Authored by By Yashvi Shah McAfee Labs have identified an increase in Wextract.exe samples, that drop a malware payload at... The post Deconstructing Amadey’s Latest Multi-Stage Attack and Malware...
UK outsourcing company Capita exposed sensitive data in a public S3 bucket with no password protection for seven years (since 2016). The bucket contained approximately 3,000 files totaling 655GB -...
The release of the National Cybersecurity Strategy by the Biden-Harris Administration is a significant development that will have an impact on security teams across the United States. What does it say?
Industry-leading CISOs share advice and best practices to break down internal barriers and reinforce cloud security
Buffer overflow to C is Reentrancy to Solidity. Reentrancy attacks are when a user can reenter code in an unintended state in order to manipulate the system somehow. For instance, while...
Logo credit: RedCanaryEver since it first appeared in late 2021, the Raspberry Robin malware campaign has been propagating globally. A number of threat intelligence reports by vendors such as...
Threat Analysis Group shares their Q1 2023 bulletin.
On April 2nd, a malicious network participant within the Flashbots eco-system "stole" (lost profits) $20M from a MEV searcher by abusing a vulnerability in the mev-boost-relay implementation. When...
CoinVertible is a euro-pegged stablecoin. Although this sounds like a good idea, the authors of this post found some horrible findings in a brief glance. The eco-system is highly permissioned. As...
This article goes through the entire process of sending a single DAI to the creator of Ethereum. It's interesting seeing the small nuances of every part of the eco-system. If you have never read...
In DeFi, there are many lending and borrowing platforms. Users on these platforms can either lend tokens to receive interest or borrow tokens to conduct other activities. Naturally, the borrowers...
Denial of Service (DoS) are attacks that come from disallowing access to a service. In the context of blockchain applications, this can be completely rejects access to the service to somebody else...
What is cross-tenant risk? How do you spot vulnerabilities? And how can the famous PEACH framework help?
1. EXECUTIVE SUMMARY CVSS v3 10.0 ATTENTION: Exploitable remotely/low attack complexity Vendor: Illumina Equipment: Universal Copy Service (UCS) Vulnerabilities: Binding to an Unrestricted IP...
Authored by Dexter Shin Minecraft is a popular video game that can be played on a desktop or mobile. This... The post HiddenAds Spread via Android Gaming Apps on Google Play appeared first on McAfee Blog.
The fsevents npm package previously pulled certain remote binaries from a public S3 bucket (fsevents-binaries.s3-us-west-2.amazonaws.com). At some point the bucket expired and the domain became...
CISOs of Paramount, Aon and Wiz reveal their secrets for creating a future-proof approach to cloud security.
New alliance to enable organizations to proactively identify, prioritize, remediate, and prevent risks in their cloud.
The Ocean Life token on BSC was hacked. Ocean Life token is a deflationary token. This means that over time the token will disappear. Why? With less supply comes more demand. For more on...
The project being tested was from Alchemist. They developed the Fjord Foundry platform which has an ERC-20 token called MIST, a staking and rewards platform called Aludel and a smart wallet called...
Platypus Finance is an AMM protocol on the Avalanche blockchain. It has asset liability management and swapping capabilities. In February of 2023, they introduced USP, a new stablecoin....
DyDx is a trading platform perpetuals, leveraged trading and general trades that runs on Ethereum. DyDx had a smart contract for currency conversion that worked by trading all assets to USDC then...
Authored by Dexter Shin McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate... The post Fakecalls Android Malware Abuses Legitimate Signing Key...
On 2023-04-21, a campaign was reported, involving 8220 Gang, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.
In some way, shape or form, the Bug bounty scope needs documented scope. On Immunefi, this typically labels contracts or websites in scope and assets at risk. So, what happens when the company...
A container escape vulnerability, combined with accidental 'write' permissions to a private registry, opened a backdoor for Wiz Research to access Alibaba Cloud databases and potentially...
Google's Threat Analysis Group shares first quarter cyber updates on the threat landscape from the war in Ukraine.
Report informing readers about the threat to UK industry and society from commercial cyber tools and services.
Yearn Finance is a suite of products to yearn yield on digital assets. This includes staking tokens to earn interest and selling/buying votes. For the yield-bearing assets, users can put positions...
Automated Market Makers are great! Well, until you manipulate the algorithmic part of it. It was audited by WhitehatDAO who cleared missed some things. In Hundred Finance, hTokens are liquidity...