OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs

2026-03-19T01:24:36Z8ecc915bf00a9946fe87778b6248340aff228fd1b78d455ea6cdb3015ad45146
AI sandboxAmazon BedrockCISA','Known Exploited Vulnerabilities','Wing FTP','GlassWorm','Cisco FMCClickFixDPRKDeno loaderEndRATGNU InetUtilsIP KVMInterlockKonniLeakNetOFACUbuntuWebKitdata exfiltrationinsecure deserializationprivilege escalationransomwareroot RCEsame-origin bypasssanctionssystemdtelnetd

What happened

The Hacker News roundup highlights multiple high-impact incidents and vulnerabilities: OFAC sanctioned DPRK-linked IT worker networks funding WMD programs; an active Interlock ransomware campaign exploiting Cisco FMC insecure-deserialization (CVE-2026-20131, CVSS 10.0) to gain root; a critical unauthenticated root RCE in GNU InetUtils telnetd (CVE-2026-32746, CVSS 9.8); nine critical IP-KVM vulnerabilities across four vendors enabling unauth root access; Ubuntu local privilege escalation via systemd timing (CVE-2026-3888); an Apple WebKit same-origin bypass (CVE-2026-20643); AI sandboxing/Bed­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
8ecc915bf00a9946fe87778b6248340aff228fd1b78d455ea6cdb3015ad45146
Enrichment time
2026-03-19T01:24:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.