BLOCKMAGE

267 posts

BLOCKMAGE banner
BLOCKMAGE

BLOCKMAGE

@BlockmageSec

Web3 Native Threat Intelligence.

The Ether Bergabung Aralık 2022
152 Mengikuti1.3K Pengikut
BLOCKMAGE
BLOCKMAGE@BlockmageSec·
Takeaway: Automated scanners are essential for flagging capabilities, but manual verification is the only way to determine intent. We acted quickly in hopes of preventing harms, but in this case, we were mistaken. We've removed the post to avoid any confusion (sorry!).
English
0
0
0
72
BLOCKMAGE
BLOCKMAGE@BlockmageSec·
- The SOL wallet identified was actually a character property table in the Oniguruma regex engine. - The "Dropper" patterns were standard Emscripten/LLHTTP boilerplate. - The "Stealer" hits were bundled dotenv and undici dependencies.
English
1
0
0
81
BLOCKMAGE
BLOCKMAGE@BlockmageSec·
Earlier today, we flagged a VS Code extension (rphlmr.vscode-drizzle-orm) based on 21 critical YARA hits from vsix-audit. After manual inspection and deeper analysis, inspecting the .vsix, and reversing the WASM binaries, we’ve confirmed this is a False Positive.
English
1
0
0
203
BLOCKMAGE me-retweet
Fantasy
Fantasy@0xFantasy·
1/ I've been doing some research into how Unity Packages (similar to Node or Pip packages) could be weaponized for malware delivery Let me tell you, it doesn't exactly look good... 🧵
Fantasy tweet media
English
4
3
19
4K
BLOCKMAGE me-retweet
Alchemyst
Alchemyst@Alchemyst0x·
No excuses. These are live use, not theoretical CVEs. Apple doesn’t push same-day cross-platform updates and delete vulnerable code unless the stakes are real. Stay sharp. Patch everything. Watch your traffic. 🧙‍♂️
English
1
1
3
334
BLOCKMAGE me-retweet
Alchemyst
Alchemyst@Alchemyst0x·
Two #CVE's, patched across every Apple platform, both marked as actively exploited in the wild: #Apple just released: - macOS 15.4.1, - iOS 18.4.1 - iPadOS 18.4.1 - tvOS 18.4.1 - visionOS 2.4.1 — and you should stop what you're doing and update now.
English
1
1
4
586
BLOCKMAGE me-retweet
IOC Investigations
IOC Investigations@intell_on_chain·
July 2023 #TornadoCash exit worth 1,400 ETH ($2.6M) Exit via 100 ETH Contract, swaps for USDC, heads out over the Synapse bridge, to Polygon 0xc09d3c2 and get gambled away at @Stake. I see this fairly often when analysing TC. Tool: @MetaSleuth
IOC Investigations tweet media
English
4
5
21
6.9K
BLOCKMAGE me-retweet
ZachXBT
ZachXBT@zachxbt·
@zaingaziani @Ledger @Microsoft Sadly received two messages about this from victims today. Seems another person lost funds in just past few min.
ZachXBT tweet media
English
18
5
71
20.3K
BLOCKMAGE me-retweet
ZachXBT
ZachXBT@zachxbt·
Community Alert: There is currently a fake @Ledger Live app on the official @Microsoft App Store which was resulted in 16.8+ BTC ($588K) stolen Scammer address bc1qg05gw43elzqxqnll8vs8x47ukkhudwyncxy64q
ZachXBT tweet media
English
336
1.5K
3.9K
1.1M
BLOCKMAGE me-retweet
ZachXBT
ZachXBT@zachxbt·
1/ An investigation into the Canadian scammer known as Yahya for their involvement in 17+ SIM swaps which resulted in more than $4.5M stolen.
ZachXBT tweet mediaZachXBT tweet media
English
296
846
3.8K
824.1K
BLOCKMAGE
BLOCKMAGE@BlockmageSec·
@solminingpunk How else would we know what they are up to all the time?
English
0
0
2
87
FastFoodRembrandt.onion
FastFoodRembrandt.onion@solminingpunk·
“Why do you associate with threat actors?” Simple answer to this: When you’re in the active threat field you will converse, infiltrate, befriend, and utilize MANY threat actors, some know the game, and get paid, some don’t and get PTSD. Threat actors are amazing and usually THE Main source of intel in the field. If you’re in cybersecurity you will be around ALOT of threat actors, and you will WORK with them, luckily some are funny and kinda cool. Lol.
English
8
4
19
2.4K
BLOCKMAGE
BLOCKMAGE@BlockmageSec·
Unfortunate but true, web3 sees security as something you pay for once prior to your contract deployment. Brand protection gets sidelined in favor of keeping hype perpetually alive. Not to mention, those who do help, very often get nothing in return, so there's little incentive for professionals, albeit rife with opportunity to improve security across the board. We hardly have a name for the position though, so it can certainly be and feel overwhelming. That said, its always appreciable seeing the builders and the devs and security techs that are here, reaching out and making such efforts. This has been a constant in the space for years despite any market or trends otherwise. There's a sense of purpose to the whole thing because of this, and it certainly brings a level of quality and enthusiasm that you can't rightly find elsewhere. Nice post - cheers.
English
0
0
0
37
Zeffa
Zeffa@0xZeffa·
Web3 is dangerous. Within my career in web2 I've seen how fortune 500 businesses (and small-mid size start-ups), have invested ludicrous amounts of money to safeguard their digital assets and customers through security awareness training. But looking into the world of Web3 - NFT communities specifically, I see businesses neglecting cybersecurity measures left, right, and centre. The only security steps I see MOST businesses take is a once off audit to ensure their infrastructure is safe. The threat landscape is ever-changing as we can see with the ridiculous % of members that are getting drained on the daily. This results in massive damage. Reputation Damage: Too many security incidents can ruin a Web3 business's reputation and cause a loss of trust from within and externally - even if they're not to blame. Web3 companies are often victims of impersonation and phishing attacks. Customer Trust: Customer trust is paramount. Web2 businesses understand that data breaches or security failures can erode that trust, resulting in a loss of customers and revenue. Most Web3 communities don't even have a security structure in place. Community Vulnerability: Many Web3 projects rely on community involvement and contributions. When businesses neglect security awareness, they put not only their own team at risk but also the assets and investments of their community members. As a founder this should be one of your biggest concerns - you WILL be targeted, and knowing this why wouldn't you make your community aware and show them how to keep safe? This is just a few of the problems founders incur. It's high time for Web3 businesses to heed the wake-up call. Neglecting security is no longer a viable option. The success of Web3 relies on the trust of its users and stakeholders. Businesses need help to bridge this gap and provide communities with the option to have an ever-lasting secure environment where ALL members (staff and holders) are equipped with the right knowledge and tools to stay secure. Not just an alert channel that's posted in once a month. I've helped a handful of web3 businesses become more secure. Communities see their founders care/commitment about their holders - which helps grow trust, knowledge and reputation from within and externally. If this is of interest to you - reach out, and keep an eye out for what's coming soon.
English
6
4
13
976
BLOCKMAGE me-retweet
Caido
Caido@CaidoIO·
It's release time 🎃 - Responses can now be intercepted and modified - Delete requests from HTTP History - [Pro] Import/export your projects using our new "backups" page - [Pro] Add shell commands to your convert workflows with the new "Shell" node github.com/caido/caido/re…
English
1
10
77
11.5K
BLOCKMAGE me-retweet
Pocket Universe 🟣
Pocket Universe 🟣@PocketUniverseZ·
Introducing the Pocket Guardians They've already saved *hundreds* of you from dangerous websites Here's a quick intro ⬇️
Pocket Universe 🟣 tweet media
English
24
53
180
16.9K