« Reports in 2026

508 reports

2026-01-21 • Runjak

A suspicious developer coding test used VS Code task definitions to pipe OS-specific commands from Vercel-hosted endpoints into shell or cmd, creating a likely script-execution risk for job applicants. Repository history showed several infrastructure vari…

2026-01-20 • Piolink

Kimsuky is described using malicious QR codes in spearphishing emails to move victims from managed desktops to less-protected mobile devices and evade URL inspection and sandboxing. The campaign targets think tanks, academic institutions, government-relat…

#Kimsuky #DocSwap
2026-01-20 • Picus Security

BlueNoroff is presented as the financially motivated arm of Lazarus, evolving from SWIFT and bank intrusions such as the Bangladesh Central Bank heist into sustained cryptocurrency and Web3 targeting. The excerpt traces campaigns including SnatchCrypto, f…

#Bluenoroff #T1082 #T1005 #T1587.001 #T1071.001 #T1059.007 #T1566.002 #T1566.003 #T1543.001 #T1059.005 #T1583.003 #T1204.004 #T1547.001 #T1583.001 #T1036.005 #T1552.001 #T1059.002 #T1055 #T1562.001 #T1027.002 #T1593 #T1589 #T1016 #T1018 #T1548.002 #T1598.001 #T1074.001 #T1087.001 #T1588.002 #T1056.002 #T1176.001 #T1543.004 #T1027.010 #T1548.006 #T1657
2026-01-19 • Ahnlab

North Korean state-sponsored groups are described as expanding hybrid intrusion models that combine fake IT employment schemes, remote-work abuse, and malware delivery changes. Famous Chollima targeted U.S. and Western companies through fraudulent remote …

#Trend #Lazarus #FamousChollima