North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

2026-09-01T01:24:01Zb9db51a0f541a62e1321cebca7d69362a3b752f3ad16b3ecd2a04399b1b0dab5
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76581CVE-2026-76639CVE-2026-76640AI securityAPT28China-linkedClickFixCosmos EVMDPRK-linkedNext.jsPaperCutServiceNowWordPressactive exploitationbackdoorbrowser extensionscPanelcryptocurrency theftinsider threatmalwareownCloudransomwareremote code executionrouterssocial engineeringstate-sponsored espionagesupply chainzero-day

What happened

The Hacker News feed highlights active exploitation of critical vulnerabilities, including WordPress, PaperCut, ownCloud, Cosmos EVM, ServiceNow, Next.js, cPanel, router firmware, and humanoid robots. It also covers state-sponsored espionage by China- and DPRK-linked actors, ransomware operations using AI coding tools, malware distribution through signed adware and browser extensions, ClickFix social engineering, and emerging AI-agent security risks. Multiple reports describe unauthenticated or root-level remote code execution and confirmed exploitation, indicating urgent patching and threat-h

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b9db51a0f541a62e1321cebca7d69362a3b752f3ad16b3ecd2a04399b1b0dab5
Enrichment time
2026-09-01T01:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales · Baitaphish