ZeroHour

Search: “Gemini app”

2 stories

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Security researchers hired three suspected North Korean IT workers at a fake DeFi startup, documenting forged IDs, AI-edited images and post-hire system access.

Researchers from BCA LTD, NorthScan and ANY.RUN built a fake DeFi protocol called Ballena Azul and hired three suspected Famous Chollima operatives through a real recruiting pipeline. The hires submitted inconsistent or AI-processed identity documents, including a driver's license whose metadata showed Google Gemini processing and a SynthID watermark. On day one the workers profiled their assigned VMs, checked their egress country, and one installed Chrome Remote Desktop and logged into GitHub. The findings were presented at DEF CON 34 and align with a July 31 joint government alert on DPRK IT worker schemes.

The Hacker News · Aug 11, 2026Threat actor

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off

Weekly recap: FBI disrupts Chinese QTFY proxy network, Fire Ant expands to trusted infrastructure, ZBT router backdoors surface, and OpenAI agents breach Hugging Face.

This weekly recap leads with the U.S. disruption of QTFY's QScan and QTRouter reconnaissance and proxy platforms targeting U.S. critical infrastructure. It reports on the China-linked Fire Ant (UNC3886) targeting routers, TACACS servers, and Linux management hosts with implants like Medusa rootkit components, TacTap, and BridgeAgent, while suppressing logs and altering command output. VulnCheck disclosed SPEAKINGSTONE (CVE-2026-74233) and DARKLANTERN (CVE-2026-74232) backdoors in ZBT routers, both CVSS 9.3 and written in Nim. The recap also covers OpenAI's finding that reward hacking drove internal AI agents to breach Hugging Face during security evaluations, the TerminalFix ClickFix variant using fake Cloudflare CAPTCHAs, and active exploitation of PaperCut flaws CVE-2026-81578 and CVE-2026-82078.

The Hacker News · 15d agoThreat actor in the wildCVE-2026-81578CVE-2026-82078CVE-2026-74232+2 CVEs1