Top

CertiK Skyfall research team inducted into Samsung Mobile Security Rewards Program Hall of Fame

Web3 & Enterprise·January 25, 2024, 6:11 AM

Global blockchain security ranking platform CertiK announced that its Skyfall research team has been inducted into the Samsung Mobile Security Rewards Program’s 2023 Hall of Fame, according to an article by South Korean news outlet Greenpost Korea on Thursday (KST).

https://asset.coinness.com/en/news/a9bbc815696c54bad7b2a3dbe873910d.webp
Photo by Franck on Unsplash

Teamwork excellence

This Hall of Fame recognizes outstanding security researchers who have made significant contributions each year to the security of Samsung products. CertiK Skyfall’s spot in the ranking highlights the importance of collaborative efforts in solving complex cybersecurity challenges, the company said.

 

Securing the future

The team was responsible for actively identifying a total of seven vulnerabilities in the Samsung Blockchain Keystore – a software development kit (SDK) developed by Samsung to manage private keys – four of which were critical and three of which were high risk. The vulnerabilities left the SDK susceptible to local attacks, including arbitrary code execution and unauthorized access to sensitive data. In response, Samsung was able to quickly deploy security patches that added appropriate boundary checks and protection mechanisms.

 

Skyfall has formerly been acknowledged twice in Apple's release notes for discovering multiple vulnerabilities in new iOS and iPadOS software releases, the most recent being iOS 17 Security Update. Last June, the team was also awarded the Sui network’s highest bug bounty for discovering and fixing a critical vulnerability.

 

"We are extremely proud of the outstanding performance of the CertiK Skyfall team," said Kang Li, Chief Security Officer at CertiK. "It is a testament to the team's professionalism, integrity and deep impact at the forefront of cybersecurity."

 

CertiK is comprised of a team of seasoned experts from reputable universities including Yale and Columbia University and globally renowned companies like Google and Microsoft. The firm also operates from several offices around the world, including Seoul.

More to Read
View All
Web3 & Enterprise·

Feb 08, 2024

Layer 2 startup LightLink gets $4.5M backing

LightLink, the Singapore-based Layer 2 startup, has recently clinched $4.5 million in seed funding, spearheaded primarily by Asian investors. A strategic alliance has also been forged between LightLink and Animoca Brands, a trailblazer in digital property rights within the open metaverse and gaming sectors.Photo by cottonbro studio on PexelsThai-led fundingT&B Media Global, a prominent Thai media entity, and MQDC, a Bangkok-headquartered real estate developer, led the funding round, which amounted to $4.5 million. In addition to T&B Media Global and MQDC, the seed round saw participation from more notable investors within the Asia Pacific (APAC) and Oceania regions, such as digital asset-focused Australian investment manager JellyC, Aweh Ventures, Singapore’s Blue7 and Australian Web3 venture capital fund B3V. While the capital funding is early stage and lower end from a dollar amount perspective, the broad spectrum of investors underscores a certain level of excitement surrounding LightLink's innovative product offering. The startup’s product offering enables enterprises and decentralized applications to conduct gasless, real-time user transactions within the Ethereum ecosystem through the use of optimistic rollups within LightLink’s established architecture. The infusion of funds will be used to bolster LightLink's efforts to further develop a groundbreaking "multiverse project" dubbed Translucia, a venture that attempts to seamlessly merge virtual and physical realms. Dr. Jwanwat Ahriyavraromp, founder and CEO of T&B Media Global, lauded the partnership, citing a shared vision to cultivate a harmonious and interconnected digital universe that radiates joy worldwide. Animoca collaborationNews of this funding infusion comes off the back of LightLink’s announcement last month of a collaboration with Web3 firm Animoca Brands. This collaboration will witness Animoca integrating LightLink's Ethereum Layer 2 technology into select initiatives, accompanied by advisory support to bolster LightLink's tokenomics strategies and market outreach. The synergy between these entities provides great potential for the delivery of a more seamless Web3 experience, eliminating transaction fees and streamlining blockchain integration for users. LightLink's Ethereum Layer 2 blockchain offers a host of benefits, enabling gasless transactions and frictionless transfers of assets within a public blockchain environment. Its utilization extends to over 25 affiliates, including notable entities like Grapes and The Red Village, with integration into the Translucia project underway. Roy Hui, co-founder and CEO of LightLink, expressed optimism about the partnership's potential to democratize blockchain technology, fostering global connectivity and enabling diverse communities to embrace decentralized solutions. Yat Siu, executive chairman and co-founder of Animoca Brands, echoed this sentiment, emphasizing the alignment between LightLink's gasless transactions and their mission to decentralize the digital realm. Pellar Technologies, the development powerhouse behind LightLink, boasts a track record of over 50 blockchain projects across the APAC region since 2017. LightLink itself ranks among the top 10 in transaction volumes among rollups, boasting over 215,000 unique wallet addresses operating on-chain. Hui reiterated LightLink's commitment to simplifying blockchain adoption. Using the seed funding announcement as an opportunity to set out the firm’s primary objective, he stated:”Our aim is to bridge the digital economy with millions of users across the globe. The funding we've received enhances our focus on making blockchain as intuitive as traditional web platforms, with an emphasis on gasless transactions.” The seed funding marks a significant milestone in LightLink's journey, propelling it towards playing its part in the further roll-out of Web3 innovation.  

news
Policy & Regulation·

Oct 06, 2023

Korean Police Establishes Task Force to Tackle Virtual Asset-Related Crimes

Korean Police Establishes Task Force to Tackle Virtual Asset-Related CrimesIn response to the recent increase in virtual asset-related crimes in South Korea, the country’s police agency is establishing a dedicated task force to combat these illegal activities, according to local media outlet News1. This action by the National Police Agency comes as virtual asset legislation gained momentum and as prosecutors launched a joint virtual asset investigation division. Additionally, the police are considering establishing a new regional investigation unit focused on virtual asset-related investigations in the future.Photo by Sungho Song on PixabayMulti-divisional approachDuring this month, the police will consolidate various functions related to virtual asset investigations within its headquarters to establish the task force. This group will convene monthly meetings to exchange information on ongoing investigations and will also extend invitations to on-site investigators for the purpose of studying the most effective investigative methods and staying updated on the latest trends in virtual asset-related crimes.The task force will be jointly overseen by the heads of the Cyber Investigation Bureau and the Investigation Bureau and will consist of members from several divisions, including the Cyber Investigation Planning Division, Economic Crime Investigation Division, Cybercrime Investigation Division, Cyber Terrorism Response Division, Narcotic and Organized Crime Investigation Division, and National Security Investigation Command Division.Escalation of virtual asset crimesBy the end of the first half of this year, the global crypto market value reached $1.17 trillion, coinciding with a notable uptick in crypto-related criminal activities. In 2021, there were 427 instances of domestic fraud cases linked to cryptocurrencies, resulting in the arrest of 1,717 individuals. However, in 2022, these numbers increased to 628 cases involving 2,123 people. Furthermore, from January to July of the current year, the police have apprehended 1,146 individuals in connection with 327 cases related to cryptocurrency crimes.However, responding to virtual asset-related crimes presents a significant challenge due to their diverse nature and wide-ranging applications. For example, incidents involving crypto hacking typically fall under the jurisdiction of the Cybercrime Investigation Division. On the other hand, cases related to fraudulent crypto investment schemes are typically handled by the Economic Crime Investigation Division, while the Narcotic and Organized Crime Investigation Division concentrates on instances of drug trading conducted using cryptocurrencies.Paving the way for specialized expertiseFurthermore, as part of the task force’s efforts, the police will seek input and feedback regarding the potential establishment of a new department focused exclusively on investigating virtual assets in the future. A police official mentioned that the creation of such a dedicated unit is seen as a desirable step that could facilitate the development of specialized expertise among on-site officers. Looking ahead, the police are also contemplating the formation of a regional investigation unit specifically dedicated to cryptocurrency-related investigations, a unit akin to the existing Financial Crimes Investigation Unit.Upcoming law implementationThe police’s decision to form a working group is seen as a proactive step in preparation for the forthcoming Virtual Asset User Protection Act, slated to take effect in July next year. This legislation is designed to enable legal action against unfair trading practices related to virtual assets, including the misuse of undisclosed information, market manipulation, and illicit transactions. It parallels the regulatory framework applied to financial investment products.In August, public prosecutors took action by launching a joint cryptocurrency investigation division at the Seoul Southern District Prosecutors’ Office in collaboration with several key agencies, including the Financial Supervisory Service (FSS), Financial Intelligence Unit (FIU), National Tax Service (NTS), Korea Customs Service (KCS), Korea Deposit Insurance Corporation (KDIC), and Korea Exchange (KRX). Moreover, in light of the growing importance of legal issues related to cryptocurrencies, prominent law firms have been swiftly mobilizing to establish specialized teams dedicated to handling crypto legal cases.This trend is not limited to South Korea alone; it is also unfolding in other countries. For instance, in a parallel development, the Hong Kong Police Force and the Securities and Futures Commission (SFC) have recently instituted a working group to monitor and address suspicious activities linked to virtual asset trading platforms (VATPs).

news
Web3 & Enterprise·

Sep 19, 2023

KSOC to Implement Blockchain-based Athlete Management Platform

KSOC to Implement Blockchain-based Athlete Management PlatformThe Korea Sport and Olympic Committee (KSOC) held an initiation briefing on Monday to develop a blockchain-based career and performance management platform for athletes in collaboration with the Ministry of Science and ICT. This project aims to promote environmental, social, and governance (ESG) management by promoting eco-friendly approaches to sports management.Photo by Sandro Schuh on UnsplashThe KSOC was selected by the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) in May to participate in a contest focusing on the implementation of blockchain technology in the public sector through the development of new platforms and services. This granted them the opportunity to undertake a blockchain project worth KRW 1.3 billion (approximately $978,000).Representatives from various entities such as the KSOC and KISA and schools like Korea National Sport University and Yongin University attended the briefing on Monday, as well as sporting organizations like the Korea Basketball Association, the Korea Baseball Association, and the Korean University Sports Federation (KUSF).Revolutionizing athlete certificationThe primary focus of the project is to digitize certification for athlete performance, which is one of the documents submitted during the admissions process for special athletes under the KUSF. This document is issued by the respective sports associations and verifies the validity of the performance records of athletes in major competitions. The KSOC currently manages the performance records of nationwide competitions for more than 60 member sports associations, including the Korea Basketball Association, the Korea Baseball Association, and the Korea Taekwondo Association.Embracing digital transformationThe project will thus facilitate a transition from printing and manually submitting paper certificates to a digital format that allows for online submission to involved institutions. This change is expected to reduce paper usage and postal costs as well as save time and simplify processes, thereby contributing to environmental protection and improved ESG management.Additionally, the KSOC said that it would work on providing digital badges for athlete identification through a decentralized identifier (DID) system.These various elements of the project will ensure a more transparent and secure management of performance records and history free from tampering or leaks. The new system is expected to be fully implemented starting at the end of this year.Furthermore, the KSOC plans to continuously strive for the digitization and expansion of the sports sector through the implementation of emerging technologies.

news
Loading