A dark web actor is advertising multi-chain cryptocurrency drainer source code for $210, claiming support for over 610 wallets across major blockchain networks including Ethereum, Bitcoin, and Solana, with features like phishing endpoints and admin panels. The claim remains unverified.
A dark web actor named 'vendoir' is advertising multi-chain cryptocurrency drainer source code for $210, claiming support for over 610 wallets across Ethereum, Bitcoin, Solana, and other blockchains with features including phishing endpoints and a web admin panel. The claim remains unverified.
SlowMist disclosed KREMLIN, a Brazilian banking malware operation active since May 2025, which uses multi-stage loaders and malicious browser extensions to steal credentials and data. The malware bypasses Chromium security mechanisms and leverages Ethereum smart contracts as dead-drop resolvers for C2 infrastructure, with 1,515 infected hosts primarily in Brazil.
A developer attending GISEC conference discusses eyebrow, a security tool for monitoring AI agents. The tool inventories agent artifacts, validates content hashes, maps host access, and flags unauthorized changes to prevent malicious code execution in both web2 and web3 environments. Presentations from Google Cloud Security and Microsoft highlighted similar concerns about autonomous exploitation and supply chain risks.
Researchers at UC Santa Barbara discovered that LLM API routers used to reduce costs and balance loads are vulnerable to man-in-the-middle attacks. They found that 9 routers inject malicious code into AI responses and 17 steal credentials, with autonomous agent execution enabling immediate code exploitation without human approval.
Check Point and academic researchers discovered critical vulnerabilities in smart bulbs including Philips Hue and TP-Link Tapo models that enable attackers to inject malware into home networks through buffer overflows and credential theft. Millions of IoT devices are publicly exposed on Shodan, and attackers exploit known CVEs at scale; users should update firmware, isolate smart bulbs on separate networks, and replace devices with unpatched vulnerabilities.
A user reported their Phantom wallets were compromised after downloading a fake Axiom Exchange app from the App Store designed to steal cryptocurrency. Security guidance recommends immediately deleting the malicious app, abandoning affected wallets, changing passwords across accounts, and reporting to Apple and local authorities.