Follow the latest coverage, related explainers and connected technology stories.
Bitget revealed that the theft of $387.5 million in crypto assets resulted from the compromise of two third-party security devices using zero-day vulnerabilities. The attack gave the attackers access to the wallet environment and enabled them to deploy malicious tools used to carry out unauthorized transfers.
Attackers exploited two zero-day vulnerabilities in Citrix NetScaler appliances to install PHP backdoors and a network tunneling tool, gain root privileges, steal credentials, and move within networks. Citrix released security updates, while Mandiant warned that disabling DTLS addresses only one of the vulnerabilities.
The ShinyHunters group claims it exploited a previously unknown vulnerability in Oracle PeopleSoft to access systems belonging to the Federal Bureau of Investigation and steal data belonging to employees and job applicants. The FBI has not confirmed the breach or data theft and said it is investigating claims related to FBIjobs.gov.