A developer critiques an analyst's explanation of a MultiversX smart contract exploit, arguing the root cause was a missing state revert after error checking—a common bug pattern—not a flaw in the chain's sharding design. The critic calls for a retraction and demands the team provide a full post-mortem on the breach.
F5 has patched a critical zero-day vulnerability in BIG-IP APM that is being actively exploited for remote code execution attacks. The flaw affects deployments using OAuth authorization server profiles, and CISA has ordered U.S. federal agencies to secure their systems by Friday. Cybercriminals and state-backed groups have a history of exploiting F5 vulnerabilities to breach networks and steal sensitive data.
A detailed technical critique of claims about a blockchain bridge exploit and chain halt, arguing that the original analysis mischaracterized public information as investigative discovery, conflated deterministic execution bugs with consensus failure, and overstated harm while lacking root-cause evidence.
ShinyHunters allegedly compromised the FBI using an Oracle PeopleSoft exploit to steal employee data and deface the recruitment website, demanding removal of a FLASH report they claim contains false allegations. The attack may have exploited a known CVSS 9.8 vulnerability that the FBI failed to patch within CISA's required timeline, followed by lateral movement to AWS GovCloud.
MultiversX blockchain experienced a significant exploit compared to Bitcoin's 2010 inflation bug and Ethereum's 2016 DAO hack combined. The team responded quickly with validators restoring service, and the community awaits a post-mortem report to verify claims of zero downtime and zero loss of funds. The incident raises questions about how blockchain projects handle security responses and damage control.
A governance exploit on the Neutron blockchain on September 22, 2026 resulted in approximately $9.4M being drained from smart contracts. An attacker purchased voting power for $20K, manipulated a governance proposal to change contract admins, and migrated contracts to steal funds. The attack exploited the chain's continued governance authority despite being in wind-down since March.