Bitget exchange suffered a $351.6M hack on September 24, 2026, with unauthorized transfers from hot and warm wallets. The exchange claims its Protection Fund covers the loss, though withdrawals remain frozen while the incident is investigated. The post also discusses address poisoning risks in crypto transactions and mentions Americanfort_io's alternative security approach using unique stealth addresses.
RemControl, a new Android banking malware-as-a-service platform, targets users in Europe and Canada through malvertising campaigns impersonating the TVTap IPTV app. The malware uses over 30 phishing overlays to steal banking credentials and can perform remote actions including screenshot capture and keystroke logging. It evades detection by blocking Google Play Protect and uses Telegram channels to dynamically rotate its command-and-control infrastructure.
Two X users discuss AmericanFortress, a privacy infrastructure platform that replaces complex crypto wallet addresses with human-readable @names while generating unique stealth addresses for each transaction to reduce phishing risk and enhance on-chain privacy.
A social media post highlights security and privacy issues in cryptocurrency transactions, including address poisoning and phishing attacks, and promotes Americanfort_io as a wallet solution that uses stealth addresses and FortressNames to enable private transactions without exposing balances or transaction history.
The placeholder domain third-party.com, widely used in developer documentation as an example hostname, is now serving ClickFix attacks that impersonate Cloudflare verification pages to trick Windows users into executing malicious PowerShell commands. Unlike IANA-reserved documentation domains, third-party.com is a normally registered domain whose owner can control its content, creating a security vulnerability for developers who copy example code literally.
Dutch intelligence services AIVD and MIVD, along with five other organizations, warn that AI is making cyberattacks faster and easier by automating attacks and lowering barriers for malicious actors. They urge businesses and institutions to strengthen cybersecurity measures, keep systems updated, monitor networks, and invest in employee awareness and training.
Nano Labs founder Jack Kong's X account was hacked and used to post phishing links impersonating a new crypto project. Users are warned not to connect wallets or sign transactions from the compromised account without official verification.
Passkeys are digital keys that replace passwords, using your device's biometric or PIN verification to securely sign in without transmitting passwords. Each service gets a unique passkey based on public key cryptography, protecting against password reuse, theft, and phishing attacks.
AmericanFortress promotes Send-to-Name technology that generates unique stealth addresses for transactions to prevent address poisoning and phishing attacks while maintaining privacy between sender and recipient.
A Binance promotional post invites users to share crypto stories and creative content for a Mid-Autumn Festival campaign, emphasizing themes of global financial connectivity and trading across time zones.
Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain to deploy CLEANGULP malware through fake websites impersonating media organizations and NGOs. Attacks targeting Asian government entities used phishing emails referencing Hong Kong activist Chow Hang-tung and spoofed the Center for American Progress. The malware supports remote command execution, file operations, and process enumeration via a C2 domain mimicking a legitimate media outlet.
Anthropic faces mounting CVEs with limited attacker response, while the tech industry navigates AI model releases, security vulnerabilities in enterprise software, and evolving cybersecurity threats including ransomware and phishing campaigns.
A social media post discusses Tangem's cryptocurrency hardware wallet ecosystem, explaining self-custody concepts and how Tangem's products—wallet cards, rings, apps, and payment solutions—integrate security with practical everyday usage for crypto users.
Microsoft disrupted EvilTokens, an AI-powered subscription scam platform that compromised 12,000 accounts across 10,000 organizations globally. The platform, introduced via Telegram in February, charged $1,500 upfront plus $500 monthly, using an AI chatbot to analyze victim inboxes and recommend fraud strategies. Microsoft seized 50 websites and 150 domains, and UK police arrested two suspects.
A user warned about receiving a suspicious unsolicited crypto interview pitch on X from an account that requested credentials through a Google Sites link with an Apps Script login flow, exhibiting multiple phishing indicators.
A crypto user lost $20,000 from their MetaMask wallet after being socially engineered by scammers posing as NPR's "The Indicator" podcast. The attackers gained credentials through a fake interview, compromised multiple accounts, and drained the wallet containing funds from a newly launched $JERRY token on Robinhood Chain.
Microsoft is retiring SMS and voice as first-factor authentication methods for Entra ID starting February 2027, requiring administrators to migrate users to phishing-resistant alternatives like passkeys, FIDO2 security keys, or QR code authentication. The company has already ended SMS sign-in for free tenants and is rolling out passkeys as the default authentication method. Organizations must complete migration before the deadline to avoid sign-in disruptions.
Microsoft disrupted EvilTokens, an AI-powered subscription scam platform charged $1,500 initially plus $500 monthly that compromised 12,000 accounts across 10,000 organizations globally using a chatbot to analyze inboxes and craft fraud schemes. Microsoft seized 50 websites and 150 domains; UK police arrested two suspects.
A website owner discovered pixel-perfect copies of their site (prepfully.com) using similar domains with different TLDs (.live, .info), likely for phishing or adversarial SEO purposes. They plan to warn users about credential theft and implement CORS policies to prevent backend endpoint abuse, while seeking additional protective measures.
A weekly DeFi incident report covering multiple security breaches and hacks across blockchain protocols in September 2026, including smart contract exploits at Balancer, Safe, Nomic, ChainFlip, Ether Fi, and Yam Finance, plus a major phishing campaign via compromised Trezor email infrastructure that reached 347k addresses.