Rust Supply Chain Attack: Malicious Crates with 245M Downloads Target Build-Time Execution
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
Google Threat Intelligence Group attributes the axios npm compromise to MIDNIGHT NEPTUNE, formerly known as UNC1069. The actor is linked to North…
North Korean IT workers are increasingly infiltrating government agencies and businesses by applying for remote jobs, passing interviews, and obtaining legitimate credentials.…
Security researchers created a fictitious cryptocurrency startup and hired three individuals they believe were North Korean IT operatives, as part of an…
Silent Push is a threat intelligence company that has separately tracked AstrillVPN as a fixture in North Korean cyber operations. Their research…
AstrillVPN is a virtual private network service that has been observed as a fixture in North Korean cyber operations. In the undercover…
North Korea's Kimsuky hacking group, operating under the Reconnaissance General Bureau, has been assembling an offline artificial intelligence (AI) stack on its…
The Reconnaissance General Bureau (RGB) is North Korea's primary military intelligence agency, overseeing cyber operations. Kimsuky operates under its direction, conducting espionage…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Six npm packages use the NullReceiver technique, fetching next-stage payloads via Ethereum transactions linked to North Korean threat actors, evolving from EtherHiding.