Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms

2026-05-10T20:52:03Z830a7277ef56a6092cf27f5cba39c505357fdb8232be49358cd536b0266d3f61
AMOSBeagle-backdoorClaude-extensionClaudeBleedClickFixDigiCertJDownloaderSHub-StealerZhong-Stealerbrowser-securitycertificate-compromisecode-signingcredential-theftdata-exfiltrationedge-plaintext-passwordsfake-sitegmailgoogle-chrome-gemini-claim','ai-model-installation'google-driveiCloud-theftmacOSmalicious-installersmalvertisingsoftware-distributionsupply-chain

What happened

This feed aggregates multiple high-impact security incidents and research from May 2026: a DigiCert support-chat compromise led to issuance (and subsequent revocation) of ~60 code‑signing certificates used to sign Zhong Stealer; the JDownloader official site was hijacked to serve malicious installers; a malvertising campaign used a fake Claude AI site to deploy a new Beagle backdoor; the ClaudeBleed flaw lets attackers bypass the Claude Chrome extension guardrails to exfiltrate Google Drive/Gmail data; ClickFix campaigns targeted macOS users to steal iCloud credentials (AMOS and SHub Stealer);

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
830a7277ef56a6092cf27f5cba39c505357fdb8232be49358cd536b0266d3f61
Enrichment time
2026-05-10T20:52:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.