c.im is one of the many independent Mastodon servers you can use to participate in the fediverse.
C.IM is a general, mainly English-speaking Mastodon instance.

Server stats:

2.9K
active users

#blackhat

2 posts2 participants0 posts today

#Bybit released the conclusions of their investigation into how they got rekt for $1.4 billion by North Korea's #LazarusGroup. Summary:

1. (background) Bybit were dumb enough to store billions of dollars in a single wallet contract using software from a company called SafeWallet (a "Gnosis Safe")

2. A dev machine of SafeWallet (name is lol) was compromised by Lazarus and used to access SafeWallet's cloud data stores (S3)

3. malicious JavaScript was pushed to the cloud drive and eventually distributed in a release (?).

4. The malicious JavaScript code targeted specifically the Bybit contract address to change the content of the transaction during the signing / approval process.

* Bybit reports: docsend.com/view/s/rmdi832mpt8
* Full Statement from SafeWallet: x.com/safe/status/189476852272

in a normal world Bybit could probably sue SafeWallet, but I'm sure SafeWallet barely exists as an entity.

Corelight’s Director of Technical Marketing Engineering, James Pope, gave Dan Raywood of SC Media UK an inside look at the Black Hat Europe NOC, where every second counts. From securing networks to detecting threats, the NOC team ensures the event runs smoothly, with Corelight providing critical visibility.

Check out the full article to see how Corelight’s visibility and threat detection are powering real-time security at one of the world’s largest cybersecurity events: insight.scmagazineuk.com/an-ho