Bitget’s $388 Million Breach Now Points to a Third-Party Security Product

Bitget says its $388 million breach may have begun in a third-party security product, exposing credentials used to send fraudulent withdrawal commands.

Bitget says its $388 million breach may have begun in a third-party security product, exposing credentials used to send fraudulent withdrawal commands.

The extension did not need to persuade the model. It impersonated the channel the browser’s privileged assistant was built to trust.

The dangerous path begins with ordinary submitted data and ends when a vulnerable custom format renders it as template code.

The bulletin contains six separate vulnerabilities. The most urgent crosses the authorization boundary before an attacker has any account.

A fake TV app can cut Google Play Protect off from the network, watch a victim’s screen, steal banking PINs and resist removal.

WordPress fixed a conditional code-execution path on 22 September. Within hours, attackers were trying to turn the flaw into PHP file writes.

The compromise is confirmed. The route in and the alleged theft of employee data are not. The distinction matters because recruitment systems hold unusually revealing records.

A compromised orchestrator is not just another vulnerable server. It is the trusted control point for the edge devices around it.

The AI did more than write convincing phishing messages. It read stolen mailboxes, mapped trust and told criminals which relationships were most valuable to abuse.

F5 says attackers are already exploiting a critical BIG-IP APM flaw. The first job is not simply to patch, but to preserve evidence and find out whether the gateway has already been touched.