Polymarket's Rush to Grow Left a Door Wide Open for Fraudsters
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
On a June afternoon Maersk’s offices filled with employees watching screens go black and display fake ransom demands as a worm spread through corporate networks, forcing a frantic two-hour global shutdown that left ships idle, phones dead, and workers sent home. The outbreak began in Kyiv when attackers hijacked the update servers of M.E.Doc, Ukraine’s ubiquitous accounting software, turning routine updates into a delivery mechanism. That compromise built on years of Russian cyberoperations against Ukraine by the Sandworm group, which had previously knocked out data and caused power outages, and it transformed a localized sabotage campaign into a crisis that hit multinational supply chains and critical services.
The malware, dubbed NotPetya, married two powerful tools - EternalBlue, an NSA-developed Windows exploit leaked earlier in 2017, and Mimikatz, a credential-stealing utility - to propagate automatically and hop across networks, even into patched systems. It masqueraded as ransomware but was a destructive wiper that irreversibly corrupted master boot records, making recovery impossible and rendering ransom payments moot. Within hours it spread worldwide, crippling companies such as Maersk, Merck, TNT Express, Saint-Gobain, Mondelez, and Reckitt Benckiser, and even striking Russia’s Rosneft, causing more than $10 billion in damages and constituting a decisive act of cyberwarfare.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
Windows product activation used a secret binary blob called 'Microsoft Bob' in volume licensing media to prevent unauthorized use. This key and media combination leaked early in 2001, leading to piracy and subsequent blacklisting by Microsoft. (twitter.com)
RSA-896, a challenge number, was factored on September 19, 2026, by Stephen A. Weis using Claude. The factorization reveals the prime factors p and q of the 896-bit RSA modulus. (saweis.net)
Twenty-five years after a proposed national ID system was rejected, the US has quietly moved toward a digital identity platform called Login.gov, which consolidates personal data without public debate. This system could eventually enable broad surveillance and access control across institutions without explicit legislation or public approval. (thedreydossier.substack.com)
Hugging Face experienced a security breach, but the impact was less severe than initially reported. The company clarified that the hack did not compromise sensitive data or major systems. (wsj.com)
Congress is investigating the diversion of F-35 aircraft parts to Hong Kong. The incident has raised concerns about potential security breaches involving military equipment. (politico.com)
Today's best Hacker News stories, summarized and screenshotted, one email a day.