North Korean Attackers Hit 30,000 Devices and Steal $10.7m
2026-09-22T14:52:08Z•2cb11fbd14de4a36908b97faddeb9af5d127c07700920c1274e05303d4f7fdbb
AI securityAndroid malwareGDPRIranian threat actorsNorth KoreaOAuth token theftRubyGemsWooCommerceWordPressactive exploitationbackdoorcloud identitycrypto theftcybersecurity newsdata breachdeepfakesinsider threatmalwarenetwork segmentationnpmphishingransomwaresocial engineeringsupply-chain securitywebshell
What happened
Infosecurity Magazine headlines from September 10–22, 2026 cover active exploitation of critical vulnerabilities, ransomware, phishing, malware, supply-chain compromise, data breaches, AI-enabled attacks, insider threats, and defensive guidance. Notable items include North Korean WaterPlum theft affecting 30,000 devices and 7,000 crypto wallets, active exploitation of Cisco ISE and GitLab flaws, a critical WooCommerce plugin campaign deploying PHP webshells, Android RatHat spyware, ClickFix infrastructure, npm and RubyGems supply-chain abuse, and major customer-data incidents. The collection’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 2cb11fbd14de4a36908b97faddeb9af5d127c07700920c1274e05303d4f7fdbb
- Enrichment time
- 2026-09-22T14:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.