Threat actors are increasingly acquiring expired domains—known as "dropcatch domains"—to inherit their reputation and traffic, redirecting victims to scams and malware. According…
North Korean IT workers are increasingly infiltrating government agencies and businesses by applying for remote jobs, passing interviews, and obtaining legitimate credentials.…
NorthScan, represented by Heiner García, contributed to the investigation by analyzing infrastructure and behavioral patterns of suspected DPRK operatives, helping to identify…
A massive operation involving 737 free VPN and proxy extensions on the Chrome Web Store has been uncovered, primarily targeting Russian-speaking users…
1.1.1.1AdGuard VPNadversary-in-the-middleAI Sidebar with Deepseek, ChatGPT, Claude, and more
Threat actors are actively exploiting a critical directory-traversal vulnerability in Broadcom's VMware vCenter, tracked as CVE-2026-59310 (CVSS 9.8), to gain persistent remote…
Microsoft Threat Intelligence has uncovered that the DeadLock ransomware group is leveraging decentralized infrastructure, including Polygon smart contracts and the Session messaging…
North Korea's Kimsuky hacking group, operating under the Reconnaissance General Bureau, has been assembling an offline artificial intelligence (AI) stack on its…
Genians is a South Korean security company that discovered Kimsuky's offline AI stack. It provides network access control and threat intelligence solutions,…