top of page

News

Public·4 members

Jake Geier
Jake Geier

DOJ, FBI Seize Domains Powering Chinese State-Sponsored "QScan" and "QTRouter" Hacking Platforms


What:

  • DOJ and FBI executed court-authorized seizures of domains hard-coded into two hacking platforms, "QScan" and "QTRouter," disabling both tools since the domains were essential for their communication and authentication functions as described in court documents unsealed in the Southern District of California U.S. Department of Justice

  • The platforms were created and operated by a PRC state-sponsored group known as "QTFY," employed by China-based Nanjing Xinjiuwei Network Technology Company — this attribution comes directly from unsealed court documents, not inference U.S. Department of Justice

  • QTFY allegedly sold hacking services to customers including China's Ministry of State Security and the People's Liberation Army Bitcoin News

  • The two platforms performed different functions within an integrated reconnaissance, exploitation, and traffic-obfuscation system Bitcoin News


9 Views
Jake Geier
Jake Geier

#StopRansomware Recap: Medusa RaaS Has Hit 300+ Critical Infrastructure Victims — Here's the Playbook


❓What:

  • Joint FBI/CISA/MS-ISAC advisory (AA25-071A, originally published March 2025) detailing Medusa ransomware-as-a-service (RaaS) TTPs from FBI investigations through February 2025

  • Medusa has operated since June 2021, evolving from a closed operation to an affiliate model, and has impacted over 300 victims across critical infrastructure sectors including medical, education, legal, insurance, technology, and manufacturing

  • CISA explicitly notes Medusa is unrelated to the MedusaLocker ransomware variant or the Medusa mobile malware — a common naming mix-up worth correcting when this comes up

  • Initial access comes via recruited initial access brokers using phishing and exploitation of unpatched CVEs, specifically the ScreenConnect authentication bypass (CVE-2024-1709) and the Fortinet EMS SQL injection flaw (CVE-2023-48788)


18 Views
Jake Geier
Jake Geier

ShinyHunters Weaponize Oracle PeopleSoft Zero-Day, Hit Higher Ed Hardest

❓What:

  • ShinyHunters (tracked by Mandiant as UNC6240) exploited an unpatched RCE flaw in Oracle PeopleSoft PeopleTools, CVE-2026-35273 (CVSS 9.8), between May 27 and June 9, 2026 — before Oracle's advisory landed on June 10, making it a true zero-day for the entire window

  • The flaw sits in the Environment Management Hub (PSEMHUB) component and requires no authentication or user interaction — just HTTP network access to the exposed endpoint

  • Affects PeopleTools 8.61 and 8.62; Oracle says older, unsupported versions are likely vulnerable too

  • The intrusion came to light because attackers left their own staging servers exposed — open directories running Python SimpleHTTP on port 8888, discovered by researcher @nahamike01 and triaged by Mandiant


15 Views
Jake Geier
Jake Geier

Coldcard Firmware Bug Traced to $88.6M in Bitcoin Thefts Across 4,500+ Addresses


❓What:

  • A firmware integration error from March 2021 in Coinkite's Coldcard hardware wallet caused seed generation to route through a deterministic software PRNG instead of the device's STM32 hardware RNG, on five affected models/tracks.

  • Block traced the root cause to a production config flag (MICROPY_HW_ENABLE_RNG) that checked whether a macro existed rather than whether it was enabled, silently binding builds to MicroPython's weak Yasmarang fallback, seeded only from chip UID and timer state at init with no further entropy collected.

  • Galaxy Research mapped an initial sweep of 1,196 addresses in 41 minutes on July 30, draining 1,082.65 BTC (~$70.2M at the time); two additional suspected waves have since raised the total to 1,367.05 BTC (~$88.6M) across 4,585 addresses.

  • Coinkite shipped emergency firmware on July 31 for all affected models, but patching does not repair seeds already generated on vulnerable firmware.


12 Views
bottom of page