#North Korea
21 stories taggedNorth Korea.

Rust developers hit by supply-chain attack on arrayref crate
Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

North Korean IT Worker Infiltrated a Federal Agency, Boeing 737 Security Flaws Explored, and Refrigeration Systems Found Vulnerable
A roundup of three security stories that deserve more attention: a suspected North Korean operative who got hired at a US government agency, researchers who probed the computers aboard a Boeing 737, and critical flaws in industrial refrigeration controllers.

The fake new hire problem: how criminals slip in through remote onboarding
Gaps between background checks, laptop delivery and account setup are letting impostors join companies as staff. Here's how the trick works, and what stops it.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

Researchers Set Up a Fake Crypto Company and Hired Three Suspected North Korean IT Workers
The sting recorded every keystroke on the laptops the fake employer issued, exposing the paper trail of a scheme US officials say funnels wages back to Pyongyang.

Kimsuky Goes Offline: North Korean Spies Build Their Own Private AI Toolkit
South Korean researchers say the Kimsuky group has stopped relying on public chatbots and is now running AI on its own servers to sharpen phishing and speed up malware writing.

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.
Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and attack in hours rather than weeks. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea
A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division calling out state-backed hackers. A busy week of stories that almost slipped past.

North Korea-Linked Hackers Booby-Trap Korean Websites to Push Backdoors via AnySign4PC Flaw
A state-sponsored crew hijacked trusted South Korean sites and abused a weakness in a widely installed banking security tool to plant SIGNBT and COPPERHEDGE malware, no click required.

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers
What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

North Korean Hackers Run Fake Zoom and Teams Sites to Rob Crypto Wallets
BlueNoroff's phishing kit screens visitors' crypto wallets before deciding who gets the malware, researchers say.

North Korean Job-Interview Scam Hides Malware Inside Flag Images
Fake coding tests planted a four-stage stealer on developers' machines, with the payload smuggled inside SVG picture files.

North Korean Hackers Poisoned Over 100 Open Source Packages to Spy on Developers
A campaign called PolinRider has quietly corrupted legitimate software building blocks used by developers worldwide, planting tools that steal data and leave a hidden door open for attackers.

North Korean hackers flood open-source repositories with 108 booby-trapped packages
The Contagious Interview crew is back, seeding npm, Packagist, Go and Chrome with malware aimed at developers.

Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.