Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack Ashish Khaitan
    Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds.  In response to the complaint, Bitkub stated that all customer assets currently held on its platform remain safe, fully accounted for, and protect
     

Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack

Bitkub cyberattack

Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds.  In response to the complaint, Bitkub stated that all customer assets currently held on its platform remain safe, fully accounted for, and protected in accordance with applicable regulations. The company argued that the allegations stem from decisions made during the aftermath of the 2021 security breach and do not reflect fraudulent conduct. 

Thailand SEC Files Complaint Over the 2021 Bitkub Cyberattack 

On 23 July 2026, the Thailand SEC filed a criminal complaint against Bitkub Online Co., Ltd. and its former directors, Sakolkorn Sakavee and Thaweesap Rawan. The regulator alleged that the company's daily net capital reports submitted between 10 May and 30 October 2021 failed to accurately reflect the material reduction in its digital asset holdings caused by the Bitkub cyberattack.  According to the regulator, the reports did not disclose the impact of the theft on the company's asset balance. The Thailand SEC also accused the two former directors of making false entries in company documents that gave the impression that customer assets were still being held normally and that the company had not suffered any damage.  The complaint has been referred to Thailand's Economic Crime Suppression Division for further investigation. Following that process, the matter may be forwarded to prosecutors and the courts. The Thailand SEC noted that filing a criminal complaint does not represent a final determination of guilt. 

Bitkub Says Disclosure Decision was Intended to Prevent Customer Losses

Following media reports about the complaint, Bitkub published a statement on LinkedIn explaining its position on the cyberattack and the subsequent reporting decisions.  The company said the allegations relate to an incident in early May 2021, when one of its digital asset wallets was compromised by cybercriminals. Bitkub acknowledged that the breach was not disclosed at the time.  According to the company, the individual responsible for disclosure obligations deliberately withheld information about the wallet compromise. Bitkub said the decision was made to avoid triggering a "bank run," or mass withdrawals of digital assets by customers, while the company worked to replace the stolen assets.  The exchange stated:  "The decision of such individual not to disclose the incident was made with the intention to prevent a bank run—that is, a mass withdrawal of digital assets by customers upon learning of the theft—which could have rendered the Company unable to procure sufficient replacement digital assets for the customers while the recovery process was still ongoing."  Bitkub added that such a scenario could have resulted in significant customer losses and broader damage to Thailand's digital asset industry.  The company also stressed that, at the time of the Bitkub cyberattack, all of its digital asset wallet security systems complied with standards prescribed by the relevant authorities and had been audited. 

Co-founders Replaced Stolen Assets After Cyberattack on Bitkub 

Although the digital assets stolen during the cyberattack on Bitkub were never recovered, the company said its co-founders voluntarily absorbed the financial loss.  According to Bitkub, the co-founders purchased digital assets matching the same types and quantities as those stolen and transferred them to the company. As a result, the exchange said neither its customers nor the business ultimately suffered any financial loss from the incident.  In its statement, Bitkub said:  "As no bank run occurred, even though the stolen digital assets could not be recovered, the Co-Founders of the Bitkub Group voluntarily absorbed the loss by purchasing equivalent digital assets (in the same type and quantity as those stolen) and providing them to the Company. Consequently, neither the Company nor its customers suffered any financial loss from the theft." 

Thailand SEC Previously Confirmed Customer Assets Were Intact 

Bitkub also pointed to the findings of an earlier inspection conducted by the Thailand SEC after reports of the Bitkub cyberattack surfaced online. According to the company, the regulator verified that, as of 8 September 2025, all customer assets held by the exchange were safe and fully accounted for.  The company reiterated this point in its latest statement, saying:  "At the outset, for the sake of clarity and mutual understanding, the Company wishes to affirm that all customers' assets currently held by the Company are safe and fully accounted for. The Company reiterates its strict compliance with all applicable laws and regulations in safeguarding and maintaining customer assets."  Bitkub maintained that the criminal complaint relates to historical reporting practices between May and October 2021, more than five years ago, rather than to the current condition of customer assets or any ongoing security concerns.  As the investigation proceeds, the case will determine whether the company's reporting following the Bitkub cyberattack complied with regulatory requirements. For now, the complaint remains an allegation, and the legal process involving the Thailand SEC, investigators, prosecutors, and the courts has yet to reach a final conclusion. 
  • ✇Firewall Daily – The Cyber Express
  • Wireshark 4.6.6 Resolves ROHC Parser and Buffer Overflow Vulnerabilities Ashish Khaitan
    The Wireshark Foundation has released Wireshark 4.6.6, delivering an important round of security and stability updates that address a serious Dissector Crash vulnerability tied to the ROHC protocol parser, along with a separate global-buffer-overflow flaw affecting MACsec traffic analysis. The release focuses heavily on improving reliability for users handling untrusted packet captures and production monitoring environments.  At the center of the update is a security issue identified as wnpa-
     

Wireshark 4.6.6 Resolves ROHC Parser and Buffer Overflow Vulnerabilities

Wireshark 4.6.6

The Wireshark Foundation has released Wireshark 4.6.6, delivering an important round of security and stability updates that address a serious Dissector Crash vulnerability tied to the ROHC protocol parser, along with a separate global-buffer-overflow flaw affecting MACsec traffic analysis. The release focuses heavily on improving reliability for users handling untrusted packet captures and production monitoring environments.  At the center of the update is a security issue identified as wnpa-sec-2026-51, tracked internally as Issue 21243. The flaw involved Wireshark’s ROHC (Robust Header Compression) dissector, the component responsible for decoding compressed IP packet headers during network analysis. According to the release notes, attackers could exploit the weakness by injecting a malformed packet into a live traffic capture or by supplying a crafted .pcap file. Successful exploitation could trigger a Dissector Crash, interrupting packet analysis sessions and potentially affecting operational monitoring systems. 

The ROHC Vulnerability 

The newly patched ROHC vulnerability emerged during fuzz testing campaigns conducted in May 2026. Researchers found that malformed packet injection could destabilize the protocol parser, exposing weaknesses in how Wireshark processed specific ROHC packet sequences. Because Wireshark is commonly used in enterprise monitoring, forensic investigations, and protocol debugging, the risk associated with a remotely triggered Dissector Crash raised concerns for security teams working with external or untrusted traffic captures.  In addition to the ROHC issue, developers also fixed a MACsec dissector global-buffer-overflow vulnerability tracked as Issue 21235. The flaw created a memory safety risk while parsing IEEE 802.1AE-secured traffic. The global-buffer-overflow condition was also identified through fuzz testing and represented another example of how malformed network traffic could affect protocol dissectors inside Wireshark. 

Wireshark 4.6.6 Introduces Stability and Windows Compatibility Fixes 

The Wireshark 4.6.6 release includes several other significant fixes aimed primarily at improving Windows compatibility and application stability. One major correction resolved a Windows crash affecting Visual Studio environments, documented under Work Item 24787. Developers also fixed uninitialized memory reads in both the pntoh16 and find_signature functions within the VeriWave (vwr) file reader, tracked under Issues 16460 and 16461.  Another high-profile issue involved compatibility problems introduced in Wireshark 4.6.5. Users reported that the software failed to run correctly on Windows 10 version 1809, Windows Server 2019, and certain Long-Term Servicing Channel (LTSC) editions. The regression, listed as Issue 21237, has now been resolved in the latest release.  The update also corrects an installation problem on Windows systems where optional features could be accidentally removed during upgrades if users did not explicitly preserve them. That issue was tracked as Issue 18925. Developers further addressed a packaging problem that caused Wireshark.exe version 4.6.5 to become nearly twice the size of version 4.6.4. The oversized executable issue, documented as Issue 21233, has now been fixed.  Two additional fuzz testing crashes discovered in May 2026 capture files, tracked as Issues 21240 and 21253, were also resolved as part of the release. These fixes collectively strengthen Wireshark’s resilience against malformed packet processing and parser instability.  Wireshark 4.6.6 now ships with Npcap 1.88, replacing the previously bundled Npcap 1.87 release. The updated packet capture library is intended to improve low-level packet capture reliability on Windows platforms. Although no entirely new protocols were introduced in this version, dissector support received updates for several technologies, including BACapp, MACsec, ROHC, Kafka, SIP, PFCP, and BPv7. Capture file handling improvements also extend to JSON and VeriWave formats.  On Unix-based systems, extcap binaries now default to the /usr/libexec/wireshark/extcap directory. While this behavior was originally introduced in Wireshark 4.6.0, the change has now been formally documented as part of the 4.6.6 release cycle. 
  • ✇Firewall Daily – The Cyber Express
  • Medtronic Confirms Data Breach, No Impact on Operations or Patient Safety Ashish Khaitan
    Medtronic, the global leader in medical technology, disclosed a data breach affecting its corporate IT systems. On April 24, the company confirmed that an unauthorized third party gained access to certain systems, although the Medtronic data breach is not expected to have any material impact on the company’s financial performance or business operations. The breach has raised concerns across the healthcare and medtech sectors, but Medtronic assured investors and customers that it had taken imm
     

Medtronic Confirms Data Breach, No Impact on Operations or Patient Safety

Medtronic data breach

Medtronic, the global leader in medical technology, disclosed a data breach affecting its corporate IT systems. On April 24, the company confirmed that an unauthorized third party gained access to certain systems, although the Medtronic data breach is not expected to have any material impact on the company’s financial performance or business operations. The breach has raised concerns across the healthcare and medtech sectors, but Medtronic assured investors and customers that it had taken immediate action to contain the situation.

What Happened to the Medtronic Data Breach? 

The Medtronic data breach, which was identified on April 24, involved unauthorized access to some of Medtronic’s corporate IT systems. However, the company was quick to clarify that no disruption had occurred in key operational areas, including product safety, customer connections, and manufacturing or distribution activities. Importantly, there was no reported impact on patient safety or the company’s ability to meet its patient care commitments. In a public filing with the U.S. Securities and Exchange Commission (SEC), Medtronic stated, “We have not identified any impact to our products, patient safety, connections to our customers, our manufacturing and distribution operations, or our financial reporting systems.” The company emphasized that the networks supporting corporate IT systems are separate from those used for products, manufacturing, and distribution, which remain unaffected by the breach. Additionally, Medtronic highlighted that the IT systems supporting hospitals and healthcare customers are managed separately and secured by the customers’ IT teams. As such, hospital networks were not impacted by the breach, nor was there any disruption to hospital operations or services.

Immediate Actions Taken by Medtronic 

Following the identification of the breach, Medtronic moved quickly to contain the incident. The company activated its incident response protocols and sought assistance from cybersecurity experts to investigate the breach and implement necessary remediation measures. Medtronic has also initiated an effort to determine if any personal information was accessed during the breach. If any sensitive data has been compromised, the company assured it would provide necessary notifications and support services to affected individuals. The company remains committed to enhancing its cybersecurity measures. “We are simultaneously identifying additional ways to further optimize our system security,” said a Medtronic spokesperson. The company has also assured its stakeholders that it does not expect the incident to have an impact on its financial results or overall business operations.

The Broader Impact on the Medtech Sector 

The data breach at Medtronic follows a series of similar cybersecurity incidents that have affected other companies in the medtech industry. In March 2026, a cyberattack disrupted operations at Stryker, another major player in the medical technology sector. The attack targeted Stryker’s Microsoft environment, affecting ordering, shipping, and manufacturing processes. It took several weeks for Stryker to fully recover and return to normal operations. Simultaneously, Intuitive Surgical, a leading manufacturer of surgical robots, reported a phishing incident. The unauthorized party gained access to sensitive customer, employee, and corporate data. Intuitive Surgical also claimed that the issue was contained without significant financial impact, echoing Medtronic’s own assessment that the data breach would not affect its financial standing. These incidents highlight the frequency and sophistication of cyberattacks within the healthcare and medtech industries. As digital transformation accelerates in these sectors, companies are vulnerable to cyber threats.
❌
❌