Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms
2026-05-10T20:52:03Z•830a7277ef56a6092cf27f5cba39c505357fdb8232be49358cd536b0266d3f61
AMOSBeagle-backdoorClaude-extensionClaudeBleedClickFixDigiCertJDownloaderSHub-StealerZhong-Stealerbrowser-securitycertificate-compromisecode-signingcredential-theftdata-exfiltrationedge-plaintext-passwordsfake-sitegmailgoogle-chrome-gemini-claim','ai-model-installation'google-driveiCloud-theftmacOSmalicious-installersmalvertisingsoftware-distributionsupply-chain
What happened
This feed aggregates multiple high-impact security incidents and research from May 2026: a DigiCert support-chat compromise led to issuance (and subsequent revocation) of ~60 code‑signing certificates used to sign Zhong Stealer; the JDownloader official site was hijacked to serve malicious installers; a malvertising campaign used a fake Claude AI site to deploy a new Beagle backdoor; the ClaudeBleed flaw lets attackers bypass the Claude Chrome extension guardrails to exfiltrate Google Drive/Gmail data; ClickFix campaigns targeted macOS users to steal iCloud credentials (AMOS and SHub Stealer);
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 830a7277ef56a6092cf27f5cba39c505357fdb8232be49358cd536b0266d3f61
- Enrichment time
- 2026-05-10T20:52:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.