POLYMARKET CONFIRMS BREACH, REFUNDS STOLEN FUNDS
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Prediction market platform Polymarket disclosed a security breach where hackers stole user funds through a third-party vulnerability. The company announced it will refund affected users.
■ MORE FROM THE SECURITY DESK
Threat actors are exploiting Shopify's Shop order-tracking app by injecting fake purchase receipts into user accounts. The attacks trick victims into revealing sensitive data or installing remote access malware.
A newly discovered macOS malware called Gaslight uses embedded fake errors and prompt injection strings to evade AI-powered malware analysis systems. The technique represents a new approach to defeating automated security tools.
Russia allegedly exploited a forensics platform to compromise an activist's phone, even after the tool's maker lost access. Cellebrite says the hardware predates current sanctions and was used without authorization.
Password manager LastPass has notified users of yet another security incident involving unauthorized access to customer data. The breach marks the latest in a series of security lapses affecting the popular service.