BREAKING: BYBIT $1 BILLION HACK BOUNTY SOLVED BY ZACHXBT
At 19:09 UTC today, @zachxbt submitted definitive proof that this attack on Bybit was performed by the LAZARUS GROUP.
His submission included a detailed analysis of test transactions and connected wallets used ahead of the exploit, as well as multiple forensics graphs and timing analyses.
The submission has been shared with the Bybit team in support of their investigation. We wish them all the best.
How to fix the Crowdstrike thing:
1. Boot Windows into safe mode
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Delete C-00000291*.sys
4. Repeat for every host in your enterprise network including remote workers
5. If you're using BitLocker jump off a bridge
There's still a load of potential for further research and discoveries in HTTP request smuggling. This massive-impact finding from @deadvolvo exploiting Akamai/F5 is a great example:
https://t.co/YHkP4fHoo8
1/ It’s unfortunate I have to make this thread but I am being sued by MachiBigBrother for an article I published in June 2022.
Today Machi filed the defamation lawsuit. The lawsuit is baseless and an attempt to chill free speech. I intend to fight back & defend free speech.
Discover how we compromise systems through misconfigured WSUS (Windows Updates) - Remote Command Execution as #SYSTEM
https://t.co/ncK5YOjQRL
#pentest#windows#wsus#injection#rce
Did you enjoy the latest blogpost on PHP filter chains? Well, our ninja @_remsio_ strikes again with a new article detailing how you can abuse them to leak files from the targeted system, as well as a freshly developed tool to exploit it! https://t.co/gQCOFD6xVv
Very nice little article. Bug hunting is more accessible than you might think; although it does obviously require some technical skills you don't have to be a seasoned veteran to find issues. https://t.co/NDyAkyUCAt
Aurelien the founder charged today by the DOJ in the $2.9m rug pull of Mutant Ape Planet also happens to be the co-founder of another $1.6m rug pull I did a thread on called Crazy Camel Club (attached below)
📑 Root cause analysis from past DeFi incidents.
Hope this stuff can help devs to avoid the same mistakes as much as possible.
Now covered 95 incidents.
https://t.co/GPsLNpFAqH
#DeFi#Web3
The Dedaub team has disclosed a Critical vulnerability to the Uniswap team!
Funds are safe - Uniswap addressed the issue and redeployed the Universal Router smart contracts on all its chains 👏
The vulnerability allows re-entertrancy to drain the user's funds, mid-tx.
🧵
1/ Six hours ago an account messaged me and sent over a db with api keys of 3Commas users. I began working to verify its validity and quickly shared the info with exchanges.