ByteScan Logo
ByteScan.net GmbH
Cybersecurity Research & Audit

25+
40+
20+
70+
ISO 27001 CVE/MITRE DeFi ZKP


ISO 27001
Global
Information security management
BSI IT-Grundschutz
Deutschland
Federal security baseline
NIS2 Directive
Europäische Union
Critical infrastructure
DORA
Europäische Union
Financial sector resilience
Cyber Essentials
Vereinigtes Königreich
UK government-backed scheme
NIST CSF 2.0
Vereinigte Staaten
Enterprise risk framework
SOC 2 Type II
Vereinigte Staaten
SaaS trust criteria
GDPR Art. 32
EU / UK
Data processor obligations

07.09.2026

Kiichain Security Incident

DeFi / Crypto - An attacker drained 148.3 million KII, worth roughly $9.7 million at the pre-exploit price, from KiiChain through the Cosmos EVM exploit class that also hit MANTRA and TAC. A halt immo…

07.09.2026

Tac Security Incident

TAC - RektTuesday, September 1, 2026TAC - Cosmos - Rekt Two days after MANTRA proved a halt could freeze what remained of an exploit in place, TAC proved that a halt can also be the moment you realize…

07.09.2026

Mantra Security Incident

Mantra - RektMonday, August 31, 2026Mantra - Cosmos - Rekt 720,923,967.99 MANTRA left two MANTRA-managed wallets on Aug. 20, worth roughly $3.6 million at the pre-incident spot price. 94.7% of it reac…

07.09.2026

Term Labs Security Incident

Term Labs - RektWednesday, August 26, 2026Term Labs - Governance - Rekt Half an Ether bought a controlling stake, and it was still overpaying. On August 23, Term Lab's vaults lost roughly $8.5 mi…

07.09.2026

Harmony Rekt2 Security Incident

DeFi / Crypto - Estimated $3.2 million lost after unauthenticated proof fields let old cross-shard receipts replay, crediting ONE without a source debit. Harmony confirmed an initial 4 billion ONE min…

01.09.2026

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with…

27.08.2026

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply ch…

14.08.2026

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-p…

11.08.2026

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploite…

06.08.2026

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organiz…

Medium Public 2026-04-10
vorbis-tools — oggenc 1.4.3

CVE Pending: SIGSEGV in oggenc 1.4.3 (vorbis-tools) via Crafted WAV File

A crafted WAV file triggers a null pointer dereference / segmentation fault (SIGSEGV) in oggenc 1.4.3, crashing the encoder unconditionally. No user interaction beyond passing the file to oggenc is required.

🏆 CVE — pending assignment
Medium Public 2026-03-31
Wings3D 3D Modelling Software — v2.4.1

CVE: Unhandled IEEE754 Special Values in Wings3D 2.4.1 OBJ Parser

A crafted Wavefront OBJ file containing IEEE754 special float values causes Wings3D to crash immediately on import. Root cause: unhandled function_clause exception in the Erlang OBJ parser.

🏆 CVE
Medium Public 2026-03-26
Scribus Desktop Publishing Software — v1.6.5

CVE: Uncontrolled Resource Consumption in Scribus 1.6.5

A crafted .sla project file with extreme numeric geometry values causes Scribus to enter an infinite loop during layout containment checking, consuming 99% CPU and triggering a system-wide memory pressure cascade.

🏆 CVE
Medium Public 2026-02-24
Actions Semiconductor — USB VID 10D6

CVE: Unsigned Firmware Update in Actions Semiconductor Platform

The firmware update tool performs zero cryptographic verification before flashing firmware over USB. An attacker with physical access can permanently compromise any affected device. Covers 12 USB Product IDs across multiple consumer brands.

🏆 CVE — pending assignment
Medium Public 2025-12-14
Shotcut / MLT Framework

CVE-2025-65834: Buffer Overflow in Shotcut 25.10.31

Buffer overflow in Shotcut video editor's MLT Framework image processing pipeline. An attacker can trigger out-of-bounds memory access via a crafted media file. CVE assigned by MITRE.

🏆 CVE-2025-65834 — assigned by MITRE

April 2026 · butterswap.io

Butter Network — Smart Contract Ecosystem Audit

BSC, Base, Arbitrum, Optimism, Polygon, Linea, zkSync, MAP Relay Chain
Public
8 Total
2 High
5 Medium
1 Low
$1.5M (at time of report) TVL
swapAndBridge() silently bypasses all fee collection across 7 chains — zero bridge fee revenue since deployment.

✉ audit@bytescan.net
Parity Technologies
Polkadot / Substrate
Blockchain Infrastructure
SAP SE
Enterprise Software
Enterprise Technology
University of Potsdam
Research Collaboration
Academia
TH Wildau
Technical University of Applied Sciences
Academia
CODE University
CODE University of Applied Sciences
Academia
SRH Berlin
SRH Berlin University of Applied Sciences
Academia
Graphcore
AI Processor Technology
Semiconductor
Imagination Technologies
GPU & AI IP
Semiconductor
Codasip
RISC-V Processor Design
Semiconductor
IQM Quantum Computers
Quantum Computing
Deep Tech
XMOS
Embedded Processing
Semiconductor
Pragmatic Semiconductor
Flexible IC Technology
Semiconductor
Dialog Semiconductor
Mixed-Signal ICs
Semiconductor