Skip to content

CounterICE — Security data and models for systems that can't afford to fail.

NEWS: Cybersecurity Attacks
Deepfaked CFO on a video call approves a $25M wireEvery face on the call was synthetic, cloned from public earnings videos. The finance clerk was the only real person in the room, and the wire cleared before anyone thought to call the CFO back.NewKrebs on Security2hHelp-desk impersonation resets MFA for a hotel chain's adminsOne phone call with a plausible employee ID and a story about a lost phone was enough to reset MFA on an admin account. The attacker never touched an exploit; the help desk did the work for them.BleepingComputer5hFake recruiter lures developers into running a trojaned take-homeThe take-home assignment's repo carries a loader in a postinstall hook, and the interview is real enough to get it run. The offer letter never arrives; the session tokens leave the same night.The Hacker News9hQR-code phishing wave slips past email filters into inboxesThe link is an image, so the mail gateway has nothing to scan. The phone that reads the code sits off the corporate network, and the login page it opens is a pixel-perfect copy of the real SSO.Proofpoint14hSIM-swap ring drains accounts through carrier retail staffBribed retail staff ported numbers on request, sometimes for a few hundred dollars a line. SMS codes did the rest: bank, exchange and email accounts fell in the same hour.Krebs on Security1d
Social Engineering
Typosquatted package harvests CI credentials on installOne transposed letter in an install command pulls a lookalike package that mirrors the real API. Its install hook reads the environment and ships every CI secret it finds to a webhook.NewSocket4hMaintainer account compromise pushes backdoored releaseA phished maintainer token published a patch release with a credential stealer folded into the build. Lockfiles that floated on the minor version picked it up within hours.GitHub Advisory8hCompromised GitHub Action rewrites its tags to a malicious commitEvery workflow pinned to a version tag pulled the new commit on its next run, and it dumped runner secrets into the build logs. Only workflows pinned to a full SHA were untouched.Wiz16hPostinstall script exfiltrates environment variablesThe script checks for CI environment variables before it does anything, so a developer's laptop looks clean. Only on the build machine, where the environment is worth stealing, does it phone home.Socket1dBackdoor in a compression library nearly reaches every major distroTwo years of patient, helpful maintainership earned commit rights, then the payload arrived hidden in binary test fixtures. It was caught by a performance regression, not by a security review.Snyk2d
Supplychain Attack
Cross-chain bridge drained via signature replayA validator signature meant for one chain was replayed on another, and the bridge released the same deposit twice. The contracts never checked which chain the message was signed for.Newrekt.news3hLending protocol loses funds to oracle manipulationA thin market let one flash-loaned trade move the oracle price several hundred percent inside a block. The protocol then lent against collateral that was worth nothing a block later.SlowMist7hUpgradeable proxy misconfiguration leaves admin exposedThe proxy's admin slot pointed at a single externally owned account rather than a multisig or timelock. One key compromise stood between the protocol and an arbitrary upgrade.PeckShield11hGovernance takeover attempted through flash-loaned votesFlash-loaned governance tokens briefly held quorum and passed a proposal that drained the treasury to the attacker. The timelock was the only thing that held, and the vote was cancelled in time.CertiK1dExchange hot wallet emptied through a poisoned signing UIThe signers saw a routine transfer on a signing interface that had been quietly modified. What the hardware wallets actually signed was a delegate call that handed the wallet's logic to the attacker.rekt.news2d
Blockchain Attack
NEWS: Cybersecurity Attacks

Contain

Training data, authored by practitioners.

Contain

Secure

Analysis that runs before the system ships.

Secure

Protect

Detection that runs while the system runs.

Protect

In development

Product: -[PROTECT]-Live Threat Analysis & Proactive Protection

Continuous monitoring for deployed contracts and services, tuned on the same corpus that trains the models, catching the run-up to an exploit.

-[PROTECT]-
Coming soon…

CounterICE

Secure. Contain. Protect.