GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Hackers Exploit macOS Screen Sharing Vulnerability to Gain Root Access and Mine Monero

Odaily News: The Dutch National Cyber Security Centre (NCSC) has reported that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to take control of devices and install Monero mining programs. Multiple systems with port 5900 exposed to the internet have been compromised, with attackers gaining root access. The vulnerability, tracked as CVE-2026-65400, has a severity score of 7.1 out of 10. It stems from a state management error in the authentication process, allowing remote attackers to bypass login verification without valid credentials. Public proof-of-concept code has already been circulated. Apple has addressed the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing the Screen Sharing service directly to the internet. (Decrypt)

French Tax Data Breach Affects Nearly 678,000 People, Potentially Heightening Violent Attack Risks Against Crypto Holders

Odaily News: The French Finance Minister has confirmed that hackers breached the systems of the French Public Finance Directorate in late June and stole taxpayer data belonging to individuals and businesses. According to FrenchBreaches, a platform that tracks cyberattacks in France, this incident affects approximately 678,437 people, roughly 1% of France's population, though the exact number is still under investigation and has not been finalised.The compromised data reportedly includes sensitive information such as names, dates of birth, home addresses, phone numbers, email addresses, tax identification details, and income data. Among those affected, nearly 27,000 individuals had taxable income of at least €100,000, 386 exceeded €1 million, and another 8 surpassed €10 million.Reports indicate that the database has been listed for sale on dark web marketplaces for several thousand euros. The attacker, going by the name ZeroBytes, claims to have extracted the records using an internal search tool before being detected and having access cut off.The incident has raised concerns within the crypto industry, as France has seen a noticeable increase in "wrench attacks" targeting crypto holders in recent years. If high-income individuals' addresses and contact details are exposed, it could provide criminals with a more precise list of targets.

BTCPay Server Temporarily Restricts Public Remote Connections to LND Nodes, Vulnerability Causes Credential Leakage and Fund Theft

Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.

BitGo CEO Issues Public Challenge to Anthropic, Claims 100 BTC Deposited in Public Address

BitGo CEO Mike Belshe posted on social media stating that rather than hyping the narrative of "creating a hacker monster," it is better to conduct real verification. He stated that he has deposited 100 Bitcoins into a BitGo wallet, made the wallet address public, and issued a public challenge to Anthropic.