BTC $62,775.10 -1.23%
ETH $1,874.15 -0.34%
BNB $604.11 -0.96%
XRP $1.00 -0.41%
SOL $75.45 -0.26%
TRX $0.3331 -0.13%
DOGE $0.0693 -1.08%
ADA $0.1795 -2.69%
BCH $205.25 -3.69%
LINK $8.80 +0.61%
HYPE $56.59 -1.35%
AAVE $86.52 -2.56%
SUI $0.6760 -1.66%
XLM $0.1587 -1.24%
ZEC $486.75 -1.41%
BTC $62,775.10 -1.23%
ETH $1,874.15 -0.34%
BNB $604.11 -0.96%
XRP $1.00 -0.41%
SOL $75.45 -0.26%
TRX $0.3331 -0.13%
DOGE $0.0693 -1.08%
ADA $0.1795 -2.69%
BCH $205.25 -3.69%
LINK $8.80 +0.61%
HYPE $56.59 -1.35%
AAVE $86.52 -2.56%
SUI $0.6760 -1.66%
XLM $0.1587 -1.24%
ZEC $486.75 -1.41%

security

All
Article
Flash

OpenAI launches the GPT-5.6-Cyber model, enhancing vulnerability discovery and security research capabilities

OpenAI announced the expansion of its cybersecurity defense program Daybreak and launched the GPT-5.6-Cyber model specifically for the cybersecurity field, aimed at helping authorized security researchers and defense teams enhance their vulnerability discovery, threat analysis, and security testing capabilities. As attackers increasingly leverage AI to launch faster and larger-scale cyberattacks, defenders need to gain advanced AI capabilities in advance.This Daybreak offers two types of access: Daybreak Blue is aimed at most defense teams, providing general models such as GPT-5.6 Sol for vulnerability discovery, secure code review, malware analysis, incident response, and patch validation; Daybreak Red is aimed at advanced security research, providing GPT-5.6-Cyber for authorized vulnerability research, vulnerability validation, and security testing. GPT-5.6-Cyber is trained on GPT-5.6 Sol and optimized for cybersecurity tasks, including discovering zero-day vulnerabilities and analyzing exploit chains. It has been used in actual vulnerability research and has identified high-risk vulnerabilities in software, including the Chrome V8 JavaScript engine. Additionally, OpenAI stated that GPT-5.6-Cyber has also helped discover high-risk vulnerabilities in various domains, including privilege escalation vulnerabilities in mobile operating systems, remote code execution vulnerabilities in databases, and hundreds of privilege escalation vulnerabilities in operating system kernels.OpenAI also emphasized that Daybreak Red will only be accessible to approved individuals and organizations, controlling access through measures such as authentication, account security, monitoring, usage restrictions, and legal disclaimers. The company stated that it will continue to strengthen security monitoring, access management, and model security testing to reduce the risk of advanced cybersecurity models being abused.

Coldcard has suspended the automatic deletion of customer data due to a security incident and will retain relevant records in accordance with the law

The cryptocurrency hardware wallet manufacturer Coldcard has released an update on its customer data retention policy. Due to legal compliance requirements arising from the security incident disclosed on July 30, the company has temporarily suspended its original automatic customer data deletion mechanism.Previously, Coldcard's standard practice was to automatically clear customer records after 120 days, retaining only the user's email address and country information, while allowing customers to request early deletion of data at any time after product delivery. Coldcard stated that due to the security incident involving ongoing and potential legal proceedings, the company is obligated to retain records that may be relevant to litigation. Therefore, customer data that was originally scheduled for deletion will be temporarily retained until the law permits the resumption of normal processes.However, users can still request Coldcard to handle their personal information according to the original data retention policy. If users wish for their data not to be included in this legal retention scope, they can contact official customer service to make a request. Coldcard emphasizes that the retained data will be strictly protected, accessible only to authorized personnel, and will not be used for any purposes other than fulfilling legal obligations. The company will restore the previous automatic data deletion mechanism once legally permissible.

hot_img Expected direction of South Korea's secondary regulations on security tokens: allowing asset pooling and setting trading limits for general investors

According to the expected plan compiled by the Korea Digital Convergence Industry Association, the secondary regulations for Security Token Offerings (STO) in South Korea may include: allowing "pooling" issuance of similar types of underlying assets, setting over-the-counter trading limits for general investors, clarifying the licensing conditions and business scope for non-standard securities over-the-counter exchanges, and developing a phased roadmap for the tokenization of standard securities. In addition, the technical and financial requirements for issuer account management institutions are also expected to be included in the regulations.This expected plan is based on publicly available policy directions and industry discussions and is not an official version. Specific standards still need to be determined through legislative announcements, regulatory reviews, and other procedures. Previously, the STO market was primarily focused on single assets; if pooling is allowed, it could promote the issuance of multi-asset composite products such as music copyrights and real estate. The over-the-counter trading limits for general investors are expected to be higher than existing sandbox cases, but the final limits still need to balance investor protection and market liquidity. The status of non-standard securities over-the-counter trading platforms and existing operators, as well as the future path for the tokenization of standard securities (stocks, bonds), will be key focuses moving forward. The industry warns that after the regulations are implemented, the preparation time for related companies' systems and internal controls may be quite urgent.

The Ethereum Foundation provides security funding to WEBCAT to assist in wallet verification front-end code to prevent phishing attacks

According to official news, the Ethereum Foundation's "Trillion Dollar Security" (1TS) has announced a special grant to the Freedom of the Press Foundation (FPF) to support the ongoing development of the open-source tool WEBCAT, aimed at addressing the long-standing front-end code verification security gap in Ethereum wallets and decentralized applications (DApps).WEBCAT (Web-based Code Assurance and Transparency) is an open-source tool designed to help browsers verify whether the code loaded by a website matches the version publicly released by the developer.This funding will promote the expansion of WEBCAT to Ethereum wallets and application scenarios, enabling users to verify whether the front-end pages they access have been tampered with.The Ethereum Foundation stated that while HTTPS can verify the website a user is connected to and encrypt communication, it cannot prove that the front-end code actually running on the website is the same version released by the developer. If an attacker controls the website's front-end code, they may modify the transaction receiving address without the user's knowledge or induce the user to sign transactions that do not match the content displayed on the page.The Ethereum Foundation noted that front-end attacks have become a significant security risk for blockchain infrastructure, with malicious modifications to web interfaces potentially leading to supply chain attacks, DNS hijacking subsequent attacks, and user interface deception.WEBCAT was initially developed by the Freedom of the Press Foundation to enhance the code credibility of secure communication systems like SecureDrop.With this expansion into the Ethereum ecosystem, it will complement security measures such as "Clear Signing" in the 1TS program: the former helps wallets confirm that the application front-end has not been tampered with, while the latter helps users understand the transaction content they are approving.
app_icon
ChainCatcher Building the Web3 world with innovations.