uz
Feedback
Sable Index

Sable Index

Kanalga Telegram’da o‘tish

contact: @SableIndexManager otc market: @SableIndexOTC discussion: @SableIndexDiscussion

Ko'proq ko'rsatish
Mamlakat belgilanmaganToif belgilanmagan
Ma'lumot yo'q
Obunachilar
+1824 soatlar
+2097 kunlar
+88830 kunlar
Postlar arxiv
[CONFIRMED] Adform removes crypto-address hijacker from ad script Adform confirmed that malicious code compromised a script e
+1
[CONFIRMED] Adform removes crypto-address hijacker from ad script Adform confirmed that malicious code compromised a script embedded in client websites, attempting to replace copied Bitcoin, Ethereum and Tron wallet addresses with attacker-controlled addresses. The adtech company published its notice on July 31 after detecting suspicious activity on July 27. It says the code was removed, the incident contained and affected clients notified. Researcher Kevin Beaumont first reported the compromise on July 30; BleepingComputer independently found an injected payload in an archived Adform script. Adform says visitors to sites using the affected technology on July 27 may have been exposed. The attacker, affected websites, visitor count and financial losses remain unknown. The incident matters because one compromised advertising component can reach many unrelated sites. @SableIndex | @SableIndexDiscussion

[MARKET SHIFT] $102 billion A7A5 stablecoin loses 96% of daily volume Elliptic says coordinated sanctions have sharply reduce
+1
[MARKET SHIFT] $102 billion A7A5 stablecoin loses 96% of daily volume Elliptic says coordinated sanctions have sharply reduced use of A7A5, a ruble-backed token that US and UK authorities linked to sanctions evasion and cybercrime infrastructure. — More than $102 billion moved through A7A5 across approximately 251,000 transactions after its January 2025 launch. — Average daily volume fell to $24.3 million in June 2026, 96% below its July 2025 peak. — No new tokens have been issued since July 2025, while its main exchange, Grinex, has gone offline. — A7A5 contracts remain operational. It is unknown whether activity will migrate to new exchanges or over-the-counter brokers. @SableIndex | @SableIndexDiscussion

[BREACH ALERT] COLDCARD entropy flaw puts wallet seeds at risk Coinkite confirmed a firmware bug weakened seed generation acr
[BREACH ALERT] COLDCARD entropy flaw puts wallet seeds at risk Coinkite confirmed a firmware bug weakened seed generation across COLDCARD Mk2/Mk3, Mk4/Mk5 and Q releases, and issued hotfixes. Seeds generated before fixed versions remain exposed; updating alone does not repair them. Coinkite published its advisory on July 30 and expanded it on August 1. Galaxy Research mapped 1,196 addresses drained of 1,082.65 BTC (about $70.2 million at transaction time) on July 30, using a shared fee and no-change pattern. The on-chain estimate is independent, but attribution and full scope remain unresolved. Coinkite says users without 50 private dice rolls or a strong, unique BIP-39 passphrase should create a new seed on fixed firmware and migrate carefully. Offline storage did not prevent remote key recovery. @SableIndex | @SableIndexDiscussion

[EXPLAINED] Wallet drainers bypass the code auditors checked An August 1 analysis of ack3’s H1 2026 incident ledger shows how
[EXPLAINED] Wallet drainers bypass the code auditors checked An August 1 analysis of ack3’s H1 2026 incident ledger shows how wallet drainers and other off-chain attacks sidestepped audited smart contracts. Ack3 verified 135 incidents and $939.86 million in attributed losses. The ledger says 46 audited projects were breached through paths outside published audit scopes, causing $680.97 million in losses. One case was Polymarket’s June 25 front-end compromise: malicious third-party code triggered wallet-draining approvals, with losses estimated at $3.1 million. The report is new analysis, not a new attack. It matters because a clean contract audit cannot protect a compromised website, dependency, signing key or cloud account. @SableIndex | @SableIndexDiscussion

[DEVELOPING] Cyberattacks disrupt U.S. water utilities across several states U.S. officials are investigating cyberattacks af
[DEVELOPING] Cyberattacks disrupt U.S. water utilities across several states U.S. officials are investigating cyberattacks affecting water and wastewater operators in multiple states. Some utilities issued boil-water notices or moved to sustained manual operations after attackers locked operators out of internet-exposed PLCs; CISA says the activity is targeting organizations of all sizes. CISA’s July 30 alert, produced with FBI and EPA input, confirms attackers changed PLC passwords and IP addresses, causing operational disruption. On July 31, CNN reported related incidents in roughly six states and said no contamination had been reported. Minnesota authorities provided the first public indication; The New York Times first reported Iran as a possible suspect. No agency has attributed the campaign, confirmed a single actor, or published a complete victim list. Iran remains only one investigative theory, and officials have warned about false flags. This is new activity, although separate Iran-linked intrusions hit U.S. industrial sites earlier in 2026. @SableIndex | @SableIndexDiscussion

[BREACH ALERT] Hijacked hotel Wi-Fi redirects travelers to fake updates Microsoft disclosed on July 31 that attackers are man
[BREACH ALERT] Hijacked hotel Wi-Fi redirects travelers to fake updates Microsoft disclosed on July 31 that attackers are manipulating DNS and HTTP traffic on compromised hospitality Wi-Fi networks in several countries. Captive portals redirected travelers to fake browser or operating-system updates delivering CornFlake, a Windows remote-access trojan capable of stealing credentials and session tokens, logging keystrokes, and recording audio and video. Microsoft says it has observed the ongoing CaptiveCrunch campaign since early May and attributes it to Storm-2945, assessed as a Midnight Blizzard sub-cluster. ReliaQuest first documented part of the DNS-poisoning activity on July 23; The Hacker News reported Microsoft’s expanded findings on August 1. Governments attribute the broader Midnight Blizzard group to Russia’s SVR, but the campaign-specific link remains Microsoft’s assessment. No affected hotel, country, portal provider or victim total has been named. The initial gateway compromise remains unknown, and public reporting does not establish how many redirects resulted in malware execution or stolen accounts. @SableIndex | @SableIndexDiscussion

[DEVELOPING] New York sues Kalshi over alleged illegal gambling New York filed suit against prediction-market operator Kalshi
[DEVELOPING] New York sues Kalshi over alleged illegal gambling New York filed suit against prediction-market operator Kalshi on July 31, seeking to halt its activities in the state, recover alleged illegal gains, obtain restitution and impose civil penalties. Authorities allege the platform offers unlicensed gambling through contracts on sports, elections and other events. Attorney General Letitia James and Governor Kathy Hochul announced the action first; the court petition is public. Cointelegraph independently reported the filing and quoted Kalshi, which argues that states cannot shut down a federally licensed exchange. Kalshi also operates tokenized prediction markets on Solana. The illegal-gambling claim has not been decided by a court, and no amounts for alleged gains, fines or restitution were disclosed. The case is new, but follows an October 2025 cease-and-desist order and Kalshi’s federal challenge. It matters because the outcome could define whether federal commodities oversight overrides state gambling laws for crypto-linked prediction markets. @SableIndex | @SableIndexDiscussion

SABLE INDEX - DAY ONE Sable Index tracks dark-web and cybercrime activity: breaches, ransomware, threat actors, underground markets, fraud, arrests and takedowns. Our standard is simple: claims are not facts. We separate confirmed information from allegations, attribute our sources and correct mistakes openly. We do not publish stolen data, credentials, malware, active illicit links or instructions that facilitate crime. Tips, corrections and partnerships: @SableIndexManager The index starts here.