Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
2026-07-30T19:23:21Z•91343de1510ecc9e0334fc6eb16d0e7bbd050a10eabed5149b85c92a3e27c204
CVE-2026-20316Chaos ransomwareCisco FMCExchange OWALaundry BearMicrosoft TeamsNorth KoreaOT securityOWAReaperShinyHuntersVMwareVoid Blizzardactive exploitationarbitrary code executionauthentication bypassdata breachhealthcarenpmransomwarestatic credentialssupply-chain attackvirtual machine escapevishingwater utilitieszero-day
What happened
BleepingComputer reports a broad set of cybersecurity developments, including North Korean-attributed npm supply-chain attacks, critical VMware vulnerabilities enabling authentication bypass, arbitrary code execution and VM escapes, Teams-based vishing leading to Chaos ransomware, Russian exploitation of an Exchange OWA zero-day, active exploitation of Cisco FMC static credentials (CVE-2026-20316), attacks against healthcare and water utilities, and multiple corporate data breaches. The most urgent items involve actively exploited zero-days and attacks affecting critical infrastructure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 91343de1510ecc9e0334fc6eb16d0e7bbd050a10eabed5149b85c92a3e27c204
- Enrichment time
- 2026-07-30T19:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.