πŸ‡ΊπŸ‡¦ Hacken was born in Ukraine, and we stand with all Ukrainians in our fight for freedom!

πŸ‡ΊπŸ‡¦ Hacken stands with Ukraine!

Learn more
bg

Weekly News Digest #65

Weekly News Digest #65

Published: 17 Dec 2021 Updated: 5 Apr 2022

Terrifying zero-click iPhone attack

The surveillance company NSO Group developed an exploit allowing the users of its software to gain access to an iPhone to install malware – in this case, a target does not even need to click on a link. Last month, NSO Group was added to the β€œentity list” of the US Department of Commerce due to the evidence that the company might have been involved in supplying spyware to foreign governments that later used it to target business people, embassy workers, officials, journalists, etc.

Google’s Project Zero has conducted the analysis of a new NSO β€œzero-click” exploit for iOS 14.71. According to the Project Zero researchers, it’s likely to be one of the most technically sophisticated exploits ever detected. This exploit may allow malicious actors to run Java-Script like code in the component of iOS that handles GIFs but, normally, doesn’t support scripting capabilities. As a result, malicious actors can remotely hack iPhone by writing to arbitrary memory locations. 

Read more

Your bank account and crypto wallet may be hacked by new Android malware

A new cybercrime campaign is bringing back the notorious Anubis malware banking trojan. This malware allows hackers to steal targets’ credit card details, GPS data, SMS messages as well as utilize other accessibility services enabled in the targeted device. This malware was first recorded in 2016. This malware is known for targeting the customers of financial institutions related to virtual payment platforms or cryptocurrency wallets. This trojan resurfaced in 2020.

Its latest version has β€œalmost-functional” ransomware module allowing malicious actors to encrypt data on the victims’ devices. Anubis malware actively exploits the Covid-19 threat and scams victims by impersonating legitimate resources. For example, attackers impersonate the official page of the World Health Organization and urge victims to download special files. As a result, they actually download Anubis malware.

Read more

NFT marketplace Vulcan Forged hacked

The Polygon-based NFT marketplace Vulcan Forged was hacked on 12 December. Malicious actors stole 4.5M PYR tokens – the native tokens of the platform. The stolen tokens are worth around $140M. Although almost all impacted users were immediately reimbursed, the value of tokens has plummeted. The platform was applying the β€œsemi-custodial” model for controlling each user’s wallet. However, it failed to properly secure them from its end.

The new solution offering fully decentralized wallet management is now being rolled out. All stolen tokens have been identified and the platform is actively working on uncovering the footprints of the malicious actors responsible for this incident. 

Read more

DDoS protection and mitigation market may reach $6.7B by 2026

As of 2021, the size of the DDoS protection and mitigation market is $3.3B. It’s likely to demonstrate the compound annual growth rate at 15.1% from 2021 to 2026. The rise in multi-vector DDoS attacks will boost demand for DDoS mitigation solutions. Also, companies will have to integrate DDoS protection solutions into their processes due to new regulations to be imposed by governments. 

The services provided by DDoS protection vendors allow clients to safeguard websites and networks. By cooperating with DDoS protection vendors companies can make their systems resistant to DNS-amplification, NTP amplification, HTTP Flood, SYN Flood, spoofing attacks, and other forms of DDoS threats. 

Read moreΒ 

Hackers have stolen over $10B in DeFi-related hacks

In November 2021, the total capitalization of the crypto market surpassed $3T. However, the rapid increase in the popularity of cryptocurrencies has also created huge opportunities for scammers. In 2021, many notable hacks involved the projects representing the decentralized finance world. DeFi projects lost more than $10B due to thefts and fraud, according to the information provided by analytic firm Elliptic. Although the scope of risks is unprecedented, there are some tips by following which investors can protect themselves from possible theft of their assets or data.

The list of most effective tips is the following:

  • Conduct a thorough research
  • Check out projects’ smart contracts
  • Look at the project’s reputation
  • Ensure the security of your wallet

Read more

share via social

Subscribe to our research

Enter your email address to subscribe to Hacken Research and receive notifications of new posts by email

Interested in getting to know whether your systems are vulnerable to cyberattacks?

Tell us about your project

  • This field is required
  • This field is required
    • telegram icon Telegram
    • whatsapp icon WhatsApp
    • wechat icon WeChat
    • signal icon Signal
  • This field is required
  • This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Apply for partnership

  • This field is required
  • This field is required
  • This field is required
  • This field is required
    • Foundation
    • VC
    • Angel investments
    • IDO or IEO platform
    • Protocol
    • Blockchain
    • Legal
    • Insurance
    • Development
    • Marketing
    • Influencer
    • Other
This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Get in touch

  • This field is required
  • This field is required
  • This field is required
  • This field is required
This field is required
By submitting this form you agree to the Privacy Policy and information beeing used to contact you
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo