GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Spanish police arrest 16-year-old suspected of operating crypto ransomware KillSec

Odaily News: Spanish police have arrested a 16-year-old Romanian national in Alicante on suspicion of being the administrator and primary operator of the KillSec ransomware group. Europol stated that law enforcement agencies have seized control of the group's servers and leak site, and preserved at least 110 TB of stolen data.The operation involved searches at 8 residences across Spain, Greece, Romania, and the United Kingdom, investigating approximately 1,000 suspected attacks worldwide, of which about 500 have been confirmed successful. Two other suspects in their 20s were arrested in the UK and Romania respectively, while a Dutch national residing in the UK was indicted and arrested in Puerto Rico, awaiting extradition.KillSec has been active since around 2024, often demanding ransoms in cryptocurrency and carrying out double extortion through encrypted servers and threats to publish stolen data. Investigators are tracing the group's proceeds, including cryptocurrency; Europol's European Cybercrime Centre provided cryptocurrency tracing and digital forensics support. (Decrypt)

UK NCA warns criminals are "innovatively" using crypto assets to launder money

According to Decrypt, the UK National Economic Crime Centre (NECC) stated in its annual report that criminals are "innovatively" leveraging crypto asset products to evade detection and transfer illicit funds at scale, while also highlighting AI alongside cryptocurrencies as an emerging threat method. Crypto assets have been ranked third among the nine priority economic crime areas jointly designated by NECC, the FCA, and the Treasury. NECC stated it will build more proactive, intelligence-driven crypto capabilities to actively identify targets for enforcement action. Previously, the NCA, in collaboration with the US Secret Service, Coinbase, Binance, Kraken, and Tether, conducted "Operation Atlantic," which identified 20,000 phishing attack victims and resulted in the freezing of $12 million in assets this March.

Hackers Exploit macOS Screen Sharing Vulnerability to Gain Root Access and Mine Monero

Odaily News: The Dutch National Cyber Security Centre (NCSC) has reported that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to take control of devices and install Monero mining programs. Multiple systems with port 5900 exposed to the internet have been compromised, with attackers gaining root access. The vulnerability, tracked as CVE-2026-65400, has a severity score of 7.1 out of 10. It stems from a state management error in the authentication process, allowing remote attackers to bypass login verification without valid credentials. Public proof-of-concept code has already been circulated. Apple has addressed the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing the Screen Sharing service directly to the internet. (Decrypt)

Cambridge Study: US Hosts ~31% of Ethereum Nodes; Over One-Third Nodes Offline Could Impact Finalization

Odaily Odaily A new study by the Cambridge Centre for Alternative Finance reveals that approximately 31% of Ethereum node activity is located in the United States, with another 39% distributed across EU countries excluding the UK, indicating that the geographic distribution of Ethereum nodes remains relatively concentrated in Western nations.Lead researcher Alexander Neumuller stated that while node distribution is not currently concentrated in any single country, it is heavily reliant on a few major cloud service providers, including Hetzner, Amazon AWS, and OVH. Notably, the Ethereum network does not require half of its validators to fail for problems to arise. If more than one-third of validators go offline simultaneously, the network may be unable to finalize block checkpoints (finalization). Neumuller pointed out that nodes and validators do not have a one-to-one correspondence; a single node may run multiple validators. Therefore, it is currently impossible to precisely assess the actual impact on the validator network from the failure of a specific node or service provider.Furthermore, the study reassessed the energy consumption of Ethereum following The Merge. Data shows that Ethereum's current annual energy consumption is approximately 7.9 GWh, equivalent to a continuous power draw of about 1 MW. This represents only about 0.02% of pre-merge levels, a reduction of approximately 99.98%. Currently, over 56% of the energy used by the Ethereum network comes from sustainable sources, exceeding the global average.The study also noted that client software diversity is another potential risk. If a dominant client software has a vulnerability, it could affect a large number of network participants. The report was published by the Cambridge Centre for Alternative Finance and supported by the Ethereum Foundation. (The)

UK Financial Regulator Urgently Assesses Risks of Anthropic’s Latest AI Model

Officials from the Bank of England, the Financial Conduct Authority, and the Treasury are consulting with the National Cyber Security Centre to examine potential vulnerabilities in critical IT systems revealed by Anthropic’s latest model.