Artículos Relacionados con Vulnerabilities

El Centro de Noticias de HTX ofrece los artículos más recientes y un análisis profundo sobre "Vulnerabilities", cubriendo tendencias del mercado, actualizaciones de proyectos, desarrollos tecnológicos y políticas regulatorias en la industria de cripto.

Beyond Private Keys: From Wallets and L2 to Supply Chains, How to Guard the Security Perimeter of Web3?

Beyond Private Keys: Securing Web3's Expanding Attack Surface from Wallets to L2s and Supply Chains The crypto space faced a wave of security incidents in June, with over $75 million lost across 40 major attacks. These breaches highlighted risks beyond private key theft, exposing vulnerabilities across the entire user interaction chain. Wallet security was compromised not through stolen seed phrases, but via a critical flaw in the Cardano wallet SecondFi's signing implementation. This bug allowed attackers to potentially derive private keys from publicly visible signature data, emphasizing that wallet security depends on correct cryptographic implementation, ideally in open-source, auditable code. Layer-2 networks also revealed complex trust chain risks. Attacks on legacy Aztec deployments exploited inconsistencies in proof systems, showing that a valid zero-knowledge proof is only as secure as its underlying rules. Another attack on Taiko's SGX-based prover stemmed from a leaked signing key and inadequate verification checks. Furthermore, a technical glitch halted Base's block production, underscoring that L2 security encompasses network availability and reliable user exit paths as much as asset safety. Finally, the Polymarket incident demonstrated that even audited smart contracts are not immune. A compromised third-party supplier led to a malicious script being injected into the platform's frontend, resulting in user fund losses. This "supply chain attack" shows that the security of the entire interaction path—from the webpage to the wallet signature—is critical. The conclusion is clear: Web3 security now involves safeguarding the entire journey from transaction intent to on-chain settlement. Users must adopt layered security habits: isolating long-term holdings, using dedicated wallets for daily interactions, scrutinizing transaction details before signing, and managing authorizations cautiously. Defense must evolve from protecting a single point (the private key) to securing a complete chain of interactions.

marsbit07/09 10:44

Beyond Private Keys: From Wallets and L2 to Supply Chains, How to Guard the Security Perimeter of Web3?

marsbit07/09 10:44

Mythos Report Released: Billions of Devices Worldwide Exposed, 10,000 Critical Vulnerabilities Uncovered in 30 Days

The first report from Anthropic's "Project Glasswing" reveals staggering results from its secret initiative using the next-generation AI model, Claude Mythos Preview. In just 30 days, collaborating with roughly 50 global tech giants and critical infrastructure developers, Mythos identified over 10,000 high or critical-severity software vulnerabilities. It demonstrated an extremely low false-positive rate, even outperforming human experts, and successfully intercepted a $1.5 million bank fraud in progress. Key findings include uncovering 2,000 bugs in Cloudflare's core systems, fixing 271 critical vulnerabilities in Firefox 150 (ten times more than previous methods), and discovering a 27-year-old hidden bug in OpenBSD's codebase. The AI even autonomously constructed full attack chains for some exploits. Mythos also scanned over 1,000 essential open-source projects, identifying 23,019 total vulnerabilities, with 6,202 rated high/critical by the AI. Independent verification confirmed a 90.6% true-positive rate, validating 1,094 severe vulnerabilities. A critical case involved wolfSSL, a cryptography library used by billions of devices, where Mythos found a flaw allowing perfect digital certificate forgery. This unprecedented discovery speed has created a new crisis: human developers are overwhelmed and cannot patch vulnerabilities fast enough. In response, Anthropic is rolling out defensive tools like "Claude Security" to auto-generate patches and releasing frameworks to help security teams automate code review and threat modeling. Due to its immense power and potential for weaponization if misused, Anthropic is delaying Mythos's public release until robust safety measures are established. The company urges the industry to shorten patch cycles, enforce updates, and strengthen security fundamentals. The project signals a paradigm shift where AI could eventually make critical code vastly more secure, though the transition period poses significant challenges for human defenders.

marsbit05/25 00:09

Mythos Report Released: Billions of Devices Worldwide Exposed, 10,000 Critical Vulnerabilities Uncovered in 30 Days

marsbit05/25 00:09

活动图片