Secondfi Security Incident
DeFi / Crypto - A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line o…
Tesseradao Security Incident
DeFi / Crypto - One key held everything. TesseraDAO lost $2.49 million - minted from nothing, dumped, and gone through Tornado Cash. No multisig, no real audit, not even an acknowledgment that they we…
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicl…
Secret Network Security Incident
Secret Network - RektFriday, June 26, 2026Aztec Connect - Aztec Labs - Rekt $4.67 million left Secret Network on June 10th. It took seven days for anyone to notice. A bridge contract forked from Secre…
Aztec Bridge Security Incident
Aztec Bridge - RektWednesday, June 24, 2026Aztec Connect - Aztec Labs - Rekt On June 14th, an attacker drained $2.28 million from a deprecated Aztec Connect contract that Aztec Labs had wound down in …
Aztec Connect Security Incident
Aztec Connect - RektThursday, June 18, 2026Aztec Connect - Aztec Labs - Rekt $2.28 million drained from a contract nobody was watching - two separate attackers, the same flaw, on two consecutive morni…
Humanity Protocol
Humanity Protocol - RektTuesday, June 16, 2026Humanity Protocol - Private Key Leak - Rekt Humanity Protocol sold the world a palm scan and a promise - that in a sea of bots, AI slop, and synthetic ide…
Syscoin Security Incident
Syscoin - RektThursday, June 11, 2026Syscoin - SPV Proof Parsing - Rekt 5 billion SYS minted from nothing. No keys stolen. No cryptography broken. Just a relay that read a lie and called it true. On J…
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport …
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-s…
CVE Pending: SIGSEGV in oggenc 1.4.3 (vorbis-tools) via Crafted WAV File
A crafted WAV file triggers a null pointer dereference / segmentation fault (SIGSEGV) in oggenc 1.4.3, crashing the encoder unconditionally. No user interaction beyond passing the file to oggenc is required.
CVE: Unhandled IEEE754 Special Values in Wings3D 2.4.1 OBJ Parser
A crafted Wavefront OBJ file containing IEEE754 special float values causes Wings3D to crash immediately on import. Root cause: unhandled function_clause exception in the Erlang OBJ parser.
CVE: Uncontrolled Resource Consumption in Scribus 1.6.5
A crafted .sla project file with extreme numeric geometry values causes Scribus to enter an infinite loop during layout containment checking, consuming 99% CPU and triggering a system-wide memory pressure cascade.
CVE: Unsigned Firmware Update in Actions Semiconductor Platform
The firmware update tool performs zero cryptographic verification before flashing firmware over USB. An attacker with physical access can permanently compromise any affected device. Covers 12 USB Product IDs across multiple consumer brands.