Related Threat Clusters
-
DarkSword iOS Exploit Chain Targets Mobile Devices Globally
The Google Threat Intelligence Group has identified DarkSword, a full-chain iOS exploit affecting versions 18.4 to 18.7. This exploit leverages multiple zero-day vulnerabilities, including CVE-2025-31277 and…
2 articles · Updated July 11, 2026 -
Coruna and DarkSword iOS Exploit Kits Targeting Users Globally
The Coruna and DarkSword iOS exploit kits, initially limited to nation-state actors, are now being widely adopted by organized cybercriminals. iVerify has tracked around 17,000 domains associated with second-generation…
3 articles · Updated August 10, 2026 -
Malicious LLM Proxy Routers Compromise AI Security
A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…
2 articles · Updated April 15, 2026 -
Kraken User Loses $18.2M in Social Engineering Crypto Attack
A Kraken user has lost approximately $18.2 million in a suspected social engineering attack, as reported by blockchain investigator ZachXBT on March 31, 2026. The attack involved manipulation techniques, likely phishing…
3 articles · Updated March 31, 2026 -
Malicious Chrome and Edge Extensions Target Crypto Users
A coordinated malware campaign has compromised 19 browser extensions—18 for Chrome and 1 for Edge—designed to steal cryptocurrency wallet secrets and login credentials. The campaign, named 'Superior,' has been active…
9 articles · Updated August 28, 2026 -
Polkadot Hyperbridge Exploit: 1 Billion DOT Minted and Sold
On April 13, 2026, a vulnerability in the Hyperbridge gateway contract on Ethereum allowed an attacker to mint 1 billion unauthorized Polkadot (DOT) tokens. The exploit was facilitated by forging messages to gain…
23 articles · Updated April 13, 2026 -
BonkDAO Suffers $20 Million Treasury Exploit from Governance Attack
BonkDAO, associated with the $BONK meme coin on Solana, experienced a governance exploit that drained approximately $20 million from its treasury. The attack involved a malicious governance proposal that was passed…
7 articles · Updated July 9, 2026 -
Jinkusu Deepfake Tool Compromises KYC Security in Crypto and Banking
A new AI cybercrime tool named JINKUSU CAM is being sold by a threat actor known as 'Jinkusu' to bypass Know Your Customer (KYC) checks on major crypto exchanges like Binance, Coinbase, and Kraken, as well as banking…
6 articles · Updated April 6, 2026 -
Kraken Ransomware Targets Windows, Linux, and VMware ESXi Systems
The Kraken ransomware has been identified as a significant threat, targeting enterprise environments running Windows, Linux, and VMware ESXi systems. Organizations utilizing these platforms are at risk of data breaches…
3 articles · Updated November 14, 2025 -
CertiK Launches Invite-Only Platform to Enhance Web3 Security Amid Rising Exploits
On July 1, 2026, CertiK launched CertiK Hunt, an invite-only platform aimed at improving Web3 security by connecting vetted researchers with blockchain projects for ongoing vulnerability testing. This initiative…
4 articles · Updated July 2, 2026
Recent Intelligence Reports
- Chrome Extension Malware Campaign Hits 19 Browser Add Ons — Coingabbar · August 29, 2026
- Darksword — www.lookout.com · August 13, 2026
- Solana Meme Coin Bonk Treasury Drained of $20 Million in 'Malicious' Governance Attack — Decrypt.Co · July 6, 2026
- CertiK Launches Invite Only Hunt Platform for Elite Security Researchers — Hackernoon · July 2, 2026
- Malicious LLM proxy routers found in the wild — News.Risky.Biz · April 15, 2026
- Kraken faces extortion threat over rogue employee breach — Americanbanker · April 15, 2026
- Crypto — Bleepingcomputer · April 14, 2026
- Kraken Faces Extortion Attempt Over Insider Data Incidents — Bitbo · April 14, 2026