domain – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 14 May 2025 03:32:19 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 domain – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Curve Finance moves to new domain after DNS attack exposes security risks https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/ https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/#respond Wed, 14 May 2025 03:32:18 +0000 https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/

Curve Finance is moving permanently to a new web domain following a targeted DNS attack that exposed users to phishing risks.

On May 13, the DeFi protocol confirmed that it will operate on Curve.finance, replacing the compromised Curve.fi.

The protocol explained that it was making the move because of the prolonged downtime and limited support from .fi domain registrars.

It stated:

“[The] .fi [domain] will be down for too long / no point of moving back. Also registrars who can hold .fi are somewhat not as great as those who can deal with .finance.”

On May 12, hackers hijacked the DNS records for Curve.fi, redirecting visitors to a malicious website that mimicked the protocol’s interface. This fake site attempted to trick users into signing wallet-draining transactions.

Following the incident, Curve said that the issue was contained at the DNS level and that no internal systems were breached.

However, the compromised website was left on for several hours as the domain registrar, iwantmyname, failed to respond to community complaints.

Curve said:

“[The registrar’s] response time is totally unacceptable: we need access to curve [.] fi taken away from hackers and the incident to be investigated.”

Speaking on this, Yu Xian, the founder of blockchain security firm Slowmist, highlighted the risk that the issue could have caused, noting that:

“The phishing gang [was] playing dirty tricks at the front end with fake wallet pop-up scams, directly fishing for mnemonic phrases… I have to say, this is pretty sleazy.”

The compromised domain name has been frozen since the attack.

Curve’s security challenges

In 2022, the protocol suffered a similar DNS hijack, which led to user losses totaling approximately $530,000. Notably, the firm was using the same registrar, iwantmyname, at the time of the attack.

Meanwhile, the recent DNS attack comes just over a week after a separate security event in which a hacker temporarily took over Curve’s X account.

On May 5, a hacker took over the platform’s social media handle to post phishing links. The team regained control of the account quickly and said no user funds were impacted.

Meanwhile, security experts emphasized that the back-to-back incidents show that attackers are shifting focus from code exploits to infrastructure-based vulnerabilities.

This year, the crypto industry has lost around $2 billion to malicious actors who have exploited centralized exchanges like Bybit and several DeFi protocols.

Mentioned in this article
]]>
https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/feed/ 0 36101
Hijacked Microsoft Stream classic domain “spams” SharePoint sites https://earlybirdsinvest.com/hijacked-microsoft-stream-classic-domain-spams-sharepoint-sites/ https://earlybirdsinvest.com/hijacked-microsoft-stream-classic-domain-spams-sharepoint-sites/#respond Fri, 28 Mar 2025 05:18:28 +0000 https://earlybirdsinvest.com/hijacked-microsoft-stream-classic-domain-spams-sharepoint-sites/

Microsoft

The legacy domain for Microsoft Stream was hijacked to show a fake Amazon site promoting a Thailand casino, causing all SharePoint sites with old embedded videos to display it as spam.

Microsoft Stream is an enterprise video streaming service that allows organizations to upload and share videos in Microsoft 365 apps, such as Teams and SharePoint.

Video content hosted on Microsoft Stream was accessed or embedded through a portal at microsoftstream.com.

In September 2020, Microsoft announced they were deprecating the Microsoft Stream classic service and moving it into SharePoint.

Organizations were told to migrate their Microsoft Stream videos to the new platform by April 2024, when the service was retired.

Microsoft Streams classic domain hijacked

Today, the Microsoft Streams classic domain, microsoftstream.com, was hijacked to display a website imitating Amazon that acts as a phishing page for a Thai online casino, as shown below.

Microsoftstream.com site showing a spam site
Microsoftstream.com site showing a spam site
Source: Archive.org

It is unclear if the domain was hijacked or DNS modified to show the news site, but WHOIS records show that a change was made to the domain on March 27, 2025.

Domain Name: MICROSOFTSTREAM.COM
Registry Domain ID: 2027086511_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.comlaude.com
Registrar URL: http://www.comlaude.com
Updated Date: 2025-03-27T02:46:29Z
Creation Date: 2016-05-09T22:38:37Z
Registry Expiry Date: 2025-05-09T22:38:37Z
Registrar: Nom-iq Ltd. dba COM LAUDE
Registrar IANA ID: 470
Registrar Abuse Contact Email: abuse@comlaude.com
Registrar Abuse Contact Phone: +442074218250
Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
Name Server: NS1-04.AZURE-DNS.COM
Name Server: NS2-04.AZURE-DNS.NET
Name Server: NS3-04.AZURE-DNS.ORG
Name Server: NS4-04.AZURE-DNS.INFO

As a result of the hijack, SharePoint servers that still had embedded videos from the classic microsoftstream.com domain, were now seeing this spam page in pages.

“This afternoon, a user reported a suspicious website on our intranet, that is using microsoftstream.com. After some analysis, it turns out the domain is currently redirecting to a sketchy website signed by ‘Ibiza99’,” reported a SharePoint admin on Reddit.

“Here’s an interesting one for you all. I just got a call that our SharePoint site was showing spam instead of embedded videos. Interesting, I thought. I wonder how that could happen,” another Reddit thread explained.

“So I jumped on to see the issue, site is using embedded video from an aspx page on the SharePoint layout. It is definitely showing spam.”

Earlier today, the domain was shut down again, blocking the spam page from appearing in SharePoint.

“We are aware of these reports and have taken appropriate action to further prevent access to impacted domains,” Microsoft told BleepingComputer when asked about the incident.

However, Microsoft did not share further information about how the domain was hijacked.

Thankfully, the threat actors behind this hijack did not attempt to conduct a more harmful campaign, such as distributing malware through fake software updates or other messages that would have been displayed on SharePoint servers.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/hijacked-microsoft-stream-classic-domain-spams-sharepoint-sites/feed/ 0 27630