<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Time Signals</title><link>https://timeline.snamibo.com/en/</link><description>Selected public-source intelligence signals.</description><item><title>AFX Bridge hacked — $24.15M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Ac021edba2ed7a941fc2637af/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Ac021edba2ed7a941fc2637af/</guid><pubDate>2026-07-22T00:00:00Z</pubDate><description>The AFX-operated cross-chain/USDC custody bridge on Arbitrum was exploited. The attacker used compromised validator hot keys to meet the quorum and drain approximately $24.15 million USDC. The funds were bridged to Ethereum and swapped for ETH. Arbitrum’s native bridge was unaffected, and AFX’s core trading infrastructure remained secure. The team suspended bridge operations and is investigating with security partners.</description></item><item><title>Ostium hacked — $18.00M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Afc51033c2ee08d421c437b04/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Afc51033c2ee08d421c437b04/</guid><pubDate>2026-07-15T00:00:00Z</pubDate><description>Ostium, an RWA-focused perpetuals DEX on Arbitrum, suffered an oracle manipulation exploit. The attacker used a compromised oracle signer key to submit fraudulent future-dated price reports, generating artificial trading profits and draining approximately $18 million USDC from the liquidity vault. The protocol has halted trading and is investigating.</description></item><item><title>BonkDAO hacked — $20.00M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Acca2914c673865ef63146baf/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Acca2914c673865ef63146baf/</guid><pubDate>2026-07-06T00:00:00Z</pubDate><description>BonkDAO suffered a governance attack. The attacker spent ~$4M to buy BONK tokens for sufficient voting power and passed a malicious governance proposal (BIP-76) to transfer ~$20M BONK from the treasury to controlled wallets. No smart contract exploit; used the DAO&#x27;s own voting system.</description></item><item><title>Triple-A hacked — $11.80M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A6766da91bf7bb7c11d0a289f/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A6766da91bf7bb7c11d0a289f/</guid><pubDate>2026-07-25T00:00:00Z</pubDate><description>Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/consolidated to a single Ethereum address. Client funds remained unaffected in separate trust accounts; services were briefly paused for security checks and have been fully restored.</description></item><item><title>Triple-A hacked — $11.80M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A65310814c58662b42b07b60b/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A65310814c58662b42b07b60b/</guid><pubDate>2026-07-24T00:00:00Z</pubDate><description>Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/consolidated to a single Ethereum address. Client funds remained unaffected in separate trust accounts; services were briefly paused for security checks and have been fully restored.</description></item><item><title>Wanchain Cardano-BNB Chain Bridge hacked — $10.00M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A50efedf07a6255a5c7ad36e4/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A50efedf07a6255a5c7ad36e4/</guid><pubDate>2026-07-21T00:00:00Z</pubDate><description>Wanchain’s Cardano-to-BNB Chain cross-chain bridge was exploited. The attacker drained approximately 515 million NIGHT tokens from the Cardano-side lock address. The incident may involve signature validation or replay flaws. Wanchain suspended the bridge; Midnight’s core network was unaffected. Multiple exchanges froze related funds, and NIGHT price dropped sharply before partial recovery.</description></item><item><title>CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/888368f1ba8ecf91dd5e80103a20ad0d/</link><guid>https://timeline.snamibo.com/en/briefs/888368f1ba8ecf91dd5e80103a20ad0d/</guid><pubDate>2026-06-25T00:00:00Z</pubDate><description>PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.；Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#x27;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.；Due: 2026-06-28</description></item><item><title>Yinhua Healthcare Innovation Mixed (QDII) C (026260): Purchase limits fully lifted</title><link>https://timeline.snamibo.com/en/briefs/901c519cb38495fad2eb41a3dc7a76c1/</link><guid>https://timeline.snamibo.com/en/briefs/901c519cb38495fad2eb41a3dc7a76c1/</guid><pubDate>2026-07-28T07:07:19.117098Z</pubDate><description>Suspended subscription → Open subscription</description></item><item><title>Yinhua Healthcare Innovation Mixed (QDII) A (026259): Purchase limits fully lifted</title><link>https://timeline.snamibo.com/en/briefs/5fa26e311ae2446d9846781c01b3e8d7/</link><guid>https://timeline.snamibo.com/en/briefs/5fa26e311ae2446d9846781c01b3e8d7/</guid><pubDate>2026-07-28T07:07:19.117098Z</pubDate><description>Suspended subscription → Open subscription</description></item><item><title>CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/1cef76714868733ad274c4f6e9e60321/</link><guid>https://timeline.snamibo.com/en/briefs/1cef76714868733ad274c4f6e9e60321/</guid><pubDate>2026-06-12T00:00:00Z</pubDate><description>Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.；Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#x27;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.；Due: 2026-06-15</description></item><item><title>CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/2bef43bf557fc92520f0dad69fa79fcd/</link><guid>https://timeline.snamibo.com/en/briefs/2bef43bf557fc92520f0dad69fa79fcd/</guid><pubDate>2026-06-08T00:00:00Z</pubDate><description>Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-06-11</description></item><item><title>CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/cbbd4007380226870c1e4ff33c733159/</link><guid>https://timeline.snamibo.com/en/briefs/cbbd4007380226870c1e4ff33c733159/</guid><pubDate>2026-05-29T00:00:00Z</pubDate><description>Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-06-01</description></item><item><title>CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/e78c4a78340f3239cc44b916ead294c2/</link><guid>https://timeline.snamibo.com/en/briefs/e78c4a78340f3239cc44b916ead294c2/</guid><pubDate>2026-05-27T00:00:00Z</pubDate><description>Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-06-10</description></item><item><title>CVE-2026-45321: TanStack Unspecified Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/518efbf428edde07c69ce885c2e5139c/</link><guid>https://timeline.snamibo.com/en/briefs/518efbf428edde07c69ce885c2e5139c/</guid><pubDate>2026-05-27T00:00:00Z</pubDate><description>TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-06-10</description></item><item><title>CVE-2026-41940: WebPros cPanel &amp; WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/a1e159de40ffd323cb9d75bbc6c2781d/</link><guid>https://timeline.snamibo.com/en/briefs/a1e159de40ffd323cb9d75bbc6c2781d/</guid><pubDate>2026-04-30T00:00:00Z</pubDate><description>WebPros cPanel &amp; WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-05-03</description></item><item><title>CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/c5435525f9bfb4388f3c83455e066590/</link><guid>https://timeline.snamibo.com/en/briefs/c5435525f9bfb4388f3c83455e066590/</guid><pubDate>2026-04-28T00:00:00Z</pubDate><description>ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-05-12</description></item><item><title>CVE-2024-57728: SimpleHelp Path Traversal Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/bdad5251f0ac2274c9f945f20bede12f/</link><guid>https://timeline.snamibo.com/en/briefs/bdad5251f0ac2274c9f945f20bede12f/</guid><pubDate>2026-04-24T00:00:00Z</pubDate><description>SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-05-08</description></item><item><title>CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/491402d16198acb6fb7b22db30e752cd/</link><guid>https://timeline.snamibo.com/en/briefs/491402d16198acb6fb7b22db30e752cd/</guid><pubDate>2026-04-24T00:00:00Z</pubDate><description>SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-05-08</description></item><item><title>CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/f9c89e18a70bd05e80590be19a36113b/</link><guid>https://timeline.snamibo.com/en/briefs/f9c89e18a70bd05e80590be19a36113b/</guid><pubDate>2026-04-22T00:00:00Z</pubDate><description>Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-05-06</description></item><item><title>CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/abb4033909c3b169ae6207b48993671a/</link><guid>https://timeline.snamibo.com/en/briefs/abb4033909c3b169ae6207b48993671a/</guid><pubDate>2026-04-20T00:00:00Z</pubDate><description>PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-05-04</description></item><item><title>CVE-2024-27199: JetBrains TeamCity Relative Path Traversal Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/3f5cbeed3c30cec6285482dcba412064/</link><guid>https://timeline.snamibo.com/en/briefs/3f5cbeed3c30cec6285482dcba412064/</guid><pubDate>2026-04-20T00:00:00Z</pubDate><description>JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-05-04</description></item><item><title>CVE-2023-21529: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/8e09a45280dfd22f0fab2bda669e65e8/</link><guid>https://timeline.snamibo.com/en/briefs/8e09a45280dfd22f0fab2bda669e65e8/</guid><pubDate>2026-04-13T00:00:00Z</pubDate><description>Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-04-27</description></item><item><title>CVE-2026-20131: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/909c41e7e170c1ed36d8f8be746ec375/</link><guid>https://timeline.snamibo.com/en/briefs/909c41e7e170c1ed36d8f8be746ec375/</guid><pubDate>2026-03-19T00:00:00Z</pubDate><description>Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-03-22</description></item><item><title>CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/11ce7ea9ca0871195c9923ba7a44eb32/</link><guid>https://timeline.snamibo.com/en/briefs/11ce7ea9ca0871195c9923ba7a44eb32/</guid><pubDate>2026-02-13T00:00:00Z</pubDate><description>BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-02-16</description></item><item><title>CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/c0ce8d609da56080b53ff87c50730a0b/</link><guid>https://timeline.snamibo.com/en/briefs/c0ce8d609da56080b53ff87c50730a0b/</guid><pubDate>2026-02-05T00:00:00Z</pubDate><description>SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution. ；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-02-26</description></item><item><title>CVE-2026-23760: SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/f264b6701bb174203d77966a30329c45/</link><guid>https://timeline.snamibo.com/en/briefs/f264b6701bb174203d77966a30329c45/</guid><pubDate>2026-01-26T00:00:00Z</pubDate><description>SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-02-16</description></item><item><title>CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/53f313423a22a614363c8ff842ba2a98/</link><guid>https://timeline.snamibo.com/en/briefs/53f313423a22a614363c8ff842ba2a98/</guid><pubDate>2026-01-26T00:00:00Z</pubDate><description>SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2026-02-16</description></item><item><title>CVE-2025-55182: Meta React Server Components Remote Code Execution Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/096fcb27a69e5f2d23c42175e2b278b9/</link><guid>https://timeline.snamibo.com/en/briefs/096fcb27a69e5f2d23c42175e2b278b9/</guid><pubDate>2025-12-05T00:00:00Z</pubDate><description>Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2025-12-12</description></item><item><title>CVE-2025-61884: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/592d3174c2129b2c7091d37df839dc92/</link><guid>https://timeline.snamibo.com/en/briefs/592d3174c2129b2c7091d37df839dc92/</guid><pubDate>2025-10-20T00:00:00Z</pubDate><description>Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2025-11-10</description></item><item><title>CVE-2025-61882: Oracle E-Business Suite Unspecified Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/d112714e5a64a0bf11757606bf3d5892/</link><guid>https://timeline.snamibo.com/en/briefs/d112714e5a64a0bf11757606bf3d5892/</guid><pubDate>2025-10-06T00:00:00Z</pubDate><description>Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2025-10-27</description></item><item><title>CVE-2025-10035: Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability</title><link>https://timeline.snamibo.com/en/briefs/8f5ec94545be5e8847bbc56251d33125/</link><guid>https://timeline.snamibo.com/en/briefs/8f5ec94545be5e8847bbc56251d33125/</guid><pubDate>2025-09-29T00:00:00Z</pubDate><description>Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.；Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.；Due: 2025-10-20</description></item><item><title>Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses</title><link>https://timeline.snamibo.com/en/briefs/7ed85614ea516e9043c6671211283520/</link><guid>https://timeline.snamibo.com/en/briefs/7ed85614ea516e9043c6671211283520/</guid><pubDate>2026-07-23T10:49:10Z</pubDate><description>Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek .</description></item><item><title>Hackers steal $23.7 million in crypto from Ostium in off-chain attack</title><link>https://timeline.snamibo.com/en/briefs/e65ce33dd35675d37c30c84d08946a49/</link><guid>https://timeline.snamibo.com/en/briefs/e65ce33dd35675d37c30c84d08946a49/</guid><pubDate>2026-07-20T22:22:56Z</pubDate><description>The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]</description></item><item><title>Bonzo Lend hacked — $9.05M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A0beed879bd8c82632ee75d0a/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A0beed879bd8c82632ee75d0a/</guid><pubDate>2026-07-11T00:00:00Z</pubDate><description>Bonzo Lend on Hedera was exploited through a third-party oracle (Supra) vulnerability. An attacker submitted a massively manipulated SAUCE price, allowing them to borrow approximately $9.05 million in assets with minimal collateral. The borrowed funds were subsequently swapped on SaucerSwap and bridged to Ethereum via LayerZero (over $5M tracked on-chain). Bonzo Lend paused the protocol shortly after detecting abnormal activity.</description></item><item><title>WEMIX hacked — $6.25M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A89708b4500e4586008e35c6b/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A89708b4500e4586008e35c6b/</guid><pubDate>2026-07-26T00:00:00Z</pubDate><description>The owner privileges of a WEMIX$-related smart contract were compromised, allowing the attacker to illegally mint approximately 5.23 million WEMIX$ stablecoins (worth about $6.25 million), which were swapped into WEMIX and USDC.e before being bridged out. The team has suspended bridges and related services while working with exchanges, security firms, and law enforcement to track the funds.</description></item><item><title>BonkDAO - Rekt</title><link>https://timeline.snamibo.com/en/briefs/d39373380fa48f5e2e0ca6f5d2d6049d/</link><guid>https://timeline.snamibo.com/en/briefs/d39373380fa48f5e2e0ca6f5d2d6049d/</guid><pubDate>2026-07-10T00:00:00Z</pubDate><description>$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighted governance voting math.</description></item><item><title>Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin</title><link>https://timeline.snamibo.com/en/briefs/cdaef03d3dbbed4fd00e61e00ca73390/</link><guid>https://timeline.snamibo.com/en/briefs/cdaef03d3dbbed4fd00e61e00ca73390/</guid><pubDate>2026-07-27T17:29:07Z</pubDate><description>Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]</description></item><item><title>Verus Ethereum Bridge hacked — $7.54M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A327ac13a3ce0233c31952e2a/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A327ac13a3ce0233c31952e2a/</guid><pubDate>2026-07-23T00:00:00Z</pubDate><description>The Verus Ethereum Bridge was exploited again. The attacker abused the bridge’s import path to trigger unbacked payouts on the Ethereum side, draining approximately $7.54 million in assets (ETH, tBTC, USDC, etc.) from the bridge reserves. This is the second exploit of the same flaw from May. The project has not issued a detailed official statement yet.</description></item><item><title>Bonzo Finance - Rekt</title><link>https://timeline.snamibo.com/en/briefs/c3257ae460d2afd580f0c11493022761/</link><guid>https://timeline.snamibo.com/en/briefs/c3257ae460d2afd580f0c11493022761/</guid><pubDate>2026-07-14T00:00:00Z</pubDate><description>Zero equals zero. Supra’s oracle verifier accepted a zeroed signature against a zeroed key, and Bonzo Finance on Hedera lost $9.05 million because the math checked out and nobody questioned the premise.</description></item><item><title>Summer Finance - Rekt</title><link>https://timeline.snamibo.com/en/briefs/faff1127e2b033e3276825966b92a222/</link><guid>https://timeline.snamibo.com/en/briefs/faff1127e2b033e3276825966b92a222/</guid><pubDate>2026-07-09T00:00:00Z</pubDate><description>$6.04 million stolen from Summer Finance&#x27;s Lazy Summer depositors when a capped-for-removal Ark was still counted in the vault’s value, letting a donated stale asset inflate the share price and drain real liquidity.</description></item><item><title>Lazy Summer Protocol hacked — $6.04M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A79f229f24f31253bbbb3af5c/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A79f229f24f31253bbbb3af5c/</guid><pubDate>2026-07-06T00:00:00Z</pubDate><description>Lazy Summer Protocol (under Summer.fi) USDC vaults were exploited due to NAV/share price calculation flaw. The attacker used flash loans and pre-accumulated overvalued Silo tokens to inflate vault NAV (~9.5%), redeeming at inflated price and extracting ~$6.04M from other depositors.</description></item><item><title>Coca-Cola confirms data theft in Fairlife ransomware attack</title><link>https://timeline.snamibo.com/en/briefs/82b5b52855506c2848bc2768da42822e/</link><guid>https://timeline.snamibo.com/en/briefs/82b5b52855506c2848bc2768da42822e/</guid><pubDate>2026-07-27T15:39:51Z</pubDate><description>The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]</description></item><item><title>Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack</title><link>https://timeline.snamibo.com/en/briefs/ce589f8446e36a9def4708086d495631/</link><guid>https://timeline.snamibo.com/en/briefs/ce589f8446e36a9def4708086d495631/</guid><pubDate>2026-07-27T11:29:03Z</pubDate><description>The Anubis cybercrime group has taken credit for the attack and is threatening to leak data. The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek .</description></item><item><title>Allbridge Core hacked — $1.65M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A4439112f824ace201e69834d/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3A4439112f824ace201e69834d/</guid><pubDate>2026-07-19T00:00:00Z</pubDate><description>Cross-chain bridge protocol Allbridge Core was exploited on July 19-20, 2026. The attacker used a ~$1.12M USDC flash loan from Kamino to rapidly swap in the Solana USDC/USDT liquidity pools, manipulating ratios and draining approximately $1.65 million. The team paused the protocol, urged affected LPs to withdraw funds immediately, and asked arbitrage profiteers to return funds for LP compensation.</description></item><item><title>SecondFi - Rekt</title><link>https://timeline.snamibo.com/en/briefs/8cc1244d623db6eccdab3d9a75149a6f/</link><guid>https://timeline.snamibo.com/en/briefs/8cc1244d623db6eccdab3d9a75149a6f/</guid><pubDate>2026-06-30T00:00:00Z</pubDate><description>A single missing secret in SecondFi&#x27;s signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line of missing code, nothing more. Just reading what was already there.</description></item><item><title>Coca-Cola says Fairlife ransomware attack halts US dairy production</title><link>https://timeline.snamibo.com/en/briefs/1d45fb1e1a95fb47aa9e3619d35b0698/</link><guid>https://timeline.snamibo.com/en/briefs/1d45fb1e1a95fb47aa9e3619d35b0698/</guid><pubDate>2026-07-16T21:09:41Z</pubDate><description>The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]</description></item><item><title>Check Point warns of SmartConsole zero-day exploited in attacks</title><link>https://timeline.snamibo.com/en/briefs/976c0798d2ef88abed29891a224ae9f0/</link><guid>https://timeline.snamibo.com/en/briefs/976c0798d2ef88abed29891a224ae9f0/</guid><pubDate>2026-07-23T08:13:07Z</pubDate><description>Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company&#x27;s SmartConsole graphical user interface (GUI) admin panel. [...]</description></item><item><title>SecondFi hacked — $2.40M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Ae5c2efdee7a747878aec70a6/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Ae5c2efdee7a747878aec70a6/</guid><pubDate>2026-06-23T00:00:00Z</pubDate><description>SecondFi (formerly Yoroi) Cardano wallet suffered an exploit due to a vulnerability in its proprietary web wallet generation software, exposing private keys at the address level. Attackers drained ~16 million ADA ($2.4M) from 374 affected wallets across three attacks. The project secured ~129 million ADA (~$19.4M) through emergency rescue; affected users must wait for official recovery and are advised to use hardware wallets for migration.</description></item><item><title>Taiko Bridge hacked — $1.70M lost</title><link>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Ad1a41b4e2decde2fc2348c1b/</link><guid>https://timeline.snamibo.com/en/briefs/slowmist_hacked%3Ad1a41b4e2decde2fc2348c1b/</guid><pubDate>2026-06-21T00:00:00Z</pubDate><description>On June 21-22, 2026, Taiko (an Ethereum L2) suffered a bridge exploit targeting its ERC20 Vault. Attackers exploited a compromise in the chain state verification mechanism by forging SGX proofs to register a malicious prover, bypassing verification to submit fake bridge messages and drain approximately $1.7 million in assets (including USDC, ETH, and TAIKO tokens). Taiko quickly confirmed the verification compromise, paused the bridge and block production, initially urged users to withdraw funds, and later contained the incident while coordinating with exchanges to freeze attacker assets. A full post-mortem is forthcoming.</description></item><item><title>Data Breach Confirmed After Australian Energy Giant Origin Is Hacked</title><link>https://timeline.snamibo.com/en/briefs/a39bb1a33eebd3925183ae0274e4ea66/</link><guid>https://timeline.snamibo.com/en/briefs/a39bb1a33eebd3925183ae0274e4ea66/</guid><pubDate>2026-07-24T05:52:31Z</pubDate><description>A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek .</description></item></channel></rss>