« Reports in 2026

593 reports

2026-05-15 • North Scan

NorthScan links Beejern, an active Oklahoma LLC, to a suspected DPRK IT worker network through GitHub identity cycling, DPRK-associated developer personas, exposed Beejern credentials, and reused company infrastructure. The GoldenDev321 account previously…

#ITWorker
2026-05-14 • Kaspersky

Kimsuky has expanded its PebbleDash and AppleSeed-related operations with newly documented tooling, including the Rust-based HelloDoor backdoor, httpMalice, MemLoad/httpTroy, AppleSeed, HappyDoor, VSCode Remote Tunneling, and DWAgent. The campaigns use sp…

#Kimsuky #Phishing #AppleSeed #PebbleDash #BlackBanshee #VelvetChollima #GitHub #ADS #APT43 #RubySleet #Springtail #HappyDoor #JSE #SparklingPisces #HttpTroy #VSCode #T1059.003 #T1005 #T1041 #T1113 #T1071.001 #T1056.001 #T1027 #T1566.001 #T1547.001 #T1053.005 #T1059.001 #T1105 #T1219 #T1543.003
2026-05-14 • Krypt3ia

Krypt3ia assesses that enterprise AI systems are becoming high-value operational infrastructure because they ingest sensitive data, connect to internal workflows, and increasingly act with delegated authority. The North Korea-focused section argues that D…

#Trend
2026-05-12 • nambrot

An attacker attributed by LayerZero to the DPRK drained about $292 million in rsETH from KelpDAO's LayerZero-powered OFT bridge on April 18, 2026. The excerpt says the attacker compromised Unichain RPC infrastructure used by LayerZero Labs' Gasolina DVN s…

#KelpDAO