Chainalysis tied the $387 million Bitget hack to North Korea-linked hackers, saying it pushed their 2026 crypto theft past $1 billion. Its AI cut more than 20 hours of tracing to minutes, while the bill falls on a Bitget user fund the exchange puts above $464 million.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 41%
- Investor
- Investor 27%
Reality
- Evidence70
- Adoption25
- Hype gap+35
- Incentives60
- Confidence65
Attackers using two NetScaler zero-days since early September left webshells that patching to 14.1-73.37 or 13.1-64.23 does not remove. Operators have to search every appliance for those traces, patched or not, and move OT remote access onto a jump host of its own.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
Dell patched six critical flaws in its Kubernetes storage modules, one letting unauthenticated attackers pull admin credentials for every registered array. The Authorization module holds those keys for each array it fronts, so one reachable deployment exposes all the storage registered behind it.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 65%
- Investor
- Investor 8%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence72
Kevin Mandia's Armadin raised $255.5 million at a valuation above $2.5 billion, bringing its total to $445 million seven months after launch. Its case against periodic pen tests rests on performance data from an exercise Armadin ran with a partner.
Perspective Coverage
6 publishers
- Builder
- Builder 24%
- Operator
- Operator 38%
- Investor
- Investor 38%
Reality
- Evidence55
- Adoption30
- Hype gap+40
- Incentives75
- Confidence60
Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 41%
- Investor
- Investor 34%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
Kevin Mandia's AI cybersecurity startup Armadin raised a $255.5 million Series B at a valuation above $2.5 billion. Security teams comparing its AI agents with periodic human pentests have only Armadin's own platform figures to go on.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 37%
- Investor
- Investor 40%
Reality
- Evidence55
- Adoption25
- Hype gap+35
- Incentives65
- Confidence60
Bitget says attackers may have used a flaw in a third-party security product to get internal credentials and forge $388 million of withdrawals. The account puts vendor software that can reach a withdrawal system inside an exchange's counterparty risk, alongside its own wallet controls.
Publishers:bitget.com · cointelegraph.com Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
Armadin, the AI attack-testing startup run by Mandiant founder Kevin Mandia, raised $255.5 million at a valuation above $2.5 billion. Investors are betting that always-on AI agents will take over the budget companies now spend on periodic penetration tests.
Perspective Coverage
6 publishers
- Builder
- Builder 31%
- Operator
- Operator 32%
- Investor
- Investor 37%
Reality
- Evidence55
- Adoption20
- Hype gap+40
- Incentives80
- Confidence60
Bitget says attackers stole $387.5 million after exploiting zero-days in two third-party security appliances. Investigators say the appliances' privileged access led the attacker to its production wallet server.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence60
FBI's Brett Leatherman urged ShinyHunters members to surrender after the Dutch arrest of an alleged leader of a group tied to $70 million in extortion. Dutch police have not ruled out more arrests, though the public record so far shows one suspect in custody.
Perspective Coverage
9 publishers
- Builder
- Builder 17%
- Operator
- Operator 68%
- Investor
- Investor 15%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives60
- Confidence64
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
LevelBlue says attackers are exploiting NetScaler flaw CVE-2026-88771, rated 9.5, to create a hidden superuser account and plant web shells. The patch closes the injection but removes neither, so already-exposed appliances need a compromise check.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives40
- Confidence60
Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.
Perspective Coverage
5 publishers
- Builder
- Builder 23%
- Operator
- Operator 60%
- Investor
- Investor 17%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence60
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
Perspective Coverage
21 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives60
- Confidence86
Bitget customers pulled about $463 million in the first 24 hours after withdrawals reopened, more than the $388 million hackers stole on September 24. The protection fund covers the theft with about $76 million to spare, so the withdrawals now test whether the $5.7 billion left in reserves matches what Bitget owes customers.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+12
- Incentives58
- Confidence58
Kelp DAO has sued LayerZero Labs and co-founder Bryan Pellegrino for negligence and misrepresentation over April's $292 million rsETH bridge exploit. The forged message cleared a bridge that trusted one LayerZero-run verifier, so the case tests who answers for that setup.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence35
ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 58%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+8
- Incentives58
- Confidence74
Bitget lost $387.5 million after attackers inside its wallet backend falsified transaction data that its own authorization process then approved. Its CEO says the private keys stayed safe, so the failure sat in the step between approval and signature.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence60
Mandiant says ShinyHunters has planted web shells on dozens of Oracle PeopleSoft systems by URL-encoding one character to get past firewall rules. Employers that treated June's stopgap as the fix now have to patch and also look for any access the attackers left behind.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+8
- Incentives20
- Confidence70
Earlier coverage
- One URL-encoded letter gets ShinyHunters past PeopleSoft WAF rules on unpatched servers
Security · September 28, 2026 · 1 publisher
- Bitget traces its $388 million wallet theft to a flaw in a third-party security product
Security · September 28, 2026 · 1 publisher
- Bitget traces $387.5 million breach to stolen internal credentials via third-party product flaw
Invest · September 28, 2026 · 2 publishers
- Suspected North Korean attackers used Bitget's own signing process to move $351.6M
Security · September 25, 2026 · 10 publishers
- Kiteworks' shutdown all-clear sends self-hosted Advanced Forms customers to support
Security · September 28, 2026 · 1 publisher
- Bitget presses THORChain to cut off the wallets holding its stolen $387.5 million
Invest · September 26, 2026 · 3 publishers
- Most of Bitget's $387.5 million hack loss sits untouched in attacker wallets
Invest · September 27, 2026 · 15 publishers
- Bitget's own approval process moved out $388 million on spoofed transaction data
Product · September 25, 2026 · 3 publishers
- ShinyHunters says its FBI haul of up to three terabytes includes staff psychiatric records
Invest · September 26, 2026 · 1 publisher
- ShinyHunters percent-encode one letter to slip PeopleSoft's 9.8 RCE past the WAF
Build · September 26, 2026 · 1 publisher
- BlackFile wears four extortion brands, so your threat feed is counting one actor as several
Security · August 17, 2026 · 1 publisher
- ShinyHunters routes around PeopleSoft firewall rules to hit systems still missing Oracle's patch
Invest · September 26, 2026 · 1 publisher
- ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered
Security · August 25, 2026 · 5 publishers
- Fire Ant taught a Cisco IOS XR router to forward only log lines containing the word Health
Security · August 31, 2026 · 6 publishers
- Breeze Comet talks its way into Brazilian payment systems with a help-desk call and AnyDesk
Security · September 1, 2026 · 2 publishers
- Attackers rode the Trivy compromise into Checkmarx's GitHub and out through its VS Code extensions
Build · September 3, 2026 · 1 publisher
- PREY-0058 phones executives to harvest Microsoft 365 session tokens
Security · September 7, 2026 · 3 publishers
- Bitget's own authorization process approved $351.6M in transfers built on spoofed data
Build · September 25, 2026 · 1 publisher
- Google's undercover analyst watched TeamPCP poison packages from inside its core chat
Product · September 18, 2026 · 1 publisher
- ShinyHunters pins its claimed FBI breach on an unpatched PeopleSoft RCE
Security · September 23, 2026 · 14 publishers
- An agent now picks the packages the person prompting it will never see
Build · September 23, 2026 · 1 publisher
- A $10 limit stored as text on a Kinde token cut the agent off after four calls
Build · September 22, 2026 · 1 publisher
- A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem
Build · September 19, 2026 · 1 publisher
- Unauthenticated SAP attackers hit memory corruption before any login check
Security · September 18, 2026 · 1 publisher
- Verizon's 43-day median patch time, against a five-day weaponization clock
Security · September 17, 2026 · 1 publisher
- Attackers went from stolen cloud credentials to mass credential harvest in under six hours
Leadership · September 16, 2026 · 2 publishers
- Mandiant's testers talked an internal AI assistant into pushing private repos to their own GitHub
Security · September 16, 2026 · 1 publisher
- Clearing Mythos Preview's 6,105 open findings at 97 fixes per two months takes a decade
Build · September 12, 2026 · 1 publisher
- An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud
Build · September 12, 2026 · 1 publisher
- Amazon puts Mandiant's founder on both its Audit and Security committees
Product · September 11, 2026 · 1 publisher
- Anthropic's most capable model built working exploits from 16 of 39 published patches
Leadership · September 11, 2026 · 1 publisher
- Amazon hands a board seat to the incident responder who built the firm Google now owns
Security · September 10, 2026 · 2 publishers
- Stealer logs now carry AI session tokens that replay straight past MFA
Security · September 9, 2026 · 1 publisher
- Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours
Security · September 8, 2026 · 3 publishers
- Slim Spider lifted crypto custody keys out of a Brazilian bank's cloud secret manager
Security · September 8, 2026 · 1 publisher
- Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks
Product · September 8, 2026 · 1 publisher
- IMDSv1 turns an SSRF finding into unauthenticated credential theft in one hop
Build · September 6, 2026 · 1 publisher
- Counting from the vendor advisory stretches the exploitation window to 116 days
Build · September 5, 2026 · 1 publisher
- Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD
Security · September 3, 2026 · 1 publisher
- Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020
Security · August 28, 2026 · 1 publisher