BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
2026-07-25T01:24:09Z•0b19c63ceeb87f7a687206c90161aa13f3b02352bae28b65ddcb55d442427443
APTactive-directoryactive-exploitationai-securitybrowser-based-c2espionagegithub-actionskerberoslinux-kernellocal-privilege-escalationmalwarephishingprivilege-escalationransomwareremote-code-executionsandbox-escapesupply-chainvm-escapewebmailxfszero-day
What happened
A broad set of high-impact security stories: North Korea-linked BlueNoroff is running a Zoom/Microsoft Teams typosquatting phishing kit to profile crypto wallets before malware delivery; a new Certighost exploit lets low-privileged AD users obtain a Domain Controller certificate and perform DCSync-style theft; OpenAI ChatGPT Workspace Agents had a critical AgentForger flaw (now patched) that could let a phishing link deploy rogue agents; crafted SVGs in Bing Images led to SYSTEM/root command execution (two critical CVEs disclosed); and multiple actively exploited or high-severity flaws were披露/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0b19c63ceeb87f7a687206c90161aa13f3b02352bae28b65ddcb55d442427443
- Enrichment time
- 2026-07-25T01:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.