ByteScan Logo
ByteScan.net GmbH
Cybersecurity Research & Audit

25+
40+
20+
70+
ISO 27001 CVE/MITRE DeFi ZKP


ISO 27001
Global
Information security management
BSI IT-Grundschutz
Deutschland
Federal security baseline
NIS2 Directive
Europäische Union
Critical infrastructure
DORA
Europäische Union
Financial sector resilience
Cyber Essentials
Vereinigtes Königreich
UK government-backed scheme
NIST CSF 2.0
Vereinigte Staaten
Enterprise risk framework
SOC 2 Type II
Vereinigte Staaten
SaaS trust criteria
GDPR Art. 32
EU / UK
Data processor obligations

04.07.2026

Secondfi Security Incident

DeFi / Crypto - A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line o…

04.07.2026

Tesseradao Security Incident

DeFi / Crypto - One key held everything. TesseraDAO lost $2.49 million - minted from nothing, dumped, and gone through Tornado Cash. No multisig, no real audit, not even an acknowledgment that they we…

02.07.2026

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicl…

27.06.2026

Secret Network Security Incident

Secret Network - RektFriday, June 26, 2026Aztec Connect - Aztec Labs - Rekt $4.67 million left Secret Network on June 10th. It took seven days for anyone to notice. A bridge contract forked from Secre…

27.06.2026

Aztec Bridge Security Incident

Aztec Bridge - RektWednesday, June 24, 2026Aztec Connect - Aztec Labs - Rekt On June 14th, an attacker drained $2.28 million from a deprecated Aztec Connect contract that Aztec Labs had wound down in …

27.06.2026

Aztec Connect Security Incident

Aztec Connect - RektThursday, June 18, 2026Aztec Connect - Aztec Labs - Rekt $2.28 million drained from a contract nobody was watching - two separate attackers, the same flaw, on two consecutive morni…

27.06.2026

Humanity Protocol

Humanity Protocol - RektTuesday, June 16, 2026Humanity Protocol - Private Key Leak - Rekt Humanity Protocol sold the world a palm scan and a promise - that in a sea of bots, AI slop, and synthetic ide…

27.06.2026

Syscoin Security Incident

Syscoin - RektThursday, June 11, 2026Syscoin - SPV Proof Parsing - Rekt 5 billion SYS minted from nothing. No keys stolen. No cryptography broken. Just a relay that read a lie and called it true. On J…

23.06.2026

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport …

18.06.2026

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-s…

Medium Public 2026-04-10
vorbis-tools — oggenc 1.4.3

CVE Pending: SIGSEGV in oggenc 1.4.3 (vorbis-tools) via Crafted WAV File

A crafted WAV file triggers a null pointer dereference / segmentation fault (SIGSEGV) in oggenc 1.4.3, crashing the encoder unconditionally. No user interaction beyond passing the file to oggenc is required.

🏆 CVE — pending assignment
Medium Public 2026-03-31
Wings3D 3D Modelling Software — v2.4.1

CVE: Unhandled IEEE754 Special Values in Wings3D 2.4.1 OBJ Parser

A crafted Wavefront OBJ file containing IEEE754 special float values causes Wings3D to crash immediately on import. Root cause: unhandled function_clause exception in the Erlang OBJ parser.

🏆 CVE
Medium Public 2026-03-26
Scribus Desktop Publishing Software — v1.6.5

CVE: Uncontrolled Resource Consumption in Scribus 1.6.5

A crafted .sla project file with extreme numeric geometry values causes Scribus to enter an infinite loop during layout containment checking, consuming 99% CPU and triggering a system-wide memory pressure cascade.

🏆 CVE
Medium Public 2026-02-24
Actions Semiconductor — USB VID 10D6

CVE: Unsigned Firmware Update in Actions Semiconductor Platform

The firmware update tool performs zero cryptographic verification before flashing firmware over USB. An attacker with physical access can permanently compromise any affected device. Covers 12 USB Product IDs across multiple consumer brands.

🏆 CVE — pending assignment
Medium Public 2025-12-14
Shotcut / MLT Framework

CVE-2025-65834: Buffer Overflow in Shotcut 25.10.31

Buffer overflow in Shotcut video editor's MLT Framework image processing pipeline. An attacker can trigger out-of-bounds memory access via a crafted media file. CVE assigned by MITRE.

🏆 CVE-2025-65834 — assigned by MITRE

April 2026 · butterswap.io

Butter Network — Smart Contract Ecosystem Audit

BSC, Base, Arbitrum, Optimism, Polygon, Linea, zkSync, MAP Relay Chain
Public
8 Total
2 High
5 Medium
1 Low
$1.5M (at time of report) TVL
swapAndBridge() silently bypasses all fee collection across 7 chains — zero bridge fee revenue since deployment.

✉ audit@bytescan.net
Parity Technologies
Polkadot / Substrate
Blockchain Infrastructure
SAP SE
Enterprise Software
Enterprise Technology
University of Potsdam
Research Collaboration
Academia
TH Wildau
Technical University of Applied Sciences
Academia
CODE University
CODE University of Applied Sciences
Academia
SRH Berlin
SRH Berlin University of Applied Sciences
Academia
Graphcore
AI Processor Technology
Semiconductor
Imagination Technologies
GPU & AI IP
Semiconductor
Codasip
RISC-V Processor Design
Semiconductor
IQM Quantum Computers
Quantum Computing
Deep Tech
XMOS
Embedded Processing
Semiconductor
Pragmatic Semiconductor
Flexible IC Technology
Semiconductor
Dialog Semiconductor
Mixed-Signal ICs
Semiconductor