ByteScan Logo
ByteScan.net GmbH
Cybersecurity Research & Audit

25+
40+
20+
70+
ISO 27001 CVE/MITRE DeFi ZKP


ISO 27001
Global
Information security management
BSI IT-Grundschutz
Deutschland
Federal security baseline
NIS2 Directive
Europäische Union
Critical infrastructure
DORA
Europäische Union
Financial sector resilience
Cyber Essentials
Vereinigtes Königreich
UK government-backed scheme
NIST CSF 2.0
Vereinigte Staaten
Enterprise risk framework
SOC 2 Type II
Vereinigte Staaten
SaaS trust criteria
GDPR Art. 32
EU / UK
Data processor obligations

05.06.2026

Gravity Bridge Security Incident

DeFi / Crypto - $5.4 million gone from Gravity Bridge after an attacker minted worthless tokens on Osmosis, poisoned the token registry with a fabricated denom string, and walked out with real assets.…

05.06.2026

Dxsale Security Incident

DeFi / Crypto - A 2021 DxSale locker, an unprotected admin key, $7.3 million gone. Decurity flagged the risk in 2023 for $500. Two compromised contracts holding $15.5 million remains untouched, for no…

05.06.2026

Newmarkettrading

New Market Trading - RektThursday, May 28, 2026New Market Trading - Access Control Failure - Rekt $3.98 million drained from 88 Gnosis Safes across Ethereum, Base, and Arbitrum in under two hours, Not…

01.06.2026

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions be…

26.05.2026

Thorchain Rekt3

THORChain - Rekt IIIThursday, May 21, 2026THORChain - Rekt Three exploits in five years. Toss in a $200 million insolvency crisis. Sprinkle $1.2 billion in North Korean laundering on top. The relation…

26.05.2026

Trustedvolumes Security Incident

TrustedVolumes - RektThursday, May 14, 2026TrustedVolumes - Authorization Failure - Rekt $5.87 million, one transaction, four assets drained before most of the security firms had finished typing their…

25.05.2026

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and …

22.05.2026

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor inten…

21.05.2026

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use…

18.05.2026

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS …

Medium Public 2026-04-10
vorbis-tools — oggenc 1.4.3

CVE Pending: SIGSEGV in oggenc 1.4.3 (vorbis-tools) via Crafted WAV File

A crafted WAV file triggers a null pointer dereference / segmentation fault (SIGSEGV) in oggenc 1.4.3, crashing the encoder unconditionally. No user interaction beyond passing the file to oggenc is required.

🏆 CVE — pending assignment
Medium Public 2026-03-31
Wings3D 3D Modelling Software — v2.4.1

CVE: Unhandled IEEE754 Special Values in Wings3D 2.4.1 OBJ Parser

A crafted Wavefront OBJ file containing IEEE754 special float values causes Wings3D to crash immediately on import. Root cause: unhandled function_clause exception in the Erlang OBJ parser.

🏆 CVE
Medium Public 2026-03-26
Scribus Desktop Publishing Software — v1.6.5

CVE: Uncontrolled Resource Consumption in Scribus 1.6.5

A crafted .sla project file with extreme numeric geometry values causes Scribus to enter an infinite loop during layout containment checking, consuming 99% CPU and triggering a system-wide memory pressure cascade.

🏆 CVE
Medium Public 2026-02-24
Actions Semiconductor — USB VID 10D6

CVE: Unsigned Firmware Update in Actions Semiconductor Platform

The firmware update tool performs zero cryptographic verification before flashing firmware over USB. An attacker with physical access can permanently compromise any affected device. Covers 12 USB Product IDs across multiple consumer brands.

🏆 CVE — pending assignment
Medium Public 2025-12-14
Shotcut / MLT Framework

CVE-2025-65834: Buffer Overflow in Shotcut 25.10.31

Buffer overflow in Shotcut video editor's MLT Framework image processing pipeline. An attacker can trigger out-of-bounds memory access via a crafted media file. CVE assigned by MITRE.

🏆 CVE-2025-65834 — assigned by MITRE

April 2026 · butterswap.io

Butter Network — Smart Contract Ecosystem Audit

BSC, Base, Arbitrum, Optimism, Polygon, Linea, zkSync, MAP Relay Chain
Public
8 Total
2 High
5 Medium
1 Low
$1.5M (at time of report) TVL
swapAndBridge() silently bypasses all fee collection across 7 chains — zero bridge fee revenue since deployment.

✉ audit@bytescan.net
Parity Technologies
Polkadot / Substrate
Blockchain Infrastructure
SAP SE
Enterprise Software
Enterprise Technology
University of Potsdam
Research Collaboration
Academia
TH Wildau
Technical University of Applied Sciences
Academia
CODE University
CODE University of Applied Sciences
Academia
SRH Berlin
SRH Berlin University of Applied Sciences
Academia
Graphcore
AI Processor Technology
Semiconductor
Imagination Technologies
GPU & AI IP
Semiconductor
Codasip
RISC-V Processor Design
Semiconductor
IQM Quantum Computers
Quantum Computing
Deep Tech
XMOS
Embedded Processing
Semiconductor
Pragmatic Semiconductor
Flexible IC Technology
Semiconductor
Dialog Semiconductor
Mixed-Signal ICs
Semiconductor