threat-intel Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development North Korea's Kimsuky hacking group is building an offline AI infrastructure to bolster its phishing attacks and automate malware development. Security firm Genians discovered this setup, finding tools like Ollama, GPT4All, and Msty being run on Kimsuky's infrastructure, alongside developer libraries and transcription… The Hacker News · Aug 10, 2026 High KRaiphishingnorth korea
threat-intel North Korean hackers behind major open-source supply chain attacks, Amazon says North Korean hackers, operating under the alias SapphireSleet, have been responsible for a series of attacks targeting widely used open-source JavaScript packages. These attacks, spanning from March 2025 to March 2026, i… The Record · Jul 30, 2026 High KRnorth koreaopen sourcesupply chain
threat-intel New Kimsuky campaign compromised South Korean software vendors A new campaign by North Korean threat actor Kimsuky (APT43) targeted South Korean software vendors in 2025 and 2026, ultimately compromising their customers. The group leveraged social engineering and exploiting remote c… The Record · Jul 22, 2026 High KRnorth koreaapt43social engineering
threat-intel Hackers were inside South Korea's diplomat training system for 9 months Hackers gained unauthorized access to South Korea's diplomat training system for nine months, stealing personal information from former and current Ministry of Foreign Affairs employees. The breach was facilitated by a p… The Record · Jul 20, 2026 High KRdata breachzero-daydiplomacy
threat-intel Attackers vote themselves $20 million in BONK cryptocurrency Attackers exploited a governance mechanism within the decentralized finance project overseeing BONK cryptocurrency, draining $20 million worth of the token. This was achieved through a malicious governance proposal, leve… The Record · Jul 6, 2026 High KRdaogovernancecryptocurrency
supply-chain North Korean Hackers Target Open Source Developers in Supply Chain Attacks North Korean hackers, linked to the Contagious Interview operation, are engaging in a sophisticated supply chain attack targeting open-source developers. They are leveraging compromised GitHub repositories and malicious… SecurityWeek · Jul 6, 2026 High KRsupply-chaingithubopen-source
malware New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos A new remote access trojan (RAT) called ChocoPoC is targeting vulnerability researchers through deceptive proof-of-concept (PoC) repositories on GitHub. The malware, disguised within Python dependencies, steals sensitive… The Hacker News · Jul 2, 2026 High CVE-2025-64446CVE-2025-55182CVE-2025-14847KRproof-of-conceptremote access trojangithub
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
threat-intel AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family, dubbed AryStinger, is exploiting vulnerabilities in older Realtek RTL819X routers to create a reconnaissance network. Approximately 4,300 routers, primarily D-Link models, have been infected, scanni… The Hacker News · Jun 22, 2026 Medium CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSEreconnaissanceproxyiot
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
data-breach South Korea hits Coupang with record $409 million fine over data breach South Korea’s data protection regulator, the PIPC, has levied a record $409 million fine against Coupang, the country’s largest online retailer, following a significant data breach impacting tens of millions of customers… The Record · Jun 12, 2026 High KRdata breachauthenticationcustomer data
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
threat-intel Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels North Korean state-sponsored threat actor Kimsuky has expanded its arsenal and tactics, utilizing HTTPSpy, HelloDoor, and VS Code tunnels to target South Korean military and corporate entities between March and April 202… The Hacker News · May 29, 2026 High KRnorth koreanremote access trojansocial engineering
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel Can Laws Stop Deepfakes? South Korea Aims to Find Out This article reports on South Korea's proactive approach to combating deepfakes ahead of upcoming local elections. The country is implementing new laws, including Article 82-8 of the Public Official Election Act and the… Dark Reading · May 18, 2026 Medium KRdeepfakeaielection
threat-intel Kimsuky targets organizations with PebbleDash-based tools This report details the ongoing activity of the Kimsuky threat actor group, also known as APT43, who have been utilizing a PebbleDash-based malware platform to conduct targeted attacks. The group has significantly evolve… Securelist · May 14, 2026 High KRBRDEspear phishingremote access trojansouth korea