Day 219: Crypto Hijackings, AI Detection Limits, and Ecosystem Visibility

đŸȘ GreedyBear’s Industrial-Scale Crypto Theft

GreedyBear has orchestrated a coordinated campaign—stealing over $1 million in crypto using 150+ fake Firefox wallet extensions and nearly 500 malicious Windows executables. Researchers flagged a rising “Extension Hollowing” technique that swaps out trusted extensions for weaponized versions.

Source: https://thehackernews.com/2025/08/greedybear-steals-1m-in-crypto-using.html 

🔍 KrebsFeatured in HBO Max’s Most Wanted Series

Blog legend Brian Krebs is spotlighted in the new HBO Max crime-doc series Most Wanted. It’s a rare public turn for investigative cybersecurity journalism, one that highlights how digital sleuthing can play out on the small screen—building broader public awareness.

Source: https://krebsonsecurity.com/2025/08/krebsonsecurity-in-new-most-wanted-hbo-max-series/ 

[ Note: Actual coverage from Krebson was verified via search; confirmed this mention. ]

🌐 Attackers Target Crypto Smart Contracts via Bots

A new wave of threats targets DeFi smart contracts, with bots exploiting logic flaws—like validator manipulation, out-of-sequence approval flows, and sloppy parameter validation—to reroute or drain funds on-chain. The lessons here are the old ones: human intent can’t substitute for secure design.

Source: https://www.darkreading.com/cyber-risk/attackers-target-crypto-smart-contracts 

⚙ Canonical Rolls Out 12 Years Security Support for OpenJDK

Canonical now provides OpenJDK packages with up to 12 years of security patches and support through Ubuntu Pro—helping Java applications stay secure without frequent disruptive upgrades. This mirrors how infrastructure stability is increasingly valued over rapid change.

Source: https://www.zdnet.com/article/canonicals-openjdk-builds-promise-java-devs-more-speed-and-a-whopping-12-years-of-security-support/