Blogs
US Charges Five People Over North Korean IT Worker Scheme
Summary: U.S. prosecutors charged five people in connection with an alleged scheme that helped North Korean IT workers obtain remote jo...
In Other News: VPN Supply Chain Attack, PayPal $2M Settlement, RAT Builder Hacks Script Kiddies
Summary: This security roundup highlights three unrelated incidents with a shared lesson: trusted software, routine payment workflows a...
North Korean Fake IT Workers More Aggressively Extorting Enterprises
Summary: U.S. authorities and incident responders warned that fraudulent North Korean remote IT workers have increasingly shifted from ...
Subaru Starlink Vulnerability Exposed Cars to Remote Hacking
Summary: Security researchers Sam Curry and Shubham Shah found flaws in Subaru’s employee-facing STARLINK administration portal that co...
FBI: North Korean IT worker scheme involves source code theft, extortion
Summary: The FBI warned U.S. organizations that fraudulent North Korean IT workers are stealing source code and other sensitive data, t...
Cloud-targeted attacks conducted by TRIPLESTRENGTH operation
Summary: Google Cloud’s Threat Horizons research described TRIPLESTRENGTH, a financially motivated operation that combined cloud accoun...
New Trump AI order pursues new action plan
Summary: President Donald Trump signed an executive order on January 23, 2025 directing the U.S. government to prepare a national artif...
Enterprise Juniper routers subjected to malware campaign
Summary: Black Lotus Labs documented a campaign called J-Magic that placed a custom backdoor on enterprise Juniper routers and waited f...
More robust BC malware with QBot ties emerges
Summary: Security researchers described a more capable BackConnect malware family associated with the QBot ecosystem. The tool gives op...
Most online Exchange Servers vulnerable to ProxyLogon still not remediated
Summary: Tenable reported in January 2025 that 91% of nearly 30,000 internet-facing Microsoft Exchange Server instances it identified a...