Hackers $643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34 By Martin • a month ago
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
Hackers $643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34 By Martin • a month ago
Ill Bloom: A Weak Seed-Phrase Generator Drained Over $5M From Crypto Wallets Researchers at Coinspect have disclosed Ill Bloom, a vulnerability in how several cryptocurrency wallets generate their mnemonic recovery phrases (seed phrases). Exploiting it, attackers emptied hundreds of wallets in a single pass and made off with more than $5.1 million. The problem is not one specific wallet but the phrase-generation method used by a handful of lesser known apps, mobile and browser extensions, some dating back to 2018. These wallets relied on a weak random number generator,
ChocoPoC: Fake Exploits on GitHub Are Hunting Security Researchers A malware campaign flips the script on bug hunters: fake proof-of-concept exploits on GitHub secretly install the ChocoPoC remote access trojan.
News Crypto Theft Fell to $972M in H1 2026, but North Korea's Share Climbed to Two-Thirds Jul 16, 2026
Ransomware The Gentlemen Hit 18 Companies in 24 Hours, Now the Second Busiest Ransomware Crew Jul 14, 2026
AI Found the Flaw, Google Got There First: A Mass Exploit Foiled Google says it caught, with high confidence, the first known case of a criminal group using AI to find and weaponize an unknown vulnerability. They planned to deploy it at scale. It was likely stopped in time. By Martin • a month ago
$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34 By Martin • a month ago
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl Jul 17, 2026
Ill Bloom: A Weak Seed-Phrase Generator Drained Over $5M From Crypto Wallets Researchers at Coinspect have disclosed Ill Bloom, a vulnerability in how several cryptocurrency wallets generate their mnemonic recovery phrases (seed phrases). Exploiting it, attackers emptied hundreds of wallets in a single pass and made off with more than $5.1 million. The problem is not one specific wallet but the phrase-generation method used by a handful of lesser known apps, mobile and browser extensions, some dating back to 2018. These wallets relied on a weak random number generator, Jul 16, 2026
Crypto Theft Fell to $972M in H1 2026, but North Korea's Share Climbed to Two-Thirds In the first half of 2026, attackers stole about $972 million from the cryptocurrency industry across 207 incidents, according to a mid-year report from analytics firm TRM Labs. The figure is down by more than half from the same period in 2025, when losses were put at $2.3 billion. Despite the overall decline, the share tied to North Korea has actually grown. Analysts attribute roughly $643 million, about 66% of the half-year total, to the Lazarus Group and its TraderTraitor subunit. Almost all Jul 16, 2026