North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
2026-09-01T01:24:01Z•b9db51a0f541a62e1321cebca7d69362a3b752f3ad16b3ecd2a04399b1b0dab5
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76581CVE-2026-76639CVE-2026-76640AI securityAPT28China-linkedClickFixCosmos EVMDPRK-linkedNext.jsPaperCutServiceNowWordPressactive exploitationbackdoorbrowser extensionscPanelcryptocurrency theftinsider threatmalwareownCloudransomwareremote code executionrouterssocial engineeringstate-sponsored espionagesupply chainzero-day
What happened
The Hacker News feed highlights active exploitation of critical vulnerabilities, including WordPress, PaperCut, ownCloud, Cosmos EVM, ServiceNow, Next.js, cPanel, router firmware, and humanoid robots. It also covers state-sponsored espionage by China- and DPRK-linked actors, ransomware operations using AI coding tools, malware distribution through signed adware and browser extensions, ClickFix social engineering, and emerging AI-agent security risks. Multiple reports describe unauthenticated or root-level remote code execution and confirmed exploitation, indicating urgent patching and threat-h
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b9db51a0f541a62e1321cebca7d69362a3b752f3ad16b3ecd2a04399b1b0dab5
- Enrichment time
- 2026-09-01T01:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.