OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs

2026-03-18T19:24:12Z084b1d5c3b2eb51f0c9aaa884c5bf03967c511484147527128b00235b4865fed
CISAOFACai-securitycredential-theftexploitationmalwarephishingprivilege-escalationransomwareremote-code-executionstate-sponsoredsupply-chainvulnerabilityzero-day

What happened

The Hacker News digest highlights multiple high-impact security developments: OFAC sanctioned DPRK-linked operators using fake remote IT jobs to fund WMD programs; an active Interlock ransomware campaign exploiting Cisco FMC zero-day CVE-2026-20131 (CVSS 10.0) for unauthenticated root access; a critical unauthenticated root RCE in GNU InetUtils telnetd (CVE-2026-32746, CVSS 9.8); a local privilege escalation in Ubuntu via systemd timing (CVE-2026-3888); and a WebKit same-origin bypass (CVE-2026-20643). Other notable items include GlassWorm supply-chain attacks and repo-tampering via stolen Git

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
084b1d5c3b2eb51f0c9aaa884c5bf03967c511484147527128b00235b4865fed
Enrichment time
2026-03-18T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.