PUBLIC INTELLIGENCE STREAM

Track what actually changed

A verified public-source timeline for security incidents, Web3 attacks, AI, and China internet developments.

Browse the live timeline

This week's selection

Latest selected signals

P0
SlowMist Hacked

AFX Bridge hacked — $24.15M lost

The AFX-operated cross-chain/USDC custody bridge on Arbitrum was exploited. The attacker used compromised validator hot keys to meet the quorum and drain approximately $24.15 million USDC. The funds were bridged to Ethereum and swapped for…

P0
SlowMist Hacked

Ostium hacked — $18.00M lost

Ostium, an RWA-focused perpetuals DEX on Arbitrum, suffered an oracle manipulation exploit. The attacker used a compromised oracle signer key to submit fraudulent future-dated price reports, generating artificial trading profits and draini…

P0
SlowMist Hacked

BonkDAO hacked — $20.00M lost

BonkDAO suffered a governance attack. The attacker spent ~$4M to buy BONK tokens for sufficient voting power and passed a malicious governance proposal (BIP-76) to transfer ~$20M BONK from the treasury to controlled wallets. No smart contr…

P0
SlowMist Hacked

Triple-A hacked — $11.80M lost

Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/cons…

P0
SlowMist Hacked

Triple-A hacked — $11.80M lost

Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/cons…

P0
SlowMist Hacked

Wanchain Cardano-BNB Chain Bridge hacked — $10.00M lost

Wanchain’s Cardano-to-BNB Chain cross-chain bridge was exploited. The attacker drained approximately 515 million NIGHT tokens from the Cardano-side lock address. The incident may involve signature validation or replay flaws. Wanchain suspe…

P0
CISA Known Exploited Vulnerabilities

CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on…

P0
CISA Known Exploited Vulnerabilities

CVE-2026-45321: TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.;Required action: Apply mitigations per vendo…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.;Required action: Apply mitigations per vendor instructions, f…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-57728: SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host i…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.;Required actio…

P0
CISA Known Exploited Vulnerabilities

CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.;Required action: Apply mitigations per vendor instru…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-27199: JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.;Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services…