BackDoS attack

DoS attack

Sality botnet
2026-09-02 11:39:43

CrowdStrike and US Justice Department Dismantle Sality Botnet That Hijacked Crypto Payments

CrowdStrike, in coordination with the U.S. Justice Department, announced Tuesday the takedown of the Sality peer-to-peer botnet, which had been active since 2003. Over the past eight years, it used the EggJagger malware to hijack cryptocurrency payments, stealing at least 12.1 million rubles (approximately $150,000). Unspent stolen crypto was valued at around 147 million rubles (roughly $1.35 million) at its peak in January 2025. The operation involved authorities from the U.S., Bulgaria, Hungary, and Romania. CrowdStrike isolated over 15,000 infected machines into honeypots. The operator, tracked as SALTY SPIDER, previously launched a DDoS attack on Russian exchange AvanChange in September 2023.

240
CrowdStrike and US Justice Department Dismantle Sality Botnet That Hijacked Crypto Payments
Bluesky
2026-08-18 20:21:31

Bluesky says recent outage was caused by a DDoS attack

Bluesky said its recent service disruption was caused by a distributed denial-of-service, or DDoS, attack that flooded the site with junk traffic and overwhelmed its resources. The decentralized social platform said it has upgraded its defenses and is continuing to monitor the situation. Security researchers said attackers with an Iranian background have claimed responsibility for the incident. The episode marks the second large-scale DDoS attack to hit Bluesky in recent months. In April, the platform suffered a prolonged outage after a similar traffic flood. It is still unclear whether the two attacks are connected. The development was reported by TechCrunch and cited by Techub.

240
Bluesky says recent outage was caused by a DDoS attack
Japan
2026-08-07 08:55:53

Japan FSA Moves to Unify Cybersecurity Report Formats, Including for Crypto Asset Exchanges

Japan's Financial Services Agency (FSA) has published a partial revision to its Comprehensive Supervision Guidelines for Major Banks, etc., a move reported by CoinPost. The proposed amendment would standardize cybersecurity incident report formats across 17 regulatory fields, a group that includes crypto asset exchange service providers. Under the revised regime, affected operators would file using a single common template. The draft also introduces a new “Common Format for Other Cyberattack Incidents,” which complements the existing dedicated formats for DDoS attacks and ransomware. Together, the three formats form a reporting system that distinguishes among the main incident categories. A transitional arrangement is in place: until the end of March 2027, operators that are not designated as social infrastructure providers may continue to use the old report forms rather than the new template. The FSA is inviting comments on the draft revision and will accept submissions from interested parties until September 7, 2026.

1280
Japan FSA Moves to Unify Cybersecurity Report Formats, Including for Crypto Asset Exchanges
Coinbase
2026-08-03 00:39:28

Coinbase’s Q2 loss widens as trading cools, while the summer split among CEXs grows sharper

Coinbase’s second-quarter 2026 results landed with a clear market reaction. After closing regular trading at $163.55 on July 30, up 2.16%, the stock fell to around $153 in after-hours trading after the company reported a wider-than-expected loss and revenue below Wall Street estimates for a third straight quarter. Coinbase posted a loss of $1.36 per share, versus expectations for a roughly break-even quarter at negative $0.01, while revenue came in at $1.22 billion against a projected range of $1.29 billion to $1.35 billion. The report showed a familiar pressure point for crypto exchanges in a quiet market: transaction revenue fell as global spot volumes dropped 25% quarter over quarter and total crypto market capitalization shrank 11%. At the same time, Coinbase’s subscription and services revenue reached 48% of total revenue, with USDC-related income accounting for more than half of that segment. The article argues this shift says more about the direction of exchange business models than the headline loss does. Set against Coinbase’s quarter, the shutdown announcements from BitMEX and BitMart in July point to a wider divide across centralized exchanges. The piece frames compliance, customer acquisition and cybersecurity as the three biggest burdens facing smaller platforms, while larger firms with scale and cash reserves keep pushing toward custody, stablecoin income and other service-based revenue streams.

1200
Coinbase’s Q2 loss widens as trading cools, while the summer split among CEXs grows sharper
Web3 Security
2026-07-27 10:02:00

Nearly 90% of stolen crypto funds were unrecoverable in H1 2026 as Web3 attacks shifted from code to people

Web3 recorded 182 publicly disclosed security incidents in the first half of 2026, with total losses reaching about $956 million, according to reports released by OKX Web3’s security team, SlowMist and OtterSec. The headline loss figure was down nearly 60% from a year earlier, but the decline mostly reflected the absence of a repeat of Bybit’s roughly $1.5 billion 2025 outlier. Incident count actually rose to 182 from 121, up about 50% year over year. The reports point to a structural shift in how attacks are carried out. The largest losses increasingly came from outside audited smart contracts and instead hit signing flows, cloud keys, validation paths, developer devices and users themselves. Examples cited in the reports include the roughly $285 million Drift Protocol attack, a months-long social engineering campaign centered on pre-signed transactions, and a Singapore case in which AI-generated officials appeared in a fake video conference, leading to losses of about S$4.9 million. Recovery remains rare. SlowMist said only 18 incidents in H1 resulted in stolen funds being recovered or frozen, totaling about $118 million, or 12.3% of overall losses. The rest, nearly 90%, was effectively gone. The reports also describe supply-chain poisoning, AI-assisted phishing, malicious browser extensions, recruiter scams and increasingly industrialized laundering routes involving privacy tools, cross-chain channels and OTC off-ramps.

1530
Nearly 90% of stolen crypto funds were unrecoverable in H1 2026 as Web3 attacks shifted from code to people
AI crawlers
2026-07-24 09:47:00

The Numbers Returned in Slimmed-Down Form After AI Bots Swamped 90% of Its Traffic

The Numbers, a long-running movie data site founded in 1997, went offline on March 5, 2026 and came back on March 13 in a reduced form after a severe strain from AI crawler traffic. According to PANews, citing reporting by Stephen Follows and comments attributed to founder Bruce Nash, AI crawlers and agents had grown to 90% of the site’s total traffic, pushing servers into repeated overload and failure. The restored version dropped historical charts, individual film detail pages and the site’s Report Builder feature. The case highlights a broader shift in web economics. PANews said Cloudflare data shows traditional search traffic once worked on a more balanced exchange, with Google crawling about five pages for each human visitor it sent back. By contrast, OpenAI reportedly crawls more than 1,000 pages per visitor, while Anthropic’s ratio exceeds 1:38,000. The article argues that for data-heavy websites with large numbers of public, structured pages, machine traffic can turn from an asset into a cost center because bots consume bandwidth and compute without producing equivalent ad, subscription or referral value. PANews also pointed to examples from Read the Docs, Wikimedia, SourceHut, iFixit and others to show that bot traffic now carries real infrastructure and labor costs. In that framing, The Numbers is not just an isolated outage story, but a sign of how legacy content and data sites may be forced to rethink architecture, traffic controls and business models as machine requests overtake human browsing.

80
The Numbers Returned in Slimmed-Down Form After AI Bots Swamped 90% of Its Traffic