DeTracker Security Feed

$1.0B lost this week $93.7B lost in 30 days $94.9B lost this year

🚨 SlowMist TI Alert 🚨 MemTensor's AI memory tooling has been compromised: MemoryOS (PyPI), the company's open-source long-term memory library for LLM and AI agents, and memtensor/memos-cloud-openclaw-plugin (npm), the official plugin connecting it to the OpenClaw agent https://t.co/QQMr3AY6YQ

MemTensor's AI memory tooling, including the MemoryOS library (PyPI) and the memtensor/memos-cloud-openclaw-plugin (npm), has been compromised. This affects their open-source long-term memory library for LLM and AI agents and its official plugin for the OpenClaw agent.

Source: SlowMist Team (opens in a new tab)

#MemoryOS #memos-cloud-openclaw-plugin

Crypto casinos might get doxxed after Curaçao regulator hacked

Curaçao's gambling regulator, the CGA, announced on September 17 that its online gaming portal was hacked. The extent of the breach is still under investigation, but users speculate that sensitive data of crypto casino operators, potentially including personal information and KYC details, may have been compromised and could be leaked.

Source: Protos (opens in a new tab)

#1xBet #Rollbit #Stake

Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager

A supply chain attack has been identified where a malicious PHP package, visanduma/nova-two-factor, injects code into Laravel Nova extensions. This code queries Ethereum transactions to find C2 server IP addresses and then downloads a cross-platform credential stealer targeting browser accounts, crypto wallets, and developer credentials. There is currently no evidence of successful theft.

Source: SlowMist Medium (opens in a new tab)

#LaravelNova

Revolut customers’ sensitive data exposed in phishing attack that fooled email security checks

Revolut experienced a data breach where a sophisticated phishing attack, impersonating a government agency, bypassed email security protocols (SPF, DKIM, DMARC) and tricked the company into handing over sensitive customer data, including identity documents and Bitcoin transaction histories. No customer funds were stolen, and Revolut has notified law enforcement and regulators.

Source: Crypto Briefing (opens in a new tab)

#Revolut

🚨 Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft SlowMist Security Team identified a campaign masquerading as a free VPS service. The landing page at event[.]polarnode[.]vip is a decoy that silently loads lk[.]js and screens for iPhone Safari on iOS 18.4–18.6.2. https://t.co/1j7mPDr0vI

SlowMist Security Team identified a campaign targeting iOS Safari users on specific versions (18.4–18.6.2) via a fake VPS service landing page. The decoy page loads JavaScript that screens for iPhones, potentially leading to asset theft from the DarkSword wallet.

Source: SlowMist Team (opens in a new tab)

#DarkSword