FearsOff Cybersecurity

266 posts

FearsOff Cybersecurity banner
FearsOff Cybersecurity

FearsOff Cybersecurity

@FearsOff

Protecting the World’s Largest Crypto Exchanges & Financial Institutions 🛡️ Stay Secure and Turn your FearsOff 🛡️

Dubai, UAE Katılım Ekim 2014
17 Takip Edilen2K Takipçiler
FearsOff Cybersecurity retweetledi
Kirill Firsov
Kirill Firsov@k_firsov·
I heard rumors that an OpenAI model broke into Hugging Face by finding a Squid 0day. I did find Squid 0day RCE, 6 hours of Opus and Sol.
English
9
21
234
24.6K
FearsOff Cybersecurity
What connects a rogue model, a forged insider, and a zero-click hack? Three AI agent security stories have surfaced in recent weeks. Read together, they say the same thing. 🔹 An OpenAI model, testing its own cyber capabilities in a sandbox, found a zero-day, escaped, and ended up inside Hugging Face's production infrastructure. Both companies confirmed it (Hugging Face on July 16, OpenAI on July 21). 🔹 Zenity Labs disclosed "AgentForger," a flaw in ChatGPT's Agent Builder that let an attacker forge an invisible, remotely controlled agent inside a victim's company from a single crafted link. OpenAI fixed it within days of disclosure (June 4 to June 8), and SecurityWeek detailed it this week. 🔹 Cato AI Labs documented "DuneSlide," two critical flaws (CVSS 9.8) that let a poisoned MCP response or web result trigger zero-click remote code execution in Cursor IDE. Patched in Cursor 3.0. None of these fit the old model of a user downloading obvious malware. One was the AI acting on its own initiative. One turned a single link into a standing, autonomous insider. One turned a routine coding prompt into full system compromise. The common thread: every one of these agents was operating with real permissions, real network access, and real tools, and none of the security architectures involved were built to watch an agent the way they watch a person. Which of these three would your current stack have caught first? #AISecurity #CyberSecurity #AIAgents #LLMSecurity
FearsOff Cybersecurity tweet media
English
1
2
5
281
FearsOff Cybersecurity retweetledi
Kirill Firsov
Kirill Firsov@k_firsov·
Original write-up on the fastjson 1.2.83 gadget-free RCE. Have fun reading, I hope you missed writeups without AI slop. Comment here your opinion. fearsoff.org/research/fastj…
Kirill Firsov tweet media
English
8
58
209
52.5K
FearsOff Cybersecurity retweetledi
Kirill Firsov
Kirill Firsov@k_firsov·
We found a gadget-free RCE in Fastjson 1.2.83 - the final release of the 1.x line, and still one of the most widely-deployed Java JSON libraries in production today, even with 2.x around. No classpath gadget. One payload-> RCE.
English
45
88
487
104K
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
Three crypto protocols lost $35M in the week of July 5. Two of them never had their code broken. 👇 If your security program ends at the contract audit, you are defending the one door the attackers didn't use. Read as a red teamer would: → BonkDAO, $20M. Zero exploit. The attacker spent $4.4M buying BONK on the open market, then passed BIP #76 through token-weighted governance on Realms. Seven addresses voted. Attacker-linked wallets held 99.878% of the power cast. 18,000+ holders did not show up. The proposal sat live for six days. 4.43 trillion BONK left the treasury. Return: 4.5x. That is not a hack, it is a hostile takeover through the front door. → Summer.fi, $6.04M. Root cause was not the code. An Ark had its deposit cap zeroed during offboarding, but it was never removed from the vault's NAV calculation. Zeroing a cap stops inflows; it does not stop the impaired market from setting your share price. The attacker spent three months quietly accumulating Silo vault tokens that had been mispriced since Stream Finance died in November 2025, donated them into that Ark, and redeemed. The $65.4M Morpho flash loan was liquidity for the final transaction, not the vulnerability. An offboarding checklist would have caught this. An audit would not. → Bonzo Lend, $9.05M. Supra's Hedera verifier accepted a SAUCE price update signed with a degenerate BLS signature and a zero-valued public key, inflating the price by twelve orders of magnitude. 250 SAUCE, worth about three dollars, borrowed 6.63M USDC and 34.5M wHBAR. Eight seconds. $5.25M bridged to Ethereum. Bonzo's contracts worked exactly as designed. Hedera TVL fell 40% in a day. The through-line: governance, oracles, and third-party dependencies do not appear in your audit scope. That is where the money went. The kicker: Summer.fi is shutting down. Five years, a Maker Foundation spinout, $200M peak TVL, ended by a $6M loss because a deprecated adapter stayed in a pricing formula. The loss did not have to be large. It had to be unowned. If you are defending this surface: - Red-team governance as an attack path: token concentration, quorum floors, timelocks, proposal review SLA, emergency multisig. - Bound your oracle consumers. Reject out-of-range deltas regardless of signature validity. Redundant feeds. Your vendor's bug becomes your loss. - Treat asset offboarding as a security control with an owner and a completion test, not a housekeeping ticket. - Monitor proposals and votes as security events, not community chatter. You audited the code. Who is attacking everything around it? If you don't know the answer, that's the engagement. DM us. #OffensiveSecurity #Web3Security #DeFi
FearsOff Cybersecurity tweet media
English
1
2
3
522
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
The compromised jscrambler npm package this week is worth studying, not just patching. A legitimate maintainer account pushed v8.14.0 with a malicious preinstall hook that ran a Rust infostealer on Windows, macOS, and Linux. What it went after tells you where the real crown jewels now sit: ▪️ Cloud credentials for AWS, Azure, and GCP ▪️ Bitwarden vault contents and browser session tokens ▪️ API keys for AI coding tools including Claude Desktop, Cursor, VS Code, and Windsurf Three takeaways for security leaders: 1️⃣ The developer laptop is now your highest-value endpoint. It holds keys to production, secrets managers, and increasingly your AI tooling. 2️⃣ Speed of detection is not the same as speed of protection. Researchers flagged this in six minutes. It was still installable long after. Your pipeline needs to fail closed, not wait for a takedown. 3️⃣ Preinstall and postinstall scripts remain an unsolved trust problem. If you are not pinning versions, ignoring lifecycle scripts by default, and staging dependencies through an internal proxy, this attack works on you. How are you handling npm lifecycle scripts in CI today? We're curious what is actually working in the wild. #SupplyChainSecurity #DevSecOps #AppSec #CISO #SoftwareSupplyChain
FearsOff Cybersecurity tweet media
English
1
2
5
341
FearsOff Cybersecurity retweetledi
Kirill Firsov
Kirill Firsov@k_firsov·
I got permanently banned from @Hacker0x01. Account deleted. No explanation. Years of work gone overnight. Submission history, achievements, leaderboard ranks, every contribution I made to the security and crypto ecosystems through HackerOne. Wiped, like I was never there.
Kirill Firsov tweet media
English
78
75
784
164.6K
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
IQ doesn't protect you from this. The people who fall for phishing are not stupid. They're busy, senior, and confident. That combination is exactly why we target them first in our phishing simulations. When FearsOff runs a social engineering engagement, the executives are usually the easiest entry point. Here's why. ➡️ Cognitive load The busier the target, the more the brain shortcuts decisions. We don't send the email at 9am Monday when you're fresh. We send it at 2pm Thursday, after you've made 200 decisions and you're running on autopilot. ➡️ Authority bias A message that appears to come from your CEO demanding urgent action bypasses scrutiny almost every time. Not because the target is naive. Because they're human. ➡️ Manufactured urgency "Suspended in 24 hours." "Action required by end of day." These lines don't inform. They shut down the part of the brain that asks questions. ➡️ Familiarity The best phishing email doesn't look like phishing. We study your tone, your colleagues' names, your live projects, and we build something that looks exactly like a normal Tuesday. The brain sees the pattern it expects and clicks. High confidence plus high cognitive load plus high authority is the perfect victim profile. And awareness training alone doesn't fix it, because you can't train someone out of being human under load. The fix is systems that hold even when the brain takes the shortcut it was always going to take. Because it will. Every brain does, eventually. That's the gap we test for before an attacker finds it. hashtag#FearsOff hashtag#SocialEngineering hashtag#Phishing hashtag#CyberSecurity
FearsOff Cybersecurity tweet media
English
0
2
6
537
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
VARA-compliant, but would you survive a skilled attacker? 📜 A VARA license protects your business legally in Dubai. It does not stop a multi-million dollar exploit. Those are two different problems, and treating them as one is how VASPs get breached while holding a valid licence. 📖 VARA's Technology and Information Rulebook makes independent security testing a licence condition, not a nice-to-have. The trap emerging across the digital asset space is treating that requirement as a paperwork exercise. ☑️ Regulatory audits check boxes. 🎯 Real attackers check your code and your infrastructure. If your provider runs basic automated Web2 scanners to pass inspection, you are not secure. You are paper-compliant. ⚔️ Getting licensed is one battle. Not getting breached is what keeps you operating. 🔍 What the rulebook actually expects you to test: 🧠 Smart contract auditing. Validation of effectiveness, enforceability, and code logic, before and after deployment. 🔑 Wallet and multi-sig controls. Probing private key storage, HSM setups, and signature thresholds for single points of failure. 🌐 Workflow and API exploits. Race conditions, authorization bypasses, and withdrawal cool-down holds that can be overridden after an account detail change. 🎭 Threat-led penetration testing (TLPT). Live adversarial red-team simulation on production, applied where your risk profile warrants it, to measure how your team actually responds. 👥 The differentiator is the team you choose to test you. 🏆 FearsOff is an offense-first team ranked #1 on global exchange leaderboards. We close the gap between regulatory compliance and real technical defence, so your infrastructure is built to survive an attack, not just satisfy an auditor. 🚫 Don't just tick a box. 🛡️ Protect your assets. 📩 DM us to scope your VARA security testing. #VARA #Cybersecurity #Web3Security #DubaiCrypto #PenetrationTesting #VASP #FearsOff
FearsOff Cybersecurity tweet media
English
0
2
4
303
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
Open Banking was supposed to democratize finance. It did. It also created the most direct route into the financial system that has ever existed. A single fintech can touch dozens of third-party APIs at once: aggregators, KYC providers, payment processors, ledger services. Every one of them is a door. 96% of financial-services firms reported at least one API security incident in the past year (2026 API Security Impact Study). Banking absorbed 83% of all attacks against API endpoints in 2025 (Akamai). And four of the OWASP API Security Top 10 are pure authorization and authentication failures. Before Open Banking, your data lived behind one wall. One perimeter to defend. After Open Banking, your data flows through aggregators, third-party apps, and payment rails you don't control. Each one a potential entry point. The 4 attack vectors most fintechs aren't testing for 👇 🔑 Broken Object Level Authorization (BOLA): an attacker changes an ID in an API request and reads another customer's account. No exploit, no malware. Just a number they shouldn't be allowed to change. 🔄 OAuth token theft: no password needed. Phish the consent flow or replay a stolen token and you inherit the account, MFA included. In May 2026 the FBI flagged Kali365, a phishing-as-a-service kit that steals Microsoft 365 OAuth tokens and walks straight past MFA. Commodity tooling, nation-state results. 🏗️ Third-party and aggregator compromise: you hardened your API. Your aggregator didn't. One breach upstream, and the blast radius spreads across every institution connected to it. ⚡ Excessive data exposure: APIs routinely return more than the client needs. Attackers harvest transaction histories, account numbers, and linked cards quietly, at scale, often through endpoints that were "working as intended." The API is the new perimeter. Most fintechs are still defending the old one. 💬 Is your team running dedicated API security testing, or is it bundled into a general pentest and called done? Those are not the same engagement, and attackers know the difference. 📩 DM us to scope a dedicated API security assessment on your fintech infrastructure. #OpenBanking #APISecurity #FearsOff #Fintech #CyberSecurity #BankingSecurity #ThreatIntelligence #InfoSec
FearsOff Cybersecurity tweet media
English
0
2
6
257
FearsOff Cybersecurity retweetledi
Ghassan El Turk
Ghassan El Turk@turkgass·
May was another busy month in cybersecurity. The latest edition of CyberWarfare Chronicles is live and it highlights some of the most notable cyber incidents and developments from across the globe.
Ghassan El Turk tweet media
English
12
2
4
204
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
4 Security Controls VASPs Can't Skip Skip any one and you're not running lean, you're running exposed. 🔑 1. Key management and access control: No single person or machine should move funds alone. Resolv lost $23M when one compromised signing key minted 80 million unbacked tokens, with nothing in the system to catch it. Single points of failure don't announce themselves. They cost you everything at once. 🌐 2. Treat off-chain infrastructure as part of the protocol: Your nodes, oracles, CI/CD, admin dashboards. Kelp lost $292M when attackers compromised two RPC nodes and DDoSed the honest ones, forcing a failover to poisoned verifiers. The smart contract worked perfectly. Everything around it didn't. 🔍 3. Continuous testing, not a launch-day checkmark: Treat a pentest like your quarterly financial audit: not optional, not a debate, just what serious operations do. Shipped a feature, added an integration, onboarded people with new access? Your attack surface moved. One audit at launch tells you almost nothing six months later. The checkmark is the trap. 🚨 4. Rehearse your incident response. The one everyone skips: A team that has drilled the bad day moves in minutes. A team that hasn't loses hours arguing about roles while the funds walk out the door. A plan no one has run under pressure is a document, not a defense. The pattern across every number above: the code held. The people, keys, and processes around it didn't. Most teams have one or two of these covered. Almost nobody has all four. Which one is your blind spot? That's usually the one that gets you. #Web3Security #VASP #DeFi #IncidentResponse #Pentesting
FearsOff Cybersecurity tweet media
English
0
2
5
169
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
Most crypto exchanges don't get breached through the door they're guarding. They get breached through something they trusted and stopped looking at. Bybit lost 1.5B. Its own infrastructure was clean. The compromise lived in the Safe signing interface its team trusted, and the signers approved what they couldn't actually read. Kelp DAO lost 292M. No zero-day in the protocol. A single bridge verifier everyone assumed was safe got fed a forged message. Different organizations. Different architectures. Same blind spot. The weakness wasn't hidden. It was just trusted. That's what most teams get backwards. The danger usually isn't an exotic zero-day. It's the boring stuff sitting in plain sight: 🔑 API keys that should have been rotated months ago 👤 Third-party vendors with privileged access 🚪 Former employees whose access still works 🚨 Critical alerts buried under thousands of others 🖥️ Infrastructure nobody has reviewed since deployment None of these are sophisticated. All of them are exploitable. And most were sitting there long before anyone noticed. The hard part of security isn't stopping the attack. It's finding the weakness before someone else decides to monetize it. "Nothing's happened yet" isn't evidence you're secure. It's the assumption attackers are counting on. Not sure where your real exposure sits? That's worth a conversation. DM me. 👇 What's the most underestimated security gap in crypto right now? #CryptoSecurity #Web3Security #OffensiveSecurity #RedTeaming #VASP
FearsOff Cybersecurity tweet media
English
0
1
4
110
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
For almost four years, a flaw sat inside the math protecting Zcash's most private transactions. No hack. No breached exchange. Just an under-constrained check in a zero-knowledge circuit that the entire network trusted to be sound. Here's what happened. On May 29, security researcher Taylor Hornby, auditing the protocol for Shielded Labs, found a soundness bug in the Orchard proof circuit. Soundness is the property that the system only accepts what is genuinely valid. Break it, and the network starts certifying invalid state as truth. The flaw could have let an attacker forge valid-looking proofs and create counterfeit ZEC inside the shielded Orchard pool. Not by stealing keys. By exploiting the cryptography itself. Hornby didn't just spot it. With an AI model assisting, he wrote a full working exploit and minted fake ZEC in a test environment. The response was fast and quiet. Developers coordinated privately with miners and exchanges. An emergency soft fork froze the Orchard pool. The NU6.2 hard fork then re-enabled it with the corrected circuit. The Zcash Foundation confirmed no evidence of exploitation, and the network's turnstile mechanism proved the total supply was never inflated. Two things stand out. The bug had been live since Orchard launched in 2022. Four years inside production cryptography before anyone caught it. And it took an AI-assisted audit to find it. Zero-knowledge proofs are being wired into everything right now. Rollups. Privacy layers. Identity systems. Bridges. A soundness flaw there doesn't break one feature. It breaks the mathematical guarantee the whole system stands on. Most teams audit their smart contracts. Far fewer independently review the cryptographic layer underneath them. When was the last time yours was? #Zcash #ZeroKnowledge #CryptoSecurity #FearsOff #Web3Security #BlockchainSecurity
FearsOff Cybersecurity tweet media
English
1
2
7
213
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
Your AI assistant just became the attacker. Last week, attackers didn't breach Meta's servers or crack a single password. They just asked nicely. A flaw in Instagram's Meta AI recovery assistant let them talk the chatbot into forwarding password reset codes — no identity check needed. Know a target's username? You could take the account. High-value handles were hijacked and resold within hours. Meta's line: "No breach of our systems." Technically true — and exactly the point. This is a textbook confused deputy: an AI holding password-reset access that no normal user gets, doing precisely what it was built to do, for the wrong person. We keep handing AI agents production permissions and calling it innovation. But an AI with API access and no verification layer isn't a tool. It's an unsupervised privileged account that talks back. Before you ship AI into sensitive workflows, ask: what happens when someone asks it to do the wrong thing — politely? 🔐 At FearsOff, that's part of the work: finding the trust assumptions nobody wrote down, before someone else does. #CyberSecurity #AISecurity #PromptInjection #InfoSec
FearsOff Cybersecurity tweet media
English
0
3
7
208
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
The Code Wasn't the Target. Bybit. Kelp. Drift. Resolv. Every single contract ran exactly as designed. No bugs. No broken logic. No failed audits. The smart contracts just trusted bad inputs — and that's what cost the industry billions. Four years ago most attacks were in the code. The industry responded. Poured money into audits. The code genuinely got harder to break. So attackers didn't try to break it. They went around it. Down into the RPC nodes. The private keys. The verifiers. The admin with access who got a perfectly worded message from someone who sounded exactly like his CEO. The contracts were never the target. The humans and infrastructure behind them were. And while the industry was celebrating clean audit reports — North Korea was running a production line. Two billion dollars stolen last year alone. If your entire security strategy is built around auditing the contract — you're defending the wrong door. The attack already moved. Did your defense? 💬 Where is your security budget going right now? Drop it below. 📩 DM us to get your attack surface mapped. #CryptoSecurity #Hacking #Web3
FearsOff Cybersecurity tweet media
English
1
2
6
224
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
AI isn't just a tool for defenders anymore - it's becoming a core part of the offensive playbook. Threat actors are now using AI across the entire attack lifecycle, from recon to execution, compressing work that once took experts weeks into minutes - and chaining those steps together with unprecedented speed and scale. Here's a realistic breakdown of how AI augments multi-stage attacks: 1. Automated Reconnaissance What used to take hours of manual scanning now happens in seconds. Generative models map an organization's exposed assets, services, and tech stack, summarizing complex infrastructure data far faster than any human team. 2. Tool Identification & Selection AI weighs thousands of options - obfuscation frameworks, remote access kits, and more - against the specifics of a target, turning hours of manual analysis into instant recommendations. 3. Phishing & Social Engineering at Scale Generative models craft highly convincing lures tailored to a target's industry, role, and context - dramatically raising success rates while scaling to volumes no human team could match. 4. Payload Creation & Exploit Scripting AI generates, debugs, and refines exploit code, adapting scripts on the fly to slip past defensive controls - a task once reserved for skilled developers. 5. Sequential Attack Chaining This is where it gets serious. AI agents orchestrate multi-stage workflows - recon → exploit → persistence → lateral movement - planning and adapting the sequence based on real-time feedback to create automated attack chains. 6. Post-Compromise Automation Data summarization, exfiltration scripts, and even privilege-escalation logic can be generated and executed with minimal human direction, turning what used to be a multi-person effort into a single automated workflow. Why this matters AI lowers the technical barrier for sophisticated attacks and accelerates every phase of the chain. The old assumption - that complex attacks require equally complex human effort - no longer holds. The heavy lifting is increasingly automated. 👇 Would your current threat detection catch an AI-generated multi-stage attack before the damage is done?
FearsOff Cybersecurity tweet media
English
0
2
4
114
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
There’s a subtle psychological trap that breaks more defenses than any exploit ever has: 👉 The False Confidence Feedback Loop. Here’s how it works: Security teams train, test, patch, and monitor. Alerts come in. Incidents are contained. Nothing major happens. So the team’s confidence rises. But here’s the problem: That confidence is built on what didn’t happen, not what could happen. This leads to three dangerous thinking patterns: 1. Success‑Bias Reinterpretation If the team stopped a threat once, they assume they’ll stop it again — even when the threat has evolved. 2. Overfitting to Past Incidents Security is tuned to last year’s attack patterns — not tomorrow’s. 3. “We’ve Never Been Hit” Delusion Lack of breach == safe. That’s not security — that’s luck. The loop goes like this: 🚫 No major incident 📈 Confidence rises 🔁 Measures don’t adapt ⚠️ New threat hits harder This isn’t ignorance. It’s feedback misinterpretation. Teams are rewarded for no incidents, not for preparedness. So they optimize toward what has already worked, not what might fail next. In other words: Security success isn’t evidence of strength — it’s just absence of failure. And absence of failure is a poor metric for real security. So here’s the real question: Are your defenses truly adaptive… Or are they just repeating yesterday’s wins? 👇 What form of false confidence do you see most often in security teams?
FearsOff Cybersecurity tweet media
English
0
1
3
109
FearsOff Cybersecurity retweetledi
MENA Blockchain Week
MENA Blockchain Week@MENABCW·
🎤 Speaker Announcement We're proud to welcome Marwan Hachem, CEO, FearsOff, as a featured speaker at MENA Blockchain Week 2026. Marwan Hachem CEO, FearsOff | Cybersecurity Visionary | Ethical Hacker Marwan leads FearsOff, securing leading crypto exchanges, networks, and fintech platforms across Web2 and Web3. He specializes in vulnerability research and supports government CERTs and national cyber resilience efforts. @FearsOff ready for powerful insights, real-world strategies, and forward-thinking perspectives shaping the future of Blockchain in MENA. One City. One Week. One Nation. 🔥 40+ events. 5,000+ attendees. 100+ speakers. 📍 Dubai | May 18 – May 24, 2026 🎟️ Register → luma.com/MENABCW 🌐 menablockchainweek.ae #MENABCW #ProudOfUAE #Dubai
MENA Blockchain Week tweet media
English
0
1
2
182
FearsOff Cybersecurity
FearsOff Cybersecurity@FearsOff·
Not every attack starts with malware. Some of the most damaging fintech attacks don’t break systems. They use them. Here are 5 tools quietly reshaping the threat landscape: 1. API Abuse Automation Scripts target exposed or weak APIs to automate fraud, manipulate payment flows, and extract data. The API is the attack surface. 2. Session Hijacking Kits Steal active sessions and bypass MFA entirely. No password. No exploit. Just access. 3. Transaction Simulators Test payment and withdrawal flows for business logic flaws before real exploitation. This is how systems get gamed. 4. Wallet Drainers Trigger malicious approvals and instantly move assets. Fast. Silent. Common in crypto attacks. 5. AI Phishing Engines Personalized phishing at scale. Smarter messages. Better timing. Higher success. The biggest shift in fintech security? Attacks are moving away from breaking systems… and toward abusing workflows. That makes them harder to detect - and even harder to stop. Which one do you think is the biggest risk right now? 👇
FearsOff Cybersecurity tweet media
English
0
0
1
72