News list for " Security Officer"

SlowMist: A data breach occurred in a third-party service used by a leading trading platform. Please pay attention to the safety of funds

On January 17, 23pds, the chief information security officer of Slow Mist Technology, said on the X platform that it had recently detected a data breach of a third-party service used by a leading trading platform, involving a large amount of employee information, including email, password and other sensitive data. The relevant situation has been synchronized to the relevant parties for processing. The end of the year is approaching, reminding everyone to be vigilant and pay attention to the safe...

clock
2025-01-17 20:26:17
SlowMist CISO: Lazarus is using fake Willo-Talent software to trick users into downloading malicious programs

Slow Mist Chief Information Security Officer @im23pds posted a warning on social media, recently monitoring that the Lazarus organization no longer relies solely on video conferencing tools such as Zoom and Meeting as a means of attack, but instead turns to Trojan software disguised as the Willo-Talent recruitment video platform to trick recruiters into downloading and running malicious programs.

clock
2025-01-13 15:18:27
Slow Mist CISO: OpenSea email service provider was attacked and the leaked address is now fully public

SlowMist Chief Information Security Officer @im23pds posted a warning on social media that the email address leaked in 2024 due to the attack on the OpenSea email service provider has been fully disclosed after multiple broadcasts. Please be aware of the relevant risks and be alert to phishing emails and other potential cyber attacks, including email addresses including CZ. Previously reported, on June 30, 2024, according to OpenSea official news, the NFT trading market disclosed its email deliv...

clock
2025-01-13 10:24:58
Slow Mist CISO: In the past two months, North Korean hackers have continued to pretend to be Hack VC and other conference scams. Please be vigilant against risks

Slow Mist Chief Information Security Officer 23pds said on the X platform that in the past two months, North Korean hackers have continued to impersonate Hack VC, SevenX Ventures and other institutions or individuals to commit conference fraud. Please be vigilant against the risks.

clock
2024-12-30 12:11:07
LockBit ransomware group developer and coder Rostislav Panev has received around $230,000 in cryptocurrency transfers

According to the Department of Justice, Israeli national Rostislav Panev allegedly worked as a developer and coder for the LockBit ransomware group since around January 2022, and received about $230,000 in cryptocurrency transfers as part of his work.

clock
2024-12-21 09:57:30
Data: Cryptocurrencies stolen from January to July 2024 have accumulated to $1.58 billion

SlowMist Chief Information Security Officer 23pds tweeted that the cumulative value of cryptocurrencies stolen between January 2024 and July 2024 has reached $1.58 billion, which is about 84.4% higher than the value stolen during the same period in 2023. In 2024, private key leakage accounted for the largest proportion of stolen cryptocurrencies, reaching 43.8%.

clock
2024-12-20 10:24:38
SlowMist 23pds: 1inch discovered that attackers fraudulently gained access to the private key belonging to the owner of the 1inch Labs parser smart contract

Slow Mist Technology Chief Information Security Officer 23pds issued a statement saying that 1inch disclosed that it discovered a security bugs on December 9, and the attacker fraudulently obtained access to the private key belonging to the owner of the 1inch Labs parser smart contract.

clock
2024-12-12 09:03:04
SlowMist CISO: All data stolen by DEXX has been updated to support address query

SlowMist Chief Information Security Officer 23pds said on the X platform that all statistics on the DEXX theft have been updated so far. Note that if you are a victim: 1. Please go to the form to check whether your stolen address exists; 2. If you have transferred the balance by yourself, please go to the form again to check whether your own address is regarded as a "hacker" address record.

clock
2024-12-04 12:24:34
Users using @solana/web3.js, version 1.95.6, and 1.95.7 may be vulnerable to thieves who leak private keys

SlowMist Chief Information Security Officer 23pds posted, Please be aware of poison attacks, users using @solana/web3.js, version 1.95.6 and 1.95.7 can be attacked by thieves who disclose private keys. If your product is using these versions, please upgrade to 1.95.8 (1.95.5 not affected).

clock
2024-12-04 08:20:10
Okta fixes serious security bugs: usernames with more than 52 characters can bypass login verification

SlowMist Chief Information Security Officer 23pds posted that Okta allows any username longer than 52 characters to bypass login! Also according to the Okta announcement from identity and access management software provider, on October 30, a vulnerability was discovered internally when generating a cache key for AD/LDAP DelAuth. The Bcrypt algorithm is used to generate a cache key, where we hash a combined string of userId + username + password. Under certain conditions, this can allow users to ...

clock
2024-11-02 20:17:01
SlowMist CISO: Indodax security issue stems from system attack, not hot wallet private key leakage

On September 11th, SlowMist Chief Information Security Officer 23pds said on the X platform that after analysis, it was found that Indodax was not hacked with its hot wallet private key, but other systems were attacked, such as signature machines. It was previously reported that at 7:00 on September 11, according to the monitoring of Cyvers Alerts, Indodax's wallet carried out more than 150 suspicious transactions on different networks, with a total loss of about $18.20 million, and the suspicio...

clock
2024-09-11 14:12:05
Polygon Chief Information Security Officer: Polygon community Discord access has been restored and changes made by hackers are being cleaned up

On August 24, Mudit Gupta, Polygon's chief information security officer, posted on social media that "access to the Polygon community Discord has been regained and all changes made by the hackers are being cleaned up to ensure that the intrusion cannot be repeated." Previously, at 15:00 on August 24, Mudit Gupta posted on social media that the Polygon community Discord has been attacked, please do not click on any of the links, and the team is trying to regain ownership.

clock
2024-08-24 18:34:08
Polygon Chief Information Security Officer: Polygon's official Discord has been attacked, please do not click on any of the links

On August 24, Polygon Chief Information Security Officer Mudit Gupta said on the X platform that the Polygon community Discord has been attacked, do not click on any of the links, and the team is trying to regain ownership.

clock
2024-08-24 15:17:52
Polygon CISO: 90% of L1/L2 BD teams request airdrops directly from eco-projects

Mudit Gupta, chief information security officer at Polygon, said in a post on X that people are panicking about Eigen Labs employees asking for airdrops from eco-sub-projects, but in fact 90% of Layer1/Layer2 BD teams will directly ask for shares or airdrops in the name of advisors. If any reporter really wants to investigate this, just start a fake new DEX and contact a different Layer1/Layer2 BD team to get a hands-on experience.

clock
2024-08-19 15:57:16
SlowMist CISO: Immunefi has now received over $30 million bounty service fee

August 6th news, slow fog chief information security officer 23pds on the X platform, said that according to slow fog monitoring Web3 vulnerability bounty platform Immunefi official bounty 10% of the total service fee address, the bounty service fee received so far has exceeded 30 million dollars.

clock
2024-08-06 13:21:19