The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
A significant vulnerability in Coldcard hardware wallets allowed attackers to exploit weak seed generation, resulting in the theft of approximately 1,367 BTC (around $88.6 million) from 4,585 addresses. The exploit,…
A phishing scam impersonating Trezor appeared at the top of Google search results, leading users to a fraudulent site that collected wallet recovery phrases. A victim identified as David reported losing his life…
Bybit's Security Operations Center (SOC) reported a sophisticated malware campaign targeting macOS users searching for 'Claude Code,' an AI development tool from Anthropic. The campaign, first identified in March 2026,…
On August 2, 2026, a Bitcoin and Litecoin holder fell victim to a scam involving attackers impersonating Trezor support staff. The victim provided a 12-word mnemonic phrase, leading to the theft of approximately $282…
In a significant case of cryptocurrency fraud, the U.S. Attorney's Office for the District of Connecticut has forfeited over $600,000 in Tether (USDT) linked to a phishing scam that targeted a Ledger hardware wallet…
Trenton Richard Johnston, a Canadian teen, stole over $13 million in cryptocurrency through social engineering scams. He impersonated employees from Google and Trezor to gain access to victims' crypto accounts. Johnston…
Two vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-21962 and CVE-2026-24061) have been flagged as actively exploited in zero-day attacks. A single IP address is responsible for over 83% of exploitation…
Cryptocurrency hardware wallet users, specifically those using Ledger and Trezor devices, are facing a new phishing campaign involving physical letters. These letters impersonate official communications from the…