Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS…
A sophisticated social engineering operation ongoing since at least December 2022, targeting software developers with fake job postings and coding challenges to…
Lazarus Group is a North Korean state-sponsored cyber threat actor known for sophisticated attacks targeting financial institutions, cryptocurrency exchanges, and software supply…
BlueNoroff is a North Korean state-sponsored threat actor known for targeting cryptocurrency exchanges, financial institutions, and individuals involved in the crypto space.…
ScarCruft, also known as APT37, is a North Korean state-sponsored hacking group known for spear-phishing campaigns and deploying malware like RokRAT and…
The North Korean state-sponsored hacking group ScarCruft (APT37) has been observed using spear-phishing emails impersonating Microsoft Account security notifications to deliver a…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…