Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
North Korean APT Targets Yanbian Gamers via Trojanized PlatformInfosecurity Magazine·May 5, 15:00 UTC · May 5, 2026Malware42
Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto WInfosecurity Magazine·Apr 29, 14:00 UTC · Apr 29, 2026Malware42
APT37 combines cloud storage and USB implants to infiltrate airSecurity Affairs·Mar 2, 12:38 UTC · Mar 2, 2026Threat actor60
North Korea’s ScarCruft Deploys KoSpy Malware, Spying on Android Users via Fake Utility AppsThe Hacker News·Dec 18, 07:30 UTC · Dec 18, 2025Malware42
Lazarus Group’s Operation DreamJob Targets European Defense FirmsInfosecurity Magazine·Oct 23, 14:30 UTC · Oct 23, 2025Threat actor45
North Korea’s APT37 deploys RokRAT in new phishing campaign against academicsSecurity Affairs·Sep 1, 10:49 UTC · Sep 1, 2025Malware55
Feds Seize $6.4M VerifTools Fake-ID Marketplace, but Operators Relaunch on New DomainThe Hacker News·Aug 30, 11:53 UTC · Aug 30, 2025Phishing & fraud30
North Korean Hackers Weaponize Seoul Intelligence FilesInfosecurity Magazine·Aug 29, 15:30 UTC · Aug 29, 2025Malware42
DHS Flew Predator Drones Over LA Protests, Audio Shows404 Media·Jun 10, 15:49 UTC · Jun 10, 2025Industry30
Kaspersky Links Head Mare to Twelve, Targeting Russian Entities via Shared C2 ServersThe Hacker News·Apr 3, 07:21 UTC · Apr 3, 2025RansomwareCVE-2023-38831CVE-2021-2685560
Intelligence chiefs insist Signal chat was a simple mistakeCyberScoop·Mar 26, 20:32 UTC · Mar 26, 2025Exploit / PoC in the wild60
North Korea-linked APT group ScarCruft spotted using new Android spyware KoSpySecurity Affairs·Mar 13, 16:17 UTC · Mar 13, 2025Malware55
AI-Powered Social Engineering: Ancillary Tools and TechniquesThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2025Phishing & fraud30
BadDNS: Open-source tool checks for subdomain takeoversHelp Net Security·Feb 3, 00:00 UTC · Feb 3, 2025Vulnerability30
Researcher Turns Insecure License Plate Cameras Into Open Source Surveillance Tool404 Media·Jan 9, 00:21 UTC · Jan 9, 2025Exploit / PoC45
North Korea-linked APT37 exploited IE zeroSecurity Affairs·Oct 19, 14:07 UTC · Oct 19, 2024Threat actor in the wildCVE-2024-38178CVE-2022-4112860
North Korean ScarCruft Exploits Windows ZeroThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2024Exploit / PoCCVE-2024-38178CVE-2020-1380CVE-2022-4112860
North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber AttacksThe Hacker News·Oct 3, 13:24 UTC · Oct 3, 2024Malware42
CosmicBeetle Deploys Custom ScRansom Ransomware, Partnering with RansomHubThe Hacker News·Sep 11, 06:02 UTC · Sep 11, 2024RansomwareCVE-2017-0144CVE-2020-1472CVE-2021-42278+3 CVEs160
'LOL No:' Maker of 'FUCK THE LAPD' Shirt Laughs at Cops' Copyright Threat404 Media·Apr 19, 19:24 UTC · Apr 19, 2024Industry30
Mysterious Kill Switch Disrupts Mozi IoT Botnet OperationsThe Hacker News·Nov 3, 04:33 UTC · Nov 3, 2023Malware30
The Signal Protocol used by 1+ billion people is getting a postArs Technica · Security·Sep 20, 13:59 UTC · Sep 20, 2023Industry30
STARK#MULE Targets Koreans with U.S. MilitaryThe Hacker News·Jul 29, 04:07 UTC · Jul 29, 2023Malware42
RedEyes Group Targets Individuals with Wiretapping MalwareInfosecurity Magazine·Jun 22, 16:30 UTC · Jun 22, 2023Malware42
North Korea-linked ScarCruft APT uses large LNK files in infection chainsSecurity Affairs·May 5, 22:20 UTC · May 5, 2023Ransomware60
North Korea's ScarCruft Deploys RokRAT Malware via LNK File Infection ChainsThe Hacker News·May 2, 11:26 UTC · May 2, 2023Malware42
Tonto Team Uses Anti-Malware File to Launch Attacks on South Korean InstitutionsThe Hacker News·Apr 28, 06:44 UTC · Apr 28, 2023Malware42
ScarCruft's Evolving Arsenal: Researchers Reveal New Malware Distribution TechniquesThe Hacker News·Mar 23, 06:08 UTC · Mar 23, 2023Malware42
North Korea's APT37 Targeting Southern Counterpart with New M2RAT MalwareThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2023MalwareCVE-2017-829147
Google Warns of Internet Explorer Zero-Day Vulnerability Exploited by ScarCruft HackersThe Hacker News·Dec 9, 17:03 UTC · Dec 9, 2022Exploit / PoC in the wildCVE-2020-1380CVE-2021-26411CVE-2022-4112860
APT37 used Internet Explorer ZeroSecurity Affairs·Dec 8, 15:08 UTC · Dec 8, 2022Threat actor in the wildCVE-2022-41128CVE-2017-019960
North Korea ScarCruft APT used previously undetected Dolphin Backdoor against South KoreaSecurity Affairs·Dec 1, 11:02 UTC · Dec 1, 2022Malware55
North Korea Hackers Using New "Dolphin" Backdoor to Spy on South Korean TargetsThe Hacker News·Dec 1, 09:22 UTC · Dec 1, 2022MalwareCVE-2020-1380CVE-2021-2641147
Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai Botnet MalwareThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2022Vulnerability in the wildCVE-2022-2296560
Warning: Yet Another Bitcoin Mining Malware Targeting QNAP NAS DevicesThe Hacker News·Dec 8, 06:33 UTC · Dec 8, 2021MalwareCVE-2020-2495CVE-2020-2496CVE-2020-2506+1 CVEs47
New Chinotto Spyware Targets North Korean Defectors, Human Rights ActivistsThe Hacker News·Nov 29, 13:14 UTC · Nov 29, 2021Malware42
Chinese Authorities Arrest Hackers Behind Mozi IoT Botnet AttacksThe Hacker News·Sep 2, 11:59 UTC · Sep 2, 2021Malware30
Mozi IoT Botnet Now Also Targets Netgear, Huawei, and ZTE Network GatewaysThe Hacker News·Aug 22, 09:35 UTC · Aug 22, 2021Malware42