android users have been removed from the Google Play Store. The apps used banking malware and have been dubbed DawDropper. The malware campaign leverages four types of banking trojans, Octo, TeaBot, Hydra, and Ermac. The attack type has been described as a…

  • Malicious Npm Packages Tapped Again to Target Discord Users

    Security researchers at Kaspersky recently uncovered a LofyLife campaign that steals tokens and infects client files, allowing them to monitor certain user actions such as logins, password changes, and payment methods. The campaign targets Discord users via the node package manager (NPM) repository. In addition to the aforementioned capabilities, the attacker can also steal information…

  • Bangladesh turns to ADB, World Bank for funds

    The government of Bangladesh has sought assistance from both the World Bank and Asian Development Bank to increase its foreign exchange reserves. The government wrote letters to both entities requesting $1 billion to help the economy. The economy in Bangladesh has been struggling since the effects of the war in Ukraine along with energy price…

  • US warns of possible retaliation over al-Qaeda death

    The United States government has urged its citizens to be vigilant against anti-American violence abroad after the al-Qaeda leader Ayman al-Zawahiri was killed. His death could prompt supporters of al-Qaeda or other terror groups to target US personnel and facilities according to the state department.  The state department gave a worldwide caution update after the…

  • North Korean fraudsters suspected of copying people’s LinkedIn and Indeed profiles in a bid to land jobs at U.S. crypto firms

    North Korean hackers are raiding job sites like LinkedIn and Indeed and stealing tidbits of information from real profiles to build plagiarized resumes and land jobs at U.S. cryptocurrency firms, according to security analysts. Security researchers at Mandiant Inc. told Bloomberg that fraudsters were attempting to secure employment at these companies as part of a bigger…

  • Threat Actors Merging Malicious Activity With Cryptocurrency Show How the Attack Landscape is Developing in Decentralized Finance

    Widespread implementation of decentralized finance (DeFi) systems since 2020 has created new fertile ground for a variety of threat actors to shift the development of cyberattack tactics, techniques, and procedures (TTPs). The number of threat actors participating in DeFi activity has grown substantially over the past two years. Current threat actor activity is incentivized by…

  • Binance US Delists Cryptocurrency SEC Claimed Is a Security

    Binance’s U.S. subsidiary announced that it will shutter trading for Flexa’s AMP token after the U.S. Securities and Exchange Commission (SEC) identified the asset as security. “We operate in a rapidly evolving industry and our listing and delisting processes are designed to be responsive to market and regulatory developments,” Binance US said in a blog post…

  • Cryptocurrency fraud scheme busted by US securities agency

    US authorities have busted a huge cryptocurrency pyramid scheme, charging 11 people for their role in defrauding retail investors for more than $300m worldwide. The US Securities and Exchange Commission (SEC) announced the charges Monday, which relate to a Ponzi scheme called Forsage that had operated for more than two years. The agency charged the alleged…

  • Hackers drain nearly $200 million from crypto startup in ‘free-for-all’ attack

    Hackers drained almost $200 million in cryptocurrency from Nomad, a tool that lets users swap tokens from one blockchain to another, in yet another attack highlighting weaknesses in the decentralized finance space. Nomad acknowledged the exploit in a tweet late Monday. “We are aware of the incident involving the Nomad token bridge,” the startup said. “We are…

  • Congress Warns of US Court Records System Breach

    Last week, Congress warned the public that the US justice system’s public document management system was compromised in a cyberattack. The news was revealed at a hearing on oversight of the Justice Department on Thursday of last week. Chairman of the House Judiciary Committee Jerold Nadler confirmed that three hostile actors had gained access to…

  • Nigeria adds 10.5 million young voters ahead of 2023 election

    Iver 10 million new voters, most of them young, have been added to Nigeria’s election register ahead of a presidential election next February. In February, a new president will be elected along with members of the Senate, House of representatives and Governors.  The Independent National Electoral Commission ended a year-long exercise on Sunday that had…

  • Al-Qaeda leader killed in US drone strike

    The leader of al-Qaeda, Ayman al-Zawahiri, has been killed in a drone strike in Afghanistan carried out by the United States. The counter-terrorism operation was carried out by the CIA in the Afghan capital of Kabul on Sunday,  Ayman al-Zawahiri plotted the 9/11 attacks with Osama Bin Laden and he was one of America’s most…

  • The IRS Is Working On A New Tax Form To Capture Your Crypto Activity

    The Infrastructure Act passed by the U.S. Congress in 2021 brought cryptocurrency exchanges under the controversial “broker” definition and subjected them to the IRS information reporting regime. As a result, starting January 1, cryptocurrency exchanges will be required to report their customers’ annual cryptocurrency gains and losses to the Internal Revenue Service, similar to stock…

  • Philosophically, It Doesn’t Matter Whether Cryptos Are Securities; Practically, It Does

    I promised Twitter I would write about proof-of-stake and proof-of-work for this newsletter, but my computer (which kept restarting uncontrollably for a couple of days) and my immune system (which gave into a rhinovirus that deposited wet cement into my head) had other ideas. Since a proper proof-of-stake and proof-of-work piece deserves a lot of…

  • Axie Infinity CEO Denies Accusation of Insider Trading

    Trung Nguyen – Co-Founder and CEO of Axie Infinity – said the accusations against him of being engaged in insider trading are “baseless and false.” However, he admitted transferring $3 million worth of AXS to “ensure that short-sellers would not be able to front-run the news.” In March this year, Ronin Bridge – an Ethereum sidechain…

  • The rise of fake cryptocurrency apps and how to avoid them

    Scammers have been taking advantage of blockchain’s decentralized and immutable nature to swindle crypto investors since the advent of the technology. And, according to the latest FBI fraud report, fraudsters are using fake crypto apps to steal money from unsuspecting crypto investors. It highlights that American investors have lost approximately $42.7 million to swindlers through…

  • Nearly 75% of retailers plan to accept cryptocurrency payments within the next 2 years

    From Starbucks to Lamborghinis, consumers are using cryptocurrency to pay for a variety of goods — and retailers are taking notice. Nearly 75% of retailers plan to accept either cryptocurrency or stablecoin payments within the next two years, according to a June survey conducted by Deloitte titled “Merchants getting ready for crypto.” Deloitte polled a sample of…

  • FCC Warns of Rising Robotext Scams

    The Federal Communications Commission (FCC) has reported increases in complaints due to scam robotexts. According to the organization, the amount of scam texts from robocall and robotext blocking services are increasing alongside the scam texts themselves. The FCC tracks consumer complaints, and found that the number of complaints have risen from 5700 in 2019 to…

  • Microsoft warns of stealthy backdoors used to target Exchange Servers

    Microsoft’s Internet Information Service (IIS) web server has reported an uptick in malware native to the server leveraged to install backdoors or steal credentials. Microsoft stated that the malware is hard to detected, meaning that IT teams might have trouble identifying the malicious IIS extensions. The IIS extensions are historically not as popular as web…

  • First grain ship leaves Ukraine under Russia deal

    The first ship carrying grain has left a Ukrainian port since the early days of the Russian invasion. The ship left the southern port of Odesa on Monday morning. The two sides of the war had made a deal recently to resume grain shipments after Ukraine had been blockaded by Russia since February.  This agreement…

  • UN brigade in Congo opened fire at border post, killing two

    On Sunday, soldiers returning from leave to a UN intervention brigade in the Democratic Republic of Congo opened fire at a border post and killed at least two people and injured 15. This is the latest incident involving the peacekeeping mission in Congo, known as MONUSCO, which has come under pressure from days of protests.…

  • Crypto’s nightmare scenario is here

    While Coinbase’s problems with the SEC have flared up just in the past week, they represent the exact scenario that has been keeping crypto executives up at night for far longer. In fact, Coinbase spokeswoman Lisa Johnson told me the company had been working for several months on the lengthy petition it filed with the agency…

  • Solana-based Nirvana loses $3.5M to flash loan exploit; tokens tank 90%

    Solana-based DeFi protocol, Nirvana Finance lost $3.5 million to a flash loan attack on July 28. The attack resulted in Nirvana’s native token ANA losing 85% of its value. The token’s price fell from $8.97 to as low as $0.81 within hours of the attack before rebounding to its current value of $1.26, CoinGecko data revealed. The…

  • Proof of Work vs. Proof of Stake: Ethereum’s Recent Price Surge Shows Why the Difference Matters

    Ethereum’s price surged by more than 40% in mid-July following an announcement by the second-largest blockchain. If you didn’t catch it at the time, you might wonder what kind of announcement has such power to send the price of ethereum surging. It all comes down to the difference between proof of stake and proof of work…

  • Hackers Force a $4B Question: Can DeFi Ever Be Safe?

    Yet another decentralized lending and algorithmic stablecoin protocol was hacked yesterday, with $3.5 million stolen from its treasury via what appears for now to be a one-off exploit. As a result, Nirvana Finance’s NIRV stablecoin lost its peg — it’s at 15 cents as of this writing, and the ANA token used to maintain it…

  • Bitcoin and Ethereum up over 10% amid recession fears

    Bitcoin is trending upward, currently trading at around $23,703. In the last 24 hours, the largest cryptocurrency by market value popped over 10%, according to CoinGecko, reacting positively after the U.S. Federal Reserve raised interest rates on Wednesday. Ethereum is also in the green, up 16% in the same timeframe. Ether (ETH) is currently trading…

  • Impeach President Buhari over Nigeria’s mounting security issues, opposition senators urge

    Ten months before the end of his second term in office, President Muhammad Buhari is being pushed to be impeached by opposition Senators. The Senate minority leader announced on Wednesday that the opposition Senators are pushing for impeachment due to the country’s increasing security issues.  Nigerians will vote in February 2023 for a new president…

  • Spain inflation highest since 1984; new record for eurozone area

    Consumer prices in Spain have risen at the fastest rate since September of 1984. Inflation in the countries using the euro currency has reached a new record. Prices increased 10.8% this month in Spain after increased 10.2% in June. Spain is battling the inflation that has occurred in many countries in Europe due to the…

  • China signals it could miss economic growth target

    China may miss its annual economic growth target due to Covid restrictions weigh on the country’s economy. The ruling Communist Party’s top policy making body, the Politburo, announced on Thursday that it aims to keep economic growth in a reasonable range, however, did not mention the official growth target of 5.5% that had previously been…

  • Russia says 40 Ukrainian prisoners killed in blast

    According to the Russian Defense Ministry, 40 Ukrainian prisoners-of-war were killed when Ukraine shelled a prison in separatist-held Donetsk. In the rocket strike, 75 others were also injured. The strike was on a prison camp in Olenivka.  Ukraine has accused Russia of shelling the prison and claimed that Moscow was hoping to cover up evidence…

  • Mali military says 15 soldiers, three civilians killed in separate ‘terrorist’ attacks

    On Wednesday, Mali suffered from three separate terrorist attacks in which security forces reportedly killed scores of attackers. The attacks targeted towns and military outposts. During the incidents, six soldiers were killed and another 25 were injured. in addition, Malian soldiers killed 48 attackers and destroyed three vehicles containing weapons and ammunition. One of the…

  • Ransomware Group Demands £500,000 From School

    A UK institution in Bedfordshire named the Wooton Upper School has been hit with a ransomware attack in which the attackers demanded over $500,000 in payment. The attack is believed to be the work of the notorious Hive ransomware group. The attack impacted two schools, both of which members of the Wooton Academy Trust. According…

  • European Police Arrest 100 Suspects in BEC Crackdown

    A recent announcement from the European police revealed that the security force conducted two major operations against business email compromise (BEC) fraudsters, leading to the arrests of almost 100 suspects. Although the campaigns were only recently made public, the crackdowns occurred in November of 2021. The police campaigns have been named Operation Wine Cellar and…

  • Google delays removal of third-party cookies in Chrome through 2024

    Google has reportedly delayed its plans to rid Chrome of third-party cookies. The implementation was set to occur in the second half of 2024, according to a blog posted by Google on Wednesday. Google’s reasoning for the delay was that more testing was necessary to improve privacy while giving businesses the tools that they require…

  • Kraken, a U.S. Crypto Exchange, Is Suspected of Violating Sanctions

    Kraken, one of the world’s largest cryptocurrency exchanges, is under federal investigation, suspected of violating U.S. sanctions by allowing users in Iran and elsewhere to buy and sell digital tokens, according to five people affiliated with the company or with knowledge of the inquiry. The Treasury Department’s Office of Foreign Assets Control has been investigating Kraken…

  • Reading the Not-So-Subtle Tea Leaves: What the SEC Is Likely to Do Next in Crypto, and How Crypto Participants Should Prepare

    It is highly likely, and hardly a surprise, that in the near future the U.S. Securities and Exchange Commission (“SEC”) will increase the number of enforcement actions it brings against crypto industry participants. It is widely known in the crypto industry that the SEC’s Division of Enforcement has been investigating a number of high-profile crypto…

  • DeFi Has Become Crypto Crime’s Main Arena, Crystal Blockchain Says

    More than $14.5 billion in crypto has been lost to hacks and scams since 2011, and DeFi (decentralized finance) is attackers’ new favorite target, says analytics firm Crystal Blockchain. In the past 11 years, there have been 167 hacks of DeFi protocols and 123 security breaches on centralized exchanges, according to Crystal’s new report. While…

  • Spree of multimillion dollar hacks creates booming business for blockchain security experts

    Even as cryptocurrency markets face economic turbulence, there’s one segment of blockchain-based industries where business is booming: blockchain security. A boutique industry of auditing firms formed over the past few years to deal with the emerging technology now boasts up to a year-long wait time to even begin working with customers and a growing list of…

  • US Senators Push Bill to Make Small Crypto Transactions Tax-Free

    Prominent U.S. senators are trying to free Americans from tracking taxes every time cryptocurrencies change hands, introducing a bill that would exempt them from reporting any transactions up to $50 or any trade in which they earn less than $50. Sen. Patrick Toomey (R-Pa.) joined with Kyrsten Sinema (D-Ariz.) to push the exemption from tax…

  • Novel Malware Hijacks Facebook Business Accounts

    A recently discovered malware dubbed Ducktail has been linked to Vietnamese threat actors. researchers from WithSecure released a report on Tuesday detailing the campaign in which the attackers use LinkedIn to steal data and admin privileges. The campaign appears to be motivated by financial gain. and has been active since late 2021. The malware uses…

  • Cyber-Criminal Offers 5.4m Twitter Users’ Data

    A seller by the nickname ‘devil’ has created a dark web database containing the personal information of 5.4 Twitter users’ data. The information is listed for sale on a popular criminal forum, according to security researchers. The seller claims to have exploited a vulnerability in Twitter systems reported in January, and Twitter is still investigating…

  • Social Media Accounts Hijacked to Post Indecent Images

    Police in the UK have warned about a surge in social media hacking incidents in which the attackers flood the victims’ accounts with indecent images of children. The shocking campaign does not appear to have any financial motivation behind it, as the victims did not receive a ransom demand. In some instances, the attackers uploaded…

  • Google Chrome security update fixes ‘high risk’ flaws

    The Cybersecurity and Infrastructure Security Agency (CISA) has urged IT administrators and users to implement recent updates released by Google as soon as possible to avoid the risk of an attacker leveraging several flaws that were patched in the update. Google released security updates for the Chrome browser on Mac, Windows, and Linux devices. The…

  • Kim Jong-un says North Korea ready to mobilize nuclear forces

    In a claim made at a Korean War anniversary event, Kim Jong Un announced North Korea is ready to mobilize its nuclear war deterrent and is fully ready for any military confrontation. There are concerns that North Korea is preparing for a seventh nuclear test, one that the US has warned could be conducted at…

  • Nicaraguan opposition leader Suazo sentenced to 10 years in prison

    According to the Nicaraguan Center for Human Rights, Nicaraguan opposition leader Yubrank Suazo has been sentenced to 10 years in prison. The opposition leader had participated in the protests in 2018 against the government of President Daniel Ortega. The announcement of his prison sentencing was made on Wednesday.  Suazo was sentenced to five years in…

  • NFT Projects Lost $22M to Largely the Same Hackers on Discord: Reports

    Two Web3 security firms have issued reports focused on the recent scourge of hacks targeting NFT projects, likely by a linked group of hackers using compromised Discord server administrator accounts. According to a recent analysis by TRM Labs, cyber attacks against NFT collections have steadily risen in 2022, costing the NFT community over $22 million in…

  • DeFi Has Become Crypto Crime’s Main Arena, Crystal Blockchain Says

    More than $14.5 billion in crypto has been lost to hacks and scams since 2011, and DeFi (decentralized finance) is attackers’ new favorite target, says analytics firm Crystal Blockchain. In the past 11 years, there have been 167 hacks of DeFi protocols and 123 security breaches on centralized exchanges, according to Crystal’s new report. While…

  • The regulatory risk in Ethereum’s new security model

    Ethereum, the world’s second-biggest blockchain, is switching to a new security model that at least one legal expert claims could raise an issue with profound repercussions for the cryptocurrency market. Why it matters: If ether (ETH), the coin that runs Ethereum, is found to be a “security” by the Securities and Exchange Commission, it’s hard to…

  • What is Cryptojacking? Why did it surge by 269% in 2022?

    Hacks and scams aren’t new to the crypto-verse. Ill doers have shown no mercy despite the gruesome bear market. They have in fact adopted new and innovative ways to pocket easy money. One such method that seems to have taken the front stage in 2022 is cryptojacking. While the term isn’t as popular as other…

  • Source code for Rust-based info-stealer released on hacker forums

    The source code for an information-stealing malware coded in Rust has been released for free on hacking forums, with security analysts already reporting that the malware is actively used in attacks. The malware, which the author claims to have developed in just six hours, is quite stealthy, with VirusTotal returning a detection rate of around 22%.…

  • Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused Brands

    Phishing attacks impersonating Microsoft have increased by 266% in Q1 compared to Q1 of 2021. Microsoft, Facebook, and French band Credit Agricole are the brands most commonly used by malicious actors to conduct phishing attacks, according to a study of phishing released by researchers at Vade Tuesday. Phishing attacks leveraging the Facebook brand are up…

  • Data Breach Costs Reach New Record High

    The average cost of a data breach is now stands at a record $4.35 million, representing a 13% increase on 2020 figures. IBM released its annual Cost of a Data Breach Report that is now in its 17th year of publication. The report was based on interviews with 550 different organizations spanning 17 different countries,…

  • US Doubles Reward for Info on North Korean Hackers

    The US government has ramped up the reward for providing information pertaining to North Korean state-linked hackers to $10 million, which may indicate that its efforts thus far have proved unsuccessful. In March of 2022, the State Department’s Rewards for Justice scheme announced a $5 million reward for information, meaning that the award has since…

  • Voters give president near unchecked power in Tunisia

    There have been new powers given to the country’s president in Tunisia after a vote that critics say risks the return of authoritarian rule. Less than a third of Tunisians voted in the referendum but almost 95% of those who did vote supported the powers being handed to President Kais Saied. Opposition groups boycotted the…

  • Poland to buy hundreds of South Korean tanks, howitzers after sending arms to Ukraine

    Poland is going to buy almost 1,000 tanks, over 600 pieces of artillery and dozens of fighter jets from South Korea to replace the equipment donated to Ukraine during the Russian invasion. The agreement will be officially announced in Poland on Wednesday. 980 tanks and 648 self-propelled K9 armored howitzers and 48 FA-50 fighter jets…

  • The Nine Largest Crypto Hacks in 2022

    Hackers exploited a software bug in the Web3 music platform Audius to make off with $1.1 million on Saturday, but the funds are a drop in the nearly-$2 billion dollar bucket of funds lost to hacks through the first half of 2022, according to Blockchain security firm Beosin. The fiat value of hacked assets are on…

  • CFTC Announces New Tech Innovation Office to Oversee Crypto

    The regulator which could soon be responsible for more of the US’s crypto oversight is beefing up its technology team, the agency’s chief said on Monday. The Commodities and Futures Trading Commission (CFTC), which stands to gain greater authority over digital assets under the proposals of a bipartisan congressional bill, is setting up a new Office…

  • How governments seize millions in stolen cryptocurrency

    There have been so many recent multimillion-dollar cryptocurrency thefts that it’s easy to lose track. Organized crime, bad cybersecurity, financially motivated spies, and colorful criminals of all kinds have made so many headlines that even huge heists can go mostly unnoticed by the public. But sometimes the government is able to get it back. Last…

  • Amid the hype, they bought crypto near its peak. Now, they cope with painful losses

    For Michelle Milkowski, who lives in Renton, Washington, one thing led to another. Because her son’s daycare closed in the early days of the pandemic, she had some extra cash. So, like millions of other people, Milkowski downloaded the Robinhood trading app. Back then, the stock market was at the beginning of what would become…