Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Whistleblower claims DoKwon, Kanav Kariya and Sam Bankman-Fried were involved in Terra’s LUNA and UST collapse

    Whistleblowers from the Terra community have made allegations that some of the most prominent figures in the cryptocurrency industry, like FTX CEO Samuel Bankman-Fried and Jump Crypto CEO Kanav Kariya, were responsible for TerraUSD’s (UST) colossal crash and de-peg. Whistleblowers in the Terra community have come forward with details of an insider deal that destroyed stablecoin…

  • These are the flaws that let hackers attack blockchain and DeFi projects

    The number of decentralized finance (DeFi) and blockchain projects grew massively during the past year, but their increased popularity has also piqued the interest of cyberattackers – who managed to steal at least an estimated $1.8 billion in 2021. The blockchain is a digital ledger that records transactions in a way that is difficult to…

  • The Great Reassessment: The Supply Chain Edition

    The logistics landscape is changing. Like the employment market in the pandemic, the need to unexpectedly adjust creates the opportunity to re-think. Sometimes the change is tactical – a reversible reaction – and things return to normal. Other times it leads to be a more structural change. Anticipating the forward shape of the supply chain means…

  • 6 Things You Need To Know About Crypto

    Despite being around for roughly 13 years and currently in the midst of a market crash, crypto feels like it’s still in a goldrush phase. As hopeful investors pile in with dreams of making big money, many still lack any real knowledge about what they’re getting into. A survey by software developer Oxford Risk last year…

  • US Car Giant General Motors Hit by Cyber-Attack Exposing Car Owners’ Personal Info

    General Motors, a US based automobile manufacturer, has announced that it suffered from a credential stuffing attack last month that ultimately exposed customer information. In addition, the attack allowed hackers to redeem rewards points and gain gift cards. General Motors stated that they detected the malicious activity between April 11 and 29 of this year,…

  • DR Congo military accused of shelling civilians in Rwanda

    Rwanda’s military has accused forces from the Democratic Republic of the Congo of cross-border shelling and wounding several civilians. Regional monitors have been asked to investigate as the shelling struck areas in Musanze district Monday morning.  The Expanded Joint Verification Mechanism is a group of military experts from the International Conference on the Great Lakes…

  • New phishing technique lures users with fake chatbot

    Trustwave has released a new report in which the company provides details regarding an emerging phishing technique through which attackers aim to steal credit card data from internet users. The initial contact method for the phishing scam is via email, like the majority of phishing campaigns. In particular, this campaign impersonates shipping company DHL and…

  • Turkey’s Erdogan says he will no longer talk to Greek PM

    Turkish President Recep Tayyip Erdogan has accused the Greek Prime Minister Kyriakos Mitsotakis of antagonizing Turkey and has said he will stop talking to the Greek leader as a result. The Turkish President also said he would cancel a meeting between the two countries after he said Mitsotakis recommended to US officials to not seel…

  • Executions spiked in Iran in Saudi Arabia in 2021

    Amnesty International says there was a concerning rise in executions in 2021 as Covid-19 restrictions were lifted. There were spikes seen in Iran and Saudi Arabia in the year of 2021. At least 579 executions were carried out in 18 countries, reflecting a 20% increase to 2020 and Iran accounted for 314 of these executions.…

  • Credit card skimmers are switching techniques to hide their attacks

    Microsoft has reported that card-skimming malware that aim to steal bank card details are increasingly turning towards utilizing malicious PHP script on web servers to manipulate payment pages. This enables the attacker to bypass browser defenses triggered by JavaScript code. Microsoft says that its researchers have observed the shift in tactics to Magecart malware that…

  • Crypto needs rules to rein in volatility

    Have we just seen a cryptocurrency meltdown or just another blip in a highly-volatile global coin market in urgent need of a regulatory reboot? Over $500 billion (£400bn) of crypto value was wiped out in less than a fortnight resembling the dot-com boom of 20 years ago. And we all know what happened then. At…

  • Multiple NFT Projects Attacked After Commonly-Used “Mee6” Discord Bot Hacked

    A Discord bot widely used by NFT projects, most notably the very popular (and very recently breached) game Axie Infinity, was compromised leading to scam messages being passed to users. A hack of the “Mee6” bot used to moderate Discord channels led to scam messages being passed in these communities, with the hackers posing as…

  • Broadcom, VMware deal could be announced by Thursday, sources say

    CNBC’s David Faber reported Monday that Broadcom had been gearing up to announce its acquisition of VMware as soon as Thursday, but the news could come sooner after several reports said the two companies were in talks. Some material terms still need to be finalized, and a deal could fall through, Faber said on CNBC’s “Squawk…

  • Bill Gates Explains Why He Doesn’t Own Any Cryptocurrency

    Microsoft cofounder Bill Gates isn’t a fan of cryptocurrency. Gates, now fourth-richest person in the world with a net worth of $125 billion, said during a Thursday Ask Me Anything exchange on Reddit that he doesn’t own any digital currency. “I like investing in things that have valuable output. The value of companies is based on how…

  • CIOs Stress Supply Chains, Efficiency as Recession Risks Rise

    Amid threats of recession, chief information officers say they are prioritizing technology that drives efficiency, mitigates ongoing supply-chain struggles and contributes quickly to the bottom line. Tech leaders at Walgreens Boots Alliance Inc., Carhartt Inc. and other companies say they are monitoring a number of factors, including the financial markets, inflation and supply-chain uncertainties as they…

  • U.N. Human Rights Chief Kicks Off Closely Watched China Trip

    This weekend, the United Nations High Commissioner for Human Rights Michelle Bachelet begun a six-day visit to China to investigate alleged violations of human rights. Bachelet’s visit will be closely monitored by Western officials and rights activists worried that China could somehow meddle in her findings and hide violations in the treatment of Muslims in…

  • Iran vows revenge after Revolutionary Guards colonel is assassinated

    Following a deadly attack against a high ranking official in the Islamic Revolution Guard Corps (IRGC), Iran’s President has promised to take revenge. Colonel Sayad Khodai was killed on Sunday in Tehran while he was sitting in his car outside of his home. Iranian officials reported that two gunmen on motorbikes opened fire at the…

  • Ransomware Hackers Steal Personal Data of 500,000 Students and Staff in Chicago

    According to Chicago Public Schools, more than half a million students and staff had their personal information leaked in a ransomware attack that occurred last December. However, the breach was not reported until April. The district stated that a vendor Battelle for Kids notified the school system of the breach in late April after a…

  • DoJ Says White Hat Hackers Will No Longer Face Prosecution

    The US Department of Justice (DoJ) recently announced that it will not prosecute “good faith” hackers in a historic policy shift. Up until this point, even white hat hackers could be prosecuted under the Computer Fraud and Abuse Act (CFAA), even when done to improve cybersecurity. The DoJ identified good-faith hacking as accessing devices solely…

  • Germany is keen to pursue gas projects with Senegal, says Scholz on first African tour

    Chancellor Olaf Scholz of Germany said the country wants to pursue gas and renewable energy projects with Senegal. The Chancellor announced this on Sunday during his frist trip to Africa as the war in Ukraine has created rising energy and food prices. The three-day tour began in Senegal, which has billions of cubic meters of…

  • Russian assault on key Donbas city intensifies

    Russia has been intensifying attacks in eastern Ukraine as they attempt to secure the Donbas region. Severodonetsk is the largest city under Ukraine rule in the Luhansk province and it has come under heavy artillery and missile fire from Moscow’s troops. Officials said on Sunday, Russian troops were repelled after trying to enter the city…

  • Pro-Russian Hackers Hit Critical Government Websites in Italy

    According to Italy’s Postal Police, pro-Russian hackers have launched a campaign targeting the websites of Italian institutions and government ministries. The cyberattacks were confirmed by law enforcement on Friday and are believed to have begun Thursday evening. Roughly 50 different institutions reported suspicious activity or cyberattacks, including the superior council of the judiciary, the customs…

  • Explosive DeFi: Where we are and where we’re heading

    The entire cryptocurrency space continues to evolve rapidly, having surpassed $3 trillion market capitalization for the first time in 2021. Further, global blockchain spending has surged 7 times over the past four years to an estimated $6.6 billion in 2021, and is projected to more than triple by 2024. That’s impressive given the seeds of…

  • Bitcoin Miners Face Shrinking Profitability Amid Crypto Crash

    As bitcoin enters a new bear market, the mining sector is feeling the pain. Specifically, miners are seeing their profit margins dwindle as Bitcoin’s price falls and Bitcoin’s mining difficulty continues to rise. Bitcoin mining revenue potential, defined as its hashprice, has fallen some 68% from its 2021 peak and 58% from 2021’s average. Two things…

  • Collapse of Luna cryptocurrency leads to $11 million exploit on Venus Protocol

    Venus Protocol, a decentralized money market, announced on Thursday evening that about $11 million had been lost due to people exploiting the historic collapse of the Luna cryptocurrency and its sister stablecoin UST. The team behind the Venus Protocol released a statement confirming suspicions that had been floating around for hours about the potential mishandling of…

  • Cyberattacks quietly launched by Russia before its invasion of Ukraine may have been more damaging than intended

    Russia is known for its potent cyber-warfare capabilities. So it is no surprise that Moscow launched cyberattacks against Ukrainian targets in the lead up to its invasion in late February. Russian hackers went after a variety of Ukrainian targets in the private and public sectors, but one cyber weapon aimed at a specific military target…

  • 380K Kubernetes API Servers Exposed to Public Internet

    According to the Shadowserver Foundation, who first discovered the security incident, more than 380,000 of 450,000 Kubernetes servers hosting the open-source container-orchestration engine for managing cloud deployments are vulnerable to third party access. The popular engine for managing cloud deployments is therefore an easy target, providing a broad attack surface for threat actors. The exposed…

  • Pharmacy Giant Hit By Data Breach Affecting 3.6 Million Customers

    Dis-Chem, a pharmacy retailer, announced that it has been affected by a data breach that exposed the personal details of roughly 3.6 million customers. Dis-Chem released a statement explaining how it contracted with a third-party service provider and operator for certain managed services, including a database. the database contained personal information that is necessary for…

  • Surprised? Modern “Smart” Farm Machinery Vulnerable to Cyber-Attackers

    Infosecurity Magazine reports that: A new risk analysis published in the journal Nature Machine Intelligence warns that smart farm machinery is vulnerable to malicious attackers, which could have significant implications for global supply chains. The analysis explains how hackers can leverage flaws in agricultural hardware that is used to plant and harvest crops, as well…

  • Microsoft says this botnet is growing fast and hunting for servers with weak passwords

    Microsoft has witnessed as 254% increase in activity of the botnet XorDDoS. XorDDoS is an eight-year-old network of infected Linux machines that is leveraged by threat actors to conduct distributed denial of service (DDoS) attacks against Linux users. The botnet conducts automated password-guessing attacks spanning thousands of Linux servers, seeking matching admin credentials utilized on…

  • Argentina found guilty of massacre of Qom and Moqoit people

    In a landmark criminal trial in Argentina, the state has been found guilty of the massacre of over 400 indigenous people almost 100 years ago. In 1924, authorities shot and killed Qom and Moqoit communities who were protesting inhumane conditions working and living on a cotton plantation. Responsibility of the attack had never been acknowledged…

  • Rwanda expects first 50 asylum seekers transferred from UK by end of May

    Rwanda is expecting to receive the first group of 50 asylum seekers from Britain by the end of May. The British government had announced plans in April to send people seeking asylum to Rwanda, but lawyers were expected to prevent their removal from Britain earlier this month.  The British government has begun to notify those…

  • Shoigu: Russia to build military bases in response to NATO moves

    Defense Minister Segei Shoigu of Russia said Moscow will create new military bases in the western part of the country in response to Finland and Sweden’s bid to join NATO. Russia believes these bids to join NATO are among an increase in military threats along Russia’s northwestern border.  The military threats cited also included the…

  • Australia election 2022: Cost of living worries voters

    Voters will head to the polls on Saturday in Australia with rising prices on their minds. The cost of living in Australia is at a 21 year high and the inflation rate in Australia is at 5.1%. The wage growth is at just 2.3%, meaning the inflation is leaving less money in people’s pockets each…

  • Israeli lawmaker resigns over ‘harassment’ of Palestinians, plunging government into parliamentary minority

    Israel’s government lost its parliamentary majority on Thursday after an Arab-Israeli lawmaker resigned. Ghaida Rinawie Zoabi is a lawmaker of the left wing Meretz party and accused the leaders of fueling tensions between Israel and Palestine. She opposes the government’s shift right and accused it of harassing her society.  Prime Minister Naftali Bennett now only…

  • New Chainalysis tool tracks stolen crypto across multiple chains

    Blockchain analytics firm Chainalysis has released a new tool to track transactions across decentralized finance (DeFi) protocols and multiple blockchains. Chainalysis launched a beta version of its Storyline software on Wednesday. Touted as a “Web3-native blockchain analysis tool,” Storyline aims to track and visualize smart contract transactions with a focus on nonfungible tokens (NFTs) and DeFi…

  • Russia to legalise cryptocurrency as means of payment ‘sooner or later’

    Russian Industry and Trade Minister Denis Manturov has said that the country will sooner or later legalise cryptocurrencies as a means of payment, suggesting that the government and central bank may be moving closer to settling their differences. The Russian minister was asked at a forum whether he believed cryptocurrencies would become legal as a…

  • Cyberattacks and misinformation activity against Ukraine continues say security researchers

    The cyber offensive against Ukraine continues with malware attacks and the spread of misinformation, according to security researchers. So far, Russian, pro-Russian, and Belarusian cyberattackers have employed the most comprehensive array of methods to achieve “tactical and strategic objectives, directly linked to the conflict itself,” according to research by security company Mandiant. However, the impact…

  • Axie Infinity hack highlights DPRK cryptocurrency heists

    Despite how enormous it was, the Axie Infinity heist marked only the latest chapter in the story of North Korean financial cybercrime. Sky Mavis, the developer of popular nonfungible token (NFT) video game Axie Infinity, lost hundreds of millions of dollars in assets when they were stolen by hackers on March 23. The attack occurred via…

  • Recovering from a cybersecurity earthquake: The lessons organizations must learn

    It’s been over a year since the SolarWinds supply chain hack sent shockwaves through thousands of organizations worldwide, but this cybersecurity earthquake is by no means over. More recently we’ve seen aftershocks fueled by the Log4Shell and Spring4Shell vulnerabilities, which impacted organizations using the Log4j library and the Spring Core framework. We had seen supply…

  • Will a Proof-of-Stake Ethereum Lead to More Centralization?

    When Ethereum eventually shifts from its current proof-of-work method to a proof-of-stake (PoS) consensus mechanism, it will rely on validators rather than on miners to validate transactions on the Ethereum blockchain. In order to run a validator and earn staking rewards, participants must stake 32 ETH, which is worth roughly $65,800 at current prices. Lido…

  • Personal Information of Nearly Two Million Texans Exposed

    According to a public notice released by the Texas Department of Insurance, the personal information of roughly two million Texans was left exposed on the internet for three years due to a programming issue. The department stated that the details of workers who have filed compensation claims were left unsecured online. The security incident was…

  • Patch these vulnerable VMware products or remove them from your network, CISA warns federal agencies

    The Cybersecurity and Infrastructure Security Agency (CISA) has warned companies that certain VMware products affected by newly disclosed critical flaws. The CISA recommends that these products be patched or removed from the network entirely to mitigate the risks posed by the vulnerabilities. The removal of the products if they cannot be patched is based on…

  • Togo authorities say 15 assailants died in ‘terrorist’ attack

    In a terrorist attack in the north of Togo that occurred lsat week, 15 assailants and eight soldiers were killed. Togo’s military are deployed in the north of the country to contain security threats from armed groups coming from Mali, Burkina Faso and Niger. The armed groups in these countries are linked to al-Qaeda and…

  • Global stock markets fall as growth fears rattle investors

    Following sharp falls in the US and Asia stock markets, fears of rising prices and slowing economies have made an impact on UK and European stock markets as well. The FTSE 100 index of leading companies decreased by 2.5% on Thursday and the main stock markets in France and Germany had similar declines.  The US…

  • Google Moves Employees Out of Russia

    Google has moved the bulk of its employees out of Russia, according to people familiar with the matter, ending the company’s commercial presence in the country for the near future. Most of Google’s Russian employees opted to leave the country and continue to work for Google outside Russia, with a large number ending up in Dubai,…

  • 5 Years That Altered the Ransomware Landscape

    The ransomware landscape has evolved considerably since WannaCry dramatically drove home the potential severity of the threat five years ago on May 12. What has changed somewhat less over the same period is enterprise preparedness in the face of ransomware attacks. Ransomware emerged and has remained entrenched as one of the most difficult security issues for…

  • German BaFin official calls for ‘innovative’ EU-wide DeFi regulation

    Birgit Rodolphe, executive director at Germany’s Federal Financial Supervisory Authority (BaFin), has called for innovative and uniform regulation of the decentralized finance (DeFi) space throughout the European Union. BaFin is Germany’s financial regulatory body responsible for regulating banks, insurance firms and financial institutions including cryptocurrency companies. BaFin is the issuer of “crypto custody licenses,” a permit…

  • What the War in Ukraine Means

    Amid the largely kinetic activity involving the invasion of Ukraine by Russia, numerous shifts in the cyber landscape are occurring. Leading up to the military invasion, Putin made overtures of cyber recourse to his global opponents. Over the last week, the cyber tables turned against him. In addition to Ukraine’s cyber offensive operations, Russia has…

  • Ernst & Young Unveils Supply Chain Manager on Polygon Network

    Big Four accounting and consulting firm Ernst & Young has unveiled its blockchain-based supply chain manager that is built for the Polygon network and that is aimed at solving bottlenecks in tracing products as they come to market. The EY OpsChain Supply Chain Manager, which is now available in a beta version, is the first…

  • Hezbollah and allies lose parliamentary majority in Lebanon election

    In Lebanon’s parliamentary elections, the Iran-backed Shia Muslim Hezbollah movement and its allies lost their majority number of seats. The results of Sunday’s election shows that the bloc’s candidates won 62 of 128 seats, three fewer than it needed to maintain a majority. While Hezbollah itself retained its own seats, its ally party President Michel…

  • Turkey threatens to block Finland and Sweden Nato bids

    Just hours after Finland and Sweden announced that they were considering seeking membership in NATO, Turkey’s president restated his opposition to the move. President Recep Tayyip Erdogan stated that the two nations should not attempt to send delegations to Turkey in an attempt to gain membership in Nato and convince the country of their bids…

  • Ransomware Hits American Healthcare Company Omnicell

    Omnicell, a multinational healthcare company, has recently confirmed that it suffered from a data breach following a reported ransomware incident. According to a statement released in the company’s quarterly 10-Q filing, Omnicell detected the ransomware attack and disclosed it on May 9. More details are expected to be released in the next few weeks as…

  • Russian soldier pleads guilty in first war crimes trial of Ukraine conflict

    The first war crimes trial in Ukraine was held since the war began. In the trial, a 21-year-old soldier pleaded guilty to killing an unarmed civilian. The attack was against a 62-year-old man only a few days after the invasion began. After pleading guilty, he will face a life sentence.  The soldier, Vadim Shishimarin, was…

  • Over 100,000 people officially missing or disappeared in Mexico

    More than 100,000 people have been registered as missing or disappeared in Mexico according to data from the Interior Ministry’s National Registry of Missing People.  The registry dates back to 1964 and continues through to this day. Since 1964, 100,023 people have been registered missing, 24,700 women and over 74,700 men along with 516 people…

  • Vulnerabilities found in Bluetooth Low Energy gives hackers access to numerous devices

    Cybersecurity researchers at NCC Group have found a critical flaw in Bluetooth Low Energy (BLE) receivers. The flaw may grant cyber criminals access to a range of devices, including phones, laptops, cars, and houses. NCC Group details how BLE uses proximity to authenticate that the user is within a close distance to the device. As…

  • Wizard Spider hackers hire cold callers to scare ransomware victims into paying up

    Security researchers at PRODAFT published the results of its investigation into Wizard Spider, a threat actor that is believed to be associated with the Grim Spider and Lunar Spider hacking groups. The report was released on Wednesday and details the group’s illegal activities, including the practice of hiring cold callers to scare victims into paying…

  • Only DevSecOps can save the metaverse

    Defined as a network of 3D virtual worlds focused on enhancing social connections through conventional personal computing and virtual reality and augmented reality headsets, the metaverse was once a fringe concept that few thought much, if anything, about. But more recently it was thrust into the limelight when Facebook decided to rebrand as Meta, and…

  • U.S. Government Issues Warning About Undercover North Koreans Working in the Crypto and IT Industries

    The U.S. government is increasingly alarmed about the thousands of North Korean tech workers that are being dispatched to American IT companies, including crypto firms, to earn revenue for North Korea and its weapons programs, violating U.S. and UN sanctions. In a new advisory, the government outlined methods to detect undercover North Korean workers, who gain…

  • Russia’s War on Ukraine Will Leave Scars on U.S., World Economies

    Russia’s invasion of Ukraine has dealt a blow to the global economy—weakening the postpandemic recovery and aggravating already-high inflation. Even if the worst fears of rising geopolitical tensions and larger economic disruptions do not materialize, private forecasters anticipate an inflationary slump for the world economy. In this context, the U.S. economy faces significant headwinds from higher…