SEAL exists because security experts chose to share knowledge instead of hoarding it. Your donation keeps that infrastructure running: securityalliance.org/donate
5
6
32
19,181
SEAL Frameworks are now in the @fund_defi OPSeC Repository! AI security, prompt injection, data exfiltration, sandboxing, security awareness, etc. Free, chain-agnostic guidance that builders and policymakers can both use. opsec.defieducationfund.org/…
Better-informed policy is good for everyone building in this space. OPSeC gives our industry a way to make that happen by curating free security resources, hosting educational events, and ensuring technical frameworks reach the policymakers who need them. Learn more: defieducationfund.org/defi-e…
1
9
25
2,482
This is what we hoped teams would do with the SEAL Frameworks: run the checklist, find the gaps, and make a plan to close them. More of this, please. 👇
Noon's has always focused on security. Almost two years live, zero security incidents. That record comes from a rigorous focus on operational security, so we put our operational security through the SEAL Framework Checklist, designed by the team behind @SEAL_911 and here are the results 🧵
1
19
2,083
SEAL weekly stats, 22-29 Sep. We were engaged in 67 incidents. Losses by category: 1) Fake support caller: $8M 2) Protocol compromise: $2.32M + 703 ETH 3) Seed compromise: $6.74M 4) Infrastructure exploit $1.23M 5) Social engineering: $517k 6) Phishing: $267k + 1,358 SOL 7) Malware: $180k
4
8
42
3,376
SINT-69, an uncategorized intrusion set using fake Zoom links. 4 new domains: 03in[.]us 04mweb[.]us 04webr[.]us livecom[.]app
1
3
262
@SEAL_911 is free to anyone who needs it, and stays that way because people fund it. If this week's numbers are useful to you, fund the next one here: securityalliance.org/donate If you require a direct and more detailed data feed from SEAL Intel contact us on our website (link in bio).
4
252
Not only DPRK. A vibe-coded phishing frontend for Microsoft Teams, found in the wild. With the proliferation of capable, unrestricted LLMs, we often observe unaffiliated threat actors deploying fully vibe-coded malware infrastructure. In this example, an endpoint misconfiguration exposed the phishing kit's assets along with the LLM's comments. Interestingly, the threat actor most likely framed the task as a benign development job - a custom video conferencing platform called "Lassy Meet" - traces of which can also be found on the suspicious GitHub organization that also appears to be LLM-automated. However, the comments reveal the intent. IOCs: 223.165.6[.]141 netwitz.zoom01[.]us teams.mlcrosoff[.]com github[.]com/altosecteam-org
1
5
21
3,417
SEAL weekly stats, 15-22 Sep: This week we responded to 62 incidents. Reported losses by category: 1) Protocol compromise $13.71M 2) Other $953k 3) Malware $530k 4) Pig butchering $500k 5) Fake ads $270k 6) Seed compromise $263k + 1.7 BTC and 14.2 ETH (DPRK) Read below for details.
2
7
43
3,393
ClickFix: 10 new domains, $530k. Six used mshta: 5843-cf[.]com 9898-cf[.]com anthropicrbh[.]com gmecoinrbh[.]com nectarbnb[.]com thebitcounfoundation[.]com Never paste what a website tells you to.
1
3
288
@SEAL_911 is free to anyone who needs it, and stays that way because people fund it. If this week's numbers are useful to you, fund the next one here: securityalliance.org/donate If you require a direct and more detailed data feed from @SEAL_Intel contact us on our website (link in bio).
3
251
Welcome @Quantstamp to the SEAL Certifications program! They’re now undergoing accreditation and taking on certification engagements. Details on SEAL Certifications: securityalliance.org/our-wor…
6
5
21
5,339