1h yang lalu
Pembeli di Hong Kong kehilangan HK$1.23 juta setelah tergiur penawaran laptop murah online
Seorang pembeli di Hong Kong kehilangan HK$1.23 juta setelah mengirim 80 kali transfer kepada penipu yang menyamar sebagai penjual laptop selama 30 hari. Sebagian pembayaran dilakukan melalui ATM Bitcoin, sehingga peluang pemulihan dana dinilai kecil karena transaksi kripto bersifat tidak dapat dibatalkan. Polisi menilai korban terus membayar karena terjebak “sunk cost fallacy”, di mana tiap biaya baru terasa seperti langkah terakhir untuk mendapatkan kembali uang yang sudah terlanjur dikirim.
BTC
BTC-3.67%
1h yang lalu
6-9
OpenAI plans major ChatGPT redesign into a superapp ahead of IPO option
OpenAI is preparing its largest ChatGPT revamp since 2022, aiming to turn the chatbot into a superapp that bundles coding tools, AI agents, and third-party integrations. The rollout is expected to surface on the web and mobile apps in the coming weeks as the company looks to convert a nearly 1 billion mostly free weekly user base into paid usage, helped by Codex’s more than 5 million weekly active users.
BTC
BTC-3.67%
6-9
6-9
Reaper macOS infostealer abuses Script Editor to target Ledger, Trezor, Exodus
Reaper, a macOS infostealer, is spreading via fake download pages impersonating apps such as WeChat and Miro, then using Script Editor to execute hidden AppleScript. It targets desktop wallet software including Ledger Live, Trezor Suite, and Exodus, while also stealing browser passwords and sensitive files. Victims are prompted by a fake Apple security update dialog to enter their Mac password before data theft begins.
6-9
6-6
Arweave-linked WeaveDB npm packages trojanized to drop IronWorm malware
A Rust-based infostealer dubbed IronWorm was embedded in 36 npm packages connected to the Arweave/WeaveDB ecosystem, targeting developer credentials, SSH keys, and Exodus wallet files. The malware ran via a preinstall hook during npm install, searched 86 environment variables and 20 credential files, and used stolen GitHub tokens to spread through malicious commits. Security researchers advised anyone who installed the affected packages to rotate exposed secrets and harden npm/GitHub accounts.
AR
AR-5.21%
6-6