Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million

2026-09-25T20:51:38Z•00b8b8d87a3f7f16ccd60676fac83a4a392e669f0a4e9b20004024174dfcfc9c
CVE-2026-5430CVE-2026-85102CVE-2026-94127AI-enabled malwareArista VeloCloudCARBONATO botnetCISA KEVCLOSEDQUORUMCheck PointClickFixDockerF5 BIG-IP APMMikroTik RouterOSNorth Korea-linked actorsPsychedelic StealerWSO2active exploitationcredential theftcryptocurrency theftcybercrimeremote code executionzero-day

What happened

SecurityAffairs RSS roundup covering a $351.6 million suspected North Korea-linked cryptocurrency exchange theft, malware campaigns using ClickFix and compromised websites, the CARBONATO Docker botnet, AI-assisted and AI-driven malware, RouterOS exploitation, and multiple actively exploited vulnerabilities added to CISA’s KEV catalog. The most urgent item is the actively exploited F5 BIG-IP APM zero-day CVE-2026-94127, a critical unauthenticated remote-code-execution flaw.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
00b8b8d87a3f7f16ccd60676fac83a4a392e669f0a4e9b20004024174dfcfc9c
Enrichment time
2026-09-25T20:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million · Baitaphish