North Korea’s Lazarus APT stole $290M from Kelp DAO
2026-04-21T20:51:52Z•3b973639d9165eaa8331d8e5d10dcc5cc30227e3821ac70482a5c327709cd18d
AI-assisted exploitationAnthropic Claude MythosBlueskyCISA KEVCVE-2023-33538Cisco CatalystClaude OpusContext.aiDDoSDeFiFrance ANTSJetBrains TeamCityKelp DAOKentico XperienceLayerZeroLazarusPaperCut NG/MFQuest KACE SMASynacor ZCSTP-LinkVercelcrypto theftdata breachsupply chain riskthird-party risk
What happened
Multiple high-impact cyber incidents and supply-chain/AI risk stories: North Korea-linked Lazarus stole $290M from Kelp DAO by abusing LayerZero (a second $95M attempt was blocked). The US NSA reportedly uses Anthropic’s Claude Mythos despite DoD supply-chain concerns. CISA added several product flaws (Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, JetBrains TeamCity) to its Known Exploited Vulnerabilities catalog. Bluesky suffered a 24-hour DDoS claimed by a pro‑Iran group. France’s ANTS ID application site was hit with a possible data breach. Vercel was bree-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 3b973639d9165eaa8331d8e5d10dcc5cc30227e3821ac70482a5c327709cd18d
- Enrichment time
- 2026-04-21T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.