AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH
How HollowGraph Operates On July 20, 2026, Group-IB security researchers released a study describing an implant known as HollowGraph that converts a hacked Microsoft 365 calendar into hidden communication channel....
The post Ghost in the Calendar: The Microsoft 365 Calendar Implant appeared first on Cyber Defense Magazine.
The company behind the disk space analyzer TreeSize has irked some users by no longer offering support or updates for perpetual licenses beyond their maintenance period unless customers subscribe. Further frustration has come from JAM Software's long-standing policy of not providing license keys or installers to TreeSize perpetual license holders after that support period ends.
Since 2025, JAM Software has been transitioning most TreeSize editions to subscription models. Today, it sells perpetual licenses only for personal use, which include 12 months of updates, support, and “downloads of older versions, and your license,” plus the option to extend the support period. TreeSize currently has "no plans to discontinue the sale of perpetual licenses for TreeSize Personal," product manager Hendrik Christ told Ars Technica.
As perpetual-license maintenance periods expire, customers are discovering that extending support now generally requires subscribing to software they already own the right to use.


© TreeSize
Healthcare software vendor Craneware confirmed attackers stole data during a cyberattack, underscoring growing cybersecurity risks facing healthcare suppliers.
The post Craneware Confirms Data Theft After Cyberattack, Investigations Underway appeared first on TechRepublic.
Healthcare software vendor Craneware confirmed attackers stole data during a cyberattack, underscoring growing cybersecurity risks facing healthcare suppliers.
The post Craneware Confirms Data Theft After Cyberattack, Investigations Underway appeared first on TechRepublic.
A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China, Russia, or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work, and deploy.
According to researchers at Purdue University, the US Military Academy at West Point, and Florida International University, one popular app used by service members to rate living conditions on their own bases include code from Huawei, the Chinese telecom that US regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian ad service Yandex.
The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the same—unless there is profit in telling them apart—despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.


© Tomas Ragina/Getty

Jimothy, the short-spined Seattle raccoon, has become a global sensation whose likeness has been immortalized in artwork, clothing, songs and tattoos — and now a video game created in the creature’s hometown.
Tech enthusiast and entrepreneur Chris Pirillo launched an 8-bit NES-style video game called “Jimothy” this weekend in which players can control the movements of the critter as he raids trash cans, crosses streets to the park, sneaks past the paparazzi, and climbs to the safety of a big tree.
Pirillo says the missions are pulled straight from Jimothy’s real life. No doubt the animal is busy these days trying to dodge curious onlookers who are hoping to capture the next photo or video that feeds the masses on social media.
The viral Jimothy sensation took off last week when Kiana Hall spotted the raccoon in Seattle’s Ballard neighborhood and posted a video on Instagram — viewed by millions since — asking the question heard around the world: “What am I looking at?”
An earlier video of Jimothy, captured by a home security camera and posted on Reddit, ignited further curiosity and adoration, and now Reddit is flooded with sightings, memes, artwork, food, crafts, poetry and more. The Mariners put a Jimothy mascot in the Salmon Run. There’s even a Lego Jimothy.
Pirillo told GeekWire the game idea came to him on Saturday afternoon after seeing so many creatives flood his feeds with their own Jimothy fan art. He started to build a not-so-live tracker and realized it was a not-so-great idea. He hopes internet creativity is enough of a fix for the Jimothy-curious.
“This game is as close as any of us should ever get to him,” the game site states. “If you find yourself in his neighborhood: don’t go looking for him, don’t feed him, don’t try to touch him, and don’t crowd him for a photo.”
The game is easy enough to play, with challenges that are reminiscent of classic 1980s games “Frogger” and “Donkey Kong.”
Pirillo’s “Vibe Arcade” is loaded with other games he’s created. Earlier this year he vibe-coded a Resume Analyzer app and a pre-rejection letter generator called Dear Applicant to channel his frustrations with searching for a job.
Pirillo credits AI with changing the speed and ease with which a moment can go viral and be captured in new and creative ways.
“I remember when every big moment had a video game. But by the time a studio could create a video game around a meme pre-AI, the meme’s energy would have dissipated,” he said. “We are now at a day and age (certainly with AI as a tool) where almost literally anybody of any age or tech experience level can bring full-fledged experiences to life in just a few hours. We can simply talk our solutions into existence. It’s astounding.”
Pirillo built the game as a single HTML page, pitting OpenAI GPT 5.6 against Anthropic’s Claude Fable 5. One of the bigger challenges was getting the look of Jimothy right, as multiple AI models kept returning regular-looking raccoons.
Pirillo said he looks forward to sharing more about it all during a free vibe-coding community workshop in Seattle this Saturday.
His final takeaway for anyone looking to get in on the Jimothy hype — or whatever creature emerges next — is to not wait for the moment to pass.
“While it’s never been easier to make something, it’s also never been more challenging to get attention,” he said.
Read more of this story at Slashdot.
Read more of this story at Slashdot.

A hacker tied to the Trusted Volumes exploit has returned 1,122 ETH to the protocol, closing part of a security incident that began with a multi-million-dollar exploit earlier this year.
The on-chain recovery is unusual because the attacker did not return everything. Instead, the wallet linked to the exploit sent back roughly $2 million worth of ETH while retaining another large amount as what now looks like a de facto bounty. That kind of outcome is familiar in DeFi, where projects sometimes negotiate with attackers after an exploit rather than risk losing the full amount forever.
The returned funds matter because they reduce the damage for the protocol and its users. But the structure of the settlement also shows how messy DeFi security remains. When smart contracts fail, the market often ends up relying on public pressure, wallet tracking, and informal negotiation rather than a clean legal process.
Reference: Etherscan
The exploit traces back to a vulnerability in Trusted Volumes’ RFQ swap proxy. According to the on-chain evidence, the May 7 attack drained approximately $5.9 million in assets through a signature-check bypass.
That is the kind of vulnerability that can be especially damaging in DeFi because it sits close to the execution layer of a protocol. If a swap proxy accepts an invalid or improperly checked instruction, an attacker may be able to move funds in a way the system was never meant to allow.
The important update now is the return of 1,122 ETH from the attacker wallet to protocol inventory. The primary source for the story is the wallet and transaction evidence on Etherscan, which shows the recovery leg of the movement.
This does not necessarily mean the protocol has been made whole. It means a meaningful part of the exploited funds has come back.
That distinction matters. A partial recovery can be better than nothing, but it still leaves users and the wider market asking why the vulnerability existed, how quickly it was detected, and whether the protocol has made changes to prevent a repeat.
Crypto has developed a strange pattern around major exploits.
In traditional finance, a theft usually leads to police reports, frozen accounts, and court processes. In DeFi, the first response is often public wallet tracking. The attacker’s address gets labelled. On-chain analysts follow the movement of funds. Protocol teams may publish messages offering a bounty if the money is returned.
Sometimes attackers accept. Sometimes they disappear into mixers, bridges, or exchange routes. Sometimes they return a portion and keep the rest.
That appears to be the shape of this case.
The reason this happens is simple: blockchains make funds visible, but not always recoverable. If an attacker controls the private keys, the protocol cannot simply reverse the transaction. The best practical outcome may be to offer a settlement before the funds are moved further away.
That is uncomfortable, but it is also realistic.
For users, the lesson is that code risk is not abstract. Even protocols with real activity can suffer from a small implementation flaw that becomes a major loss. For developers, the lesson is even sharper: signature validation, access controls, proxy logic, and upgrade paths need aggressive review because attackers only need one weak point.
The return of 1,122 ETH is clearly positive for Trusted Volumes, but it should not be treated as a full reset.
An exploit still happened. Funds were still removed. The attacker still appears to have kept a significant sum. The protocol still needs to show that the underlying issue has been addressed and that users can trust the system going forward.
That matters because DeFi confidence is fragile after security incidents. Users may forgive a protocol that responds quickly, communicates clearly, and recovers funds. They are less forgiving when teams stay vague, downplay the incident, or fail to explain what changed.
The strongest next step for Trusted Volumes would be a clear post-mortem: what failed, how the attacker used it, how the contract logic has been fixed, and whether any user balances remain affected.
Until then, the market can recognise the recovery without pretending the episode is over.
This is also a useful reminder for the wider sector. DeFi security is not only about preventing hacks. It is about incident response, transparency, on-chain monitoring, and whether projects can recover enough trust after something goes wrong.
Trusted Volumes got some funds back. The harder job is proving the system is safer than it was before the exploit.
This article is based on Etherscan wallet and transaction data.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by Etherscan. at Etherscan
