Cybersecurity – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 02 Aug 2025 08:37:13 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Cybersecurity – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hackers Attack Android Users’ Bank Accounts As Rapidly Improving Malware Steals PIN Codes and Login Credentials, Unlocks Patterns and Records Screens: Cybersecurity Researchers https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/ https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/#respond Sat, 02 Aug 2025 08:37:13 +0000 https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/

A rapidly evolving bank malware now has far greater capabilities to infect Android devices and steal personal information, according to researchers.

The cybersecurity firm Zimperium says the so-called DoubleTrouble trojan “has rapidly evolved in both its distribution methods and capabilities,” and is now permeating channels on the social platform Discord.

“In its latest evolution, the malware has integrated several new and advanced features, significantly expanding its capabilities beyond earlier iterations. These enhancements enable more effective data theft, device manipulation, and evasion techniques.

The new functionalities include: displaying malicious UI overlays to steal PIN codes or unlock patterns, comprehensive screen recording capabilities, the ability to block the opening of specific applications, and advanced keylogging functionality.”

Researchers say the malware convinces users to download it by masking itself as an extension or an add-on, and it uses the Google Play icon to appear trustworthy.

It also manipulates device functionality by exploiting Android’s Accessibility Services, allowing it to block legitimate banking or security apps with misleading “system maintenance” prompts.

In addition, the malicious software simulates user actions like taps and swipes, allowing attackers to remotely control infected devices and steal data, including passwords and banking details, with alarming precision.

The trojan’s attacks are ongoing, primarily targeting users in Europe through phishing websites and Discord-hosted APKs. Specific victim counts remain unknown at time of publishing.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/feed/ 0 51025
Billion-Dollar Bank Handing Thousands of Dollars To Data Breach Victim After Cybersecurity Incident Exposed Names, Social Security Numbers, Account Details https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/ https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/#respond Sat, 05 Jul 2025 18:07:43 +0000 https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/

Victims of a bank data breach are set to receive up to $3,000 each after a settlement was reached in a class action lawsuit.

According to the settlement administration portal, impacted customers at Arizona-based Evolve Bank & Trust who file a claim and provide documentary evidence of losses resulting from the data breach stand to receive up to $3,000.

A flat cash payment of $20 will also be available but claimants can only choose one or the other, not both.

“In addition to selection one of the Cash Payment options, Settlement Class Members may elect one (1) year of monitoring that will provide the following benefits: Credit Monitoring, real-time alerts, and insurance coverage for up to $1,000,000 for identity theft.”

Claims must be filed by October 30th. A final approval hearing of the settlement will be held on November 14th.

The lawsuit against Evolve Bank & Trust was filed in January and alleges that cybercriminals infiltrated the billion-dollar lender’s information systems and gained access to sensitive and confidential information.

In a notice to customers in July of 2024, Evolve Bank said the data breach had occurred between February and May of 2024.

“…it appears the criminals downloaded information from our databases and a file share that included names, Social Security numbers, bank account numbers, and contact information for most of our personal banking customers, as well as customers of our Open Banking partners. We have also learned that personal information relating to our employees was also likely affected.”

Evolve Bank & Trust, which started as First State Bank in 1925, is headquartered in West Memphis, Arizona. It boasts of around $1.6 billion in total assets and has five branches in the US.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/feed/ 0 45953
US Banks ‘Deeply Concerned’ About Cybersecurity Risk Following Attack on Top Financial Regulator https://earlybirdsinvest.com/us-banks-deeply-concerned-about-cybersecurity-risk-following-attack-on-top-financial-regulator/ https://earlybirdsinvest.com/us-banks-deeply-concerned-about-cybersecurity-risk-following-attack-on-top-financial-regulator/#respond Thu, 12 Jun 2025 15:50:23 +0000 https://earlybirdsinvest.com/us-banks-deeply-concerned-about-cybersecurity-risk-following-attack-on-top-financial-regulator/

Trade associations representing banks and financial firms are worried about the cybersecurity risk management practices at federal regulatory agencies.

Officials at the American Bankers Association, the Bank Policy Institute, the Managed Funds Association and the Securities Industry and Financial Markets Association recently penned a letter to US Treasury Secretary Scott Bessent outlining their concerns, specifically highlighting the recently disclosed cybersecurity breach of Office of the Comptroller of the Currency’s (OCC) email system.

“To address similar challenges across all financial regulatory agencies, we encourage the Administration to implement the following recommendations:

(1) ensure agencies are held to the same or substantively similar security and data protection standards expected of financial institutions to include transparency and accountability for upholding these standards;

(2) enable firms to retain and house their own sensitive data needed for regulatory engagement;

(3) improve regulatory agencies’ incident response processes to include notification and communication with regulated institutions; and

(4) consolidate and streamline examinations conducted by the financial regulatory agencies to reduce the amount of data being shared.”

The trade associations note that “nation-state cyber adversaries” are increasingly targeting federal agencies, including financial regulators.

In regard to the OCC, hackers accessed nearly 150,000 emails after first compromising the regulator’s system back in May 2023, Bloomberg reports.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/us-banks-deeply-concerned-about-cybersecurity-risk-following-attack-on-top-financial-regulator/feed/ 0 41630
Microsoft unveils free EU cybersecurity program for governments https://earlybirdsinvest.com/microsoft-unveils-free-eu-cybersecurity-program-for-governments/ https://earlybirdsinvest.com/microsoft-unveils-free-eu-cybersecurity-program-for-governments/#respond Thu, 05 Jun 2025 00:45:21 +0000 https://earlybirdsinvest.com/microsoft-unveils-free-eu-cybersecurity-program-for-governments/

Microsoft

Microsoft announced in Berlin today a new European Security Program that promises to bolster cybersecurity for European governments.

The program expands to Microsoft’s existing Government Security Program, which is free to all European Union countries, including accession states, European Free Trade Association (EFTA) members, the UK, Monaco, and the Vatican.

The tech giant noted that the program primarily aims to thwart attacks from state-backed actors in Russia, Iran, China, and North Korea, who have escalated their operations against the EU.

“Microsoft continues to observe persistent threat activity targeting European networks from nation-state actors, with Russian and Chinese activity being particularly prolific in Europe,” reads the announcement.

“Nation-state actors, including those engaging in malicious activity from Iran and North Korea, are predominantly pursuing espionage objectives in Europe through credential theft or the exploitation of vulnerabilities to gain access to corporate and government networks,” mentions Microsoft in another part.

State-sponsored attacks targeting Europe
State-sponsored attacks targeting Europe
Source: Microsoft

AI at the center of cyber-defense

The key element of the program is the use of artificial intelligence to create actionable intelligence that will help in the timely detection and blocking of sophisticated attacks.

Microsoft will provide real-time AI-driven threat insights tailored to the needs of each nation, leveraging the program and expanding access to intelligence from the Digital Crimes Unit and Threat Analysis Center.

Moreover, Microsoft will supply updates on foreign influence operations using deepfakes and deliver early warnings and remediation guidance for newly discovered vulnerabilities.

Another important pillar in the new program is strengthening partnerships to identify new threats, develop defense measures, and disrupt cybercrime.

Microsoft will renew and strengthen collaborations with Europol, the CyberPeace Institute, LASR, and the Western Balkans Cyber Capacity Center, and will continue to support the GitHub Secure Open Source Fund. Also, it will work closer with internet service providers to advise on user-level remediation.

Microsoft highlights its recent role in the recent takedown of the Lumma infostealer malware as a clear demonstration of its deepening commitment to protecting Europe’s digital infrastructure.

The info-stealer operation had many infections in the continent, mainly in Spain, France, Poland, Germany, Italy, and the United Kingdom.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/microsoft-unveils-free-eu-cybersecurity-program-for-governments/feed/ 0 40195
3 Top Cybersecurity Stocks to Buy in May https://earlybirdsinvest.com/3-top-cybersecurity-stocks-to-buy-in-may/ https://earlybirdsinvest.com/3-top-cybersecurity-stocks-to-buy-in-may/#respond Mon, 26 May 2025 17:00:34 +0000 https://earlybirdsinvest.com/3-top-cybersecurity-stocks-to-buy-in-may/

When it comes to cybersecurity, I don’t know much about how it works from an experiential perspective. So, I suppose one could say I’m an outsider. But even an outsider like me understands that businesses must invest in cybersecurity in 2025. And I can appreciate that the need for cybersecurity will only get bigger in the coming years.

Research firm Gartner predicts that spending for cybersecurity will increase by 15% in 2025 alone, which is huge when looking at an entire market. Gartner further predicts that the cybersecurity threat will increasingly come from generative artificial intelligence (AI) applications, highlighting how the threat evolves over time. Cybersecurity companies, consequently, must be fast-changing as well.

When it comes to the future of cybersecurity, I believe that CrowdStrike (CRWD 2.82%), Rubrik (RBRK 1.45%), and Palo Alto Networks (PANW 0.43%) are three cybersecurity stocks that investors should consider here in May. Here’s why.

A man works on cybersecurity at a computer.

Image source: Getty Images.

1. CrowdStrike: The top dog

When it comes to cloud-based cybersecurity, CrowdStrike is routinely recognized as a top player in the space. The company provides a subscription platform for its products, providing it with recurring revenue. It completed its fiscal 2025 on Jan. 31. And it ended the year with annualized recurring revenue (ARR) of $4.2 billion, which was up 23% from the end of fiscal 2024.

CrowdStrike’s Falcon platform isn’t a single cybersecurity product but is composed of 29 separate software modules that customers can use to meet their needs. The company is currently modifying its business model with this. Before, customers would select what they wanted and pay the subscription price. Now, customers can agree to a certain level of spending and use it on the module they want.

It’s called Falcon Flex, and the hope is that this will lower the bar when it comes to experimentation with CrowdStrike’s modules. As customers try new modules for the first time, the hope is that they’ll see the value and use them regularly. In other words, CrowdStrike plans to boost growth by making it easier for existing customers to adopt more software modules, which sounds like a good idea to me.

As of the end of its fiscal 2025, only 21% of CrowdStrike’s customers used eight or more of its software modules. Getting its customers to use more modules is quite significant for its long-term growth. The recent launch of Falcon Flex could help it get there, and it’s one reason I like CrowdStrike stock today.

2. Rubrik: The niche up-and-comer

Many investors know about CrowdStrike, but far fewer have heard about Rubrik. That’s understandable. It only went public about 13 months ago, so it’s a new company for most investors. Moreover, with $887 million in trailing-12-month revenue, it’s considerably smaller than other publicly traded cybersecurity companies.

Whereas CrowdStrike tries to prevent attacks, Rubrik gives customers a secure way to prepare for an attack beforehand and get back to normal after it happens. The reality is that even if cybersecurity players stop most attacks, they don’t stop all of them. And the risk of one getting through might only increase with advances in AI.

The good thing about Rubrik’s focus on this aspect of the market is that it’s not a direct competitor with CrowdStrike or others — in fact, it partners with CrowdStrike. This gives the up-and-coming company its own little corner of the market, and it’s growing fast. Like CrowdStrike, Rubrik’s fiscal 2025 ended on Jan. 31. It ended fiscal 2025 with an ARR of just over $1 billion, which was up a strong 39%.

Investors should consider Rubrik stock now, not only because it’s fast-growing. The company also just started generating positive free cash flow. This profitability metric suggests that management can scale its business while maintaining operational excellence. This combination could soon start elevating the attention it receives from the investment community.

3. Palo Alto Networks: The relentless consolidator

Rubrik is a niche player, but even CrowdStrike could be considered niche compared to how broad Palo Alto Networks is with its vision. It has both hardware and software solutions. Its software products can be used on the cloud or on-premises. It’s a large portfolio of products that have been both built and acquired over many years, which makes it one of the best cybersecurity stocks for investors interested in covering all the bases.

Indeed, Palo Alto Networks is always eager to acquire another business — it already acquired one in 2025 by buying Protect AI for $700 million. While there are risks to being a company that makes a lot of acquisitions, the company has historically done it well, and it is paying off with growth. For example, it just completed its fiscal third quarter of 2025, showing good growth in its newer products.

Specifically, Palo Alto Networks grew its ARR for Next-Generation Security by 34% year over year to over $5 billion. And demand for its products overall is promising. In Q3, its remaining performance obligations (its future revenue under contract) grew by 19% to a whopping $13.5 billion. In short, the outlook for this company is as strong as ever, making Palo Alto Networks another cybersecurity stock to consider here in May.

In closing, the subject of valuation for these companies is also important, but that’s a completely different subject from the things that I’ve discussed here. But allow me to say that the valuation for Rubrik stock is far lower than that for CrowdStrike stock, and it’s comparable to the valuation for Palo Alto Networks. But I believe that Rubrik, being a smaller company, has a chance for a better growth rate from here.

Rubrik is probably the riskiest of these three stocks, given its size and newcomer status. But for investors willing to take a shot with a less-proven player, Rubrik might be the best value for long-term investors.

]]>
https://earlybirdsinvest.com/3-top-cybersecurity-stocks-to-buy-in-may/feed/ 0 38433
Google Issues Cybersecurity Alert to US Retailers, Says Hackers Who Paralyzed UK Counterparts Now Targeting American Stores https://earlybirdsinvest.com/google-issues-cybersecurity-alert-to-us-retailers-says-hackers-who-paralyzed-uk-counterparts-now-targeting-american-stores/ https://earlybirdsinvest.com/google-issues-cybersecurity-alert-to-us-retailers-says-hackers-who-paralyzed-uk-counterparts-now-targeting-american-stores/#respond Fri, 16 May 2025 16:34:50 +0000 https://earlybirdsinvest.com/google-issues-cybersecurity-alert-to-us-retailers-says-hackers-who-paralyzed-uk-counterparts-now-targeting-american-stores/

Tech titan Google is warning US retailers about cybersecurity attacks after hackers disrupted UK businesses.

John Hultquist, an analyst at Google’s cybersecurity arm, says that US retailers are now facing cyberattacks involving ransomware and extortion tactics, similar to what UK businesses have just been contending with.

“Shields up US retailers. They’re here.”

Hultquist says the hackers are likely connected to a group known as Scattered Spider, or UNC3944.

Says Google in a blog post,

“Recent public reporting has suggested that threat actors used tactics consistent with Scattered Spider to target a UK retail organization and deploy DragonForce ransomware. Subsequent reporting by BBC News indicates that actors associated with DragonForce claimed responsibility for attempted attacks at multiple UK retailers.”

According to Google, Scattered Spider initially targeted telecommunications-related companies to engage in SIM swap scams but has since expanded its tactics.

“After shifting to ransomware and data theft extortion in early 2023, they impacted organizations in a broader range of industries. Since then, we have regularly observed UNC3944 conduct waves of targeting against a specific sector, such as financial services organizations in late 2023 and food services in May 2024. Notably, UNC3944 has also previously targeted prominent brands, possibly in an attempt to gain prestige and increased attention by news media.”

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/google-issues-cybersecurity-alert-to-us-retailers-says-hackers-who-paralyzed-uk-counterparts-now-targeting-american-stores/feed/ 0 36589
Android users just dodged a bullet as the CVE cybersecurity tracker stays funded https://earlybirdsinvest.com/android-users-just-dodged-a-bullet-as-the-cve-cybersecurity-tracker-stays-funded/ https://earlybirdsinvest.com/android-users-just-dodged-a-bullet-as-the-cve-cybersecurity-tracker-stays-funded/#respond Thu, 17 Apr 2025 00:59:11 +0000 https://earlybirdsinvest.com/android-users-just-dodged-a-bullet-as-the-cve-cybersecurity-tracker-stays-funded/

Most users of technology don’t have to consciously think about security vulnerabilities on their most-used devices, including Android-based products, very often. As long as you update your phone as soon as new security patches are available, you’re usually covered. However, there’s an intricate government-supported program operating to make that all possible, and it almost went dark today.

After roughly 24 hours of uncertainty, the U.S. Cybersecurity and Infrastructure Agency (CISA) announced that it would continue funding the Common Vulnerabilities and Exposures (CVE) on the day its previous contract was set to expire. Today, April 16, a spokesperson for the CISA told The Verge that the agency “executed the option period on the contract to ensure there will be no lapse in critical CVE services.”

But it went down to the wire in a move that could’ve sent the entire globe into a tech security nightmare.

The Google Pixel Watch 3 showing

(Image credit: Michael Hicks / Android Central)

It all has to do with the CVE program, which identifies and tracks security issues in public view, from the point a potential problem is identified to the time when a proper fix is issued. It has nearly 500 partners that include security researchers, open-source developers, and major companies — including big ones like Google, Microsoft, and Apple.

If the CVE program sounds familiar, that’s probably because you’ve seen a CVE code mentioned in an article (like one of the many CVE-related ones on Android Central) or the release notes of an update. They’re also a major part of monthly releases on the Android Security Bulletin. These codes, like CVE-2024-53104, start with CVE followed by the year and a number, and create a universal database to track security flaws across devices, platforms, and companies.

A screenshot of the latest Android Security Bulletin with CVE codes.

A screenshot of the latest Android Security Bulletin with CVE codes. (Image credit: Future / Google)

The CVE program has been active for 25 years, beginning in 1999. It has become invaluable to the security community, serving as a universal way for researchers, developers, companies, and the public to work together to discover and patch crucial vulnerabilities. More importantly, it publicly states whether a vulnerability is believed to have been actively exploited by bad actors.

Android 15 logo on the Galaxy S25 Ultra

(Image credit: Andrew Myrick / Android Central)

Leading security researchers have pointed out the consequences of the CVE program shutting down, like Lukasz Olejnik on X (formerly Twitter).

“The consequence will be a breakdown in coordination between vendors, analysts, and defense systems — no one will be certain they are referring to the same vulnerability,” wrote Olejnik, a scholar with advanced degrees in computer science and information technology law with specializations in privacy. “Total chaos, and a sudden weakening of cybersecurity across the board.”

The crisis has been avoided… for now?

Luckily, it appears that the crisis has been avoided, as the federal government will continue to fund the CVE program for at least the near future. However, the decision coming down to the wire as the Trump administration slashes federal funding across the board puts the CVE program in a more uncertain position now than at any point in its 25-year history.

“The CVE Program is invaluable to the cyber community and a priority of CISA,” the spokesperson said in a statement to The Verge. “We appreciate our partners’ and stakeholders’ patience.”

Android 15 Easter egg on Pixel 9 Pro XL, Pixel 9, and Pixel 9 Pro Fold

(Image credit: Harish Jonnalagadda / Android Central)

But that final green light didn’t come quick enough, as the security world already started making plans to keep the CVE program up and running — even without federal funding. CVE board members created the CVE Foundation, a nonprofit planned for in secret for the past year that would ensure the CVE mission continues.

“CVE, as a cornerstone of the global cybersecurity ecosystem, is too important to be vulnerable itself,” said Kent Landfield, an officer of the CVE Foundation, in a press release. “Cybersecurity professionals around the globe rely on CVE identifiers and data as part of their daily work, from security tools and advisories to threat intelligence and response. Without CVE, defenders are at a massive disadvantage against global cyber threats.”

The foundation explains that it is concerned that having a single government sponsor could create “a single point of failure in the vulnerability management ecosystem.”

The CVE program could be changing as we know it

An orange and blue Android 16 logo on a OnePlus 13

(Image credit: Nicholas Sutrich / Android Central)

The CVE program is a critical part of Android security, and it should be relevant to every single person who touches an Android-based device. Although government funding has been acquired for now, the moves that have been set in motion by the last-minute decision may not be reversed. The CVE Foundation is here, and it might be here to stay.

There’s no word on whether the CVE Foundation will continue to operate now that the CVE program has retained U.S. government funding, but the foundation said more information will be released “over the coming days.” The immediate U.S. government funding doesn’t solve the long-term problem the CVE Foundation has identified — the possibility of having a single point of failure — so there still may be a reason for it to exist.

Regardless of how this all plays out, the decision to fund the CVE program should’ve never come this close to ending a crucial global security program. Most of us have the luxury to not think about device security that often, and it’s programs like the CVE that allow us that privilege.

]]>
https://earlybirdsinvest.com/android-users-just-dodged-a-bullet-as-the-cve-cybersecurity-tracker-stays-funded/feed/ 0 31204
21,899 Bank Customers Affected As US Lender Suffers Cybersecurity Breach, Hacker Taps Social Security Numbers and Other Sensitive Information https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/ https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/#respond Sat, 22 Mar 2025 04:26:39 +0000 https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/

A billion-dollar bank is warning customers after a cybersecurity breach affecting thousands of customers.

In a filing with the Office of the Maine Attorney General, Western Alliance Bank says an unauthorized actor exploited a vulnerability in a third-party file transfer software system it uses.

The breach, which was discovered in late January and happened in October, impacts 21,899 customers, according to the filing.

“Western Alliance learned that an unauthorized actor had potentially accessed some of Western Alliance’s data on January 27, 2025. Our investigation determined that the unauthorized actor acquired certain files from the systems from October 12, 2024, to October 24, 2024…

On February 21, 2025, we determined that the files contained some of your personal information, including your name and Social Security number. The files may have also contained your date of birth, financial account number, driver’s license number, tax identification number, and/or passport, if you provided it to Western Alliance.”

The bank says it has informed law enforcement about the data breach and is offering customers a 12-month complimentary membership to an identity-theft protection service.

Western Alliance Bank currently has approximately $81 billion in total assets, according to the Federal Reserve.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/feed/ 0 26513
Cybersecurity Wake-Up Call – Lessons From Bybit’s $1.5 Billion Breach https://earlybirdsinvest.com/cybersecurity-wake-up-call-lessons-from-bybits-1-5-billion-breach/ https://earlybirdsinvest.com/cybersecurity-wake-up-call-lessons-from-bybits-1-5-billion-breach/#respond Tue, 04 Mar 2025 07:55:16 +0000 https://earlybirdsinvest.com/cybersecurity-wake-up-call-lessons-from-bybits-1-5-billion-breach/
HodlX Guest Post  Submit Your Post

 

As someone with deep experience in cross-chain crypto exchanges within Telegram mini-apps, I’d like to share my insights on the current state of crypto security and key measures to prevent cyber attacks.

The recent hack of the Bybit Exchange on February 21, 2025, has once again highlighted the significant impact of cyber attacks on the cryptocurrency market.

This incident which resulted in the theft of approximately $1.5 billion worth of Ethereum (ETH) stands as the largest digital heist in cryptocurrency history.

Let’s examine some interesting statistics and data surrounding cyber attacks in the crypto space and their consequences.

Scale and frequency of attacks and market impact

The Bybit hack is part of a worrying trend of increasing cyber attacks on cryptocurrency platforms.

In 2024, North Korea-linked hackers alone stole approximately $1.34 billion in 47 incidents, a 102.9% increase from the $660.5 million stolen in 20 incidents in the previous year.

The Bybit hack in 2025 has already surpassed the entire amount stolen by North Korea in 2024 by nearly $160 million.

The immediate market reaction to the Bybit hack demonstrated the volatility that such incidents can cause, including the following.

  • ETH dropped 4.2% from $2,828 to $2,708 within minutes of the announcement.
  • A brief rebound of 3.4% followed, bringing the price back to $2,759.

The initial drop in the ETH price was followed by a quick rebound, fueled by speculation that Bybit would have to buy back ETH on a one-to-one basis to compensate affected users.

Bybit has secured a bridging loan for 80% of the lost ETH, as clarified by Ben Zhou, co-founder and CEO of Bybit, during a live stream.

He also stated that Bybit had no immediate plans to buy large amounts of ETH on the spot market.

This news caused a rapid shift in market sentiment from bullish to bearish, due to concerns that the hacker would sell the stolen ETH and a general increase in risk aversion among investors.

Types of cyber attacks

While previous major hacks have often targeted vulnerabilities in smart contract code or cross-chain bridges, the Bybit incident represents a shift towards targeting the human element.

  • The attackers used social engineering tactics to compromise the exchange’s user interface.
  • They manipulated cold wallet signatories to authorize malicious transactions.

This trend is consistent with research showing a shift from traditional security attacks to more sophisticated methods.

In terms of the amount stolen by type of victim platform, 2024 also showed interesting patterns.

In most quarters between 2021 and 2023, DeFi (decentralized finance) platforms were the main targets of crypto hacks.

It’s possible that DeFi platforms were more vulnerable because their developers tend to prioritize rapid growth and getting their products to market over implementing security measures, making them prime targets for hackers.

Although DeFi still accounted for the largest share of stolen assets in Q1 2024, centralized services were the most targeted in Q2 and Q3.

This shift in focus from DeFi to centralized services highlights the increasing importance of security mechanisms commonly exploited in hacks, such as private keys.

Private key compromises accounted for the largest share of stolen crypto in 2024 at 43.8%.

For centralized services, ensuring the security of private keys is critical as they control access to users’ assets.

User education – A critical component

While exchanges bear significant responsibility for security, user education plays a critical role. Comprehensive education initiatives should equip users with the knowledge to do the following.

  • Create and manage strong, unique passwords
  • Recognize social engineering tactics and phishing attempts
  • Understand the importance of regular backups

In conclusion, the Bybit hack is a stark reminder of the ongoing security challenges in the cryptocurrency space. As the market continues to grow, so too will the methods used by hackers.

It is imperative that the industry stays ahead of the curve by adopting advanced technologies, fostering collaboration and continuously educating users.

By implementing comprehensive security measures and remaining vigilant, we can work towards creating a safer environment for all participants in the crypto ecosystem.


Valeriy Yasakov is the CEO of The One, a pioneering mini app on Telegram designed for crypto trading. A visionary entrepreneur, Valeriy combines technical expertise with strategic foresight to drive advances in decentralized financial and trading solutions through his leadership roles.

 

Check Latest Headlines on HodlX

Follow Us on Twitter Facebook Telegram

Check out the Latest Industry Announcements
 

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any loses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/cybersecurity-wake-up-call-lessons-from-bybits-1-5-billion-breach/feed/ 0 23161