Bitget hacked via zero-day in third-party security products
Summary
Cryptocurrency exchange Bitget has reported that a recent hack, resulting in the theft of $387.5 million, was perpetrated by exploiting a zero-day vulnerability in third-party security products. The attackers gained access to Bitget's systems through this previously unknown flaw.
IFF Assessment
The exploitation of a zero-day vulnerability in security products represents a significant win for attackers, as it bypasses existing defenses and allows for undetected system compromise.
Defender Context
This incident highlights the critical risk associated with supply chain attacks and vulnerabilities in third-party software. Defenders must maintain rigorous oversight of all integrated security products and vendor relationships, with a focus on rapid patching and incident response capabilities for any identified zero-day exploits.