mastodon.uno è uno dei tanti server Mastodon indipendenti che puoi usare per partecipare al fediverso.
Mastodon.Uno è la principale comunità mastodon italiana. Con 77.000 iscritti è il più grande nodo Mastodon italiano: anima ambientalista a supporto della privacy e del mondo Open Source.

Statistiche del server:

6,2K
utenti attivi

#lazarusgroup

1 post1 partecipante1 post oggi

good thing the US is gutting beneficial ownership regulations that would make it easier to understand who actually owns US trusts and corporations while simultaneously trashing both crypto enforcement at the DOJ but also more generally cyber defense

"The companies, Blocknovas LLC and Softglide LLC, were set up in the states of #NewMexico and New York using fake personas and addresses."

* Reuters: reuters.com/sustainability/boa
* Technical details from Silent Push: silentpush.com/blog/contagious

Operation SyncHole: Lazarus Hackers Target South Korean Firms with Sophisticated Watering Hole Attacks

In a recent wave of cyber espionage, the notorious Lazarus group has breached six South Korean companies through a cunning combination of watering hole attacks and exploits targeting popular software....

news.lavx.hu/article/operation

Discussione continua

2/ ...and it just so happens that #PaloAlto released a long investigation into a newer and less well known North Korean crypto operation called "Slow Pisces" and/or "Jade Sleet" at the same time.

This time the #DRPK's crypto thieves pose as recruiters on LinkedIn and try to lure developers into doing various coding challenges hosted on #GitHub as part of a job interview. Doing a challenge leads to infection with custom Python #malware.

unit42.paloaltonetworks.com/sl

Unit 42 · Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python MalwareDi Prashil Pattni

1/ Deep dive case study of the kind of open source contributions and #GitHub astroturfing that North Korean hackers employ to try get jobs as devs at crypto companies, this time in an attempt to infiltrate #onlyDust.

tl;dr DPRK hackers use contributions to FOSS projects to build cred, after which, armed with AI video avatars, they try to leverage the cred into success in interviews for blockchain development jobs.

I've said it before but i'll say it again: the one real upside of crypto is that the industry draws close to 100% of the incoming fire from sophisticated #DPRK threat actors like Lazarus Group who would otherwise be hacking banks.

ketman.org/dprk-it-workers-in-

#ZachXBT is probably world's greatest crypto detective. He's pro-crypto but has busted a *ton* of frauds and scams.

Recently he's been working on tracking #NorthKorea's massive money laundering operation in the wake of the #Bybit hack and seems to have concluded that the entire crypto industry is fucked (which some of us have known all along).

* Telegram link: t.co/7Fi2sk1cqF

OKX Takes Action Against Lazarus Hackers: Enhancing DEX Security Amid Crypto Heist Threats

In a bold move to thwart the notorious Lazarus hackers, OKX has suspended its DEX aggregator services to implement crucial security upgrades. This decision follows a $1.5 billion crypto heist and high...

news.lavx.hu/article/okx-takes

#news#tech#DeFi