Kiichain Security Incident
DeFi / Crypto - An attacker drained 148.3 million KII, worth roughly $9.7 million at the pre-exploit price, from KiiChain through the Cosmos EVM exploit class that also hit MANTRA and TAC. A halt immo…
Tac Security Incident
TAC - RektTuesday, September 1, 2026TAC - Cosmos - Rekt Two days after MANTRA proved a halt could freeze what remained of an exploit in place, TAC proved that a halt can also be the moment you realize…
Mantra Security Incident
Mantra - RektMonday, August 31, 2026Mantra - Cosmos - Rekt 720,923,967.99 MANTRA left two MANTRA-managed wallets on Aug. 20, worth roughly $3.6 million at the pre-incident spot price. 94.7% of it reac…
Term Labs Security Incident
Term Labs - RektWednesday, August 26, 2026Term Labs - Governance - Rekt Half an Ether bought a controlling stake, and it was still overpaying. On August 23, Term Lab's vaults lost roughly $8.5 mi…
Harmony Rekt2 Security Incident
DeFi / Crypto - Estimated $3.2 million lost after unauthenticated proof fields let old cross-shard receipts replay, crediting ONE without a source debit. Harmony confirmed an initial 4 billion ONE min…
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with…
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply ch…
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-p…
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploite…
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organiz…
CVE Pending: SIGSEGV in oggenc 1.4.3 (vorbis-tools) via Crafted WAV File
A crafted WAV file triggers a null pointer dereference / segmentation fault (SIGSEGV) in oggenc 1.4.3, crashing the encoder unconditionally. No user interaction beyond passing the file to oggenc is required.
CVE: Unhandled IEEE754 Special Values in Wings3D 2.4.1 OBJ Parser
A crafted Wavefront OBJ file containing IEEE754 special float values causes Wings3D to crash immediately on import. Root cause: unhandled function_clause exception in the Erlang OBJ parser.
CVE: Uncontrolled Resource Consumption in Scribus 1.6.5
A crafted .sla project file with extreme numeric geometry values causes Scribus to enter an infinite loop during layout containment checking, consuming 99% CPU and triggering a system-wide memory pressure cascade.
CVE: Unsigned Firmware Update in Actions Semiconductor Platform
The firmware update tool performs zero cryptographic verification before flashing firmware over USB. An attacker with physical access can permanently compromise any affected device. Covers 12 USB Product IDs across multiple consumer brands.