North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
2026-09-01T07:24:01Z•c70121b81d7d57736062e64b187febda50bab3081483807b54c788444614fa1a
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76581CVE-2026-76639CVE-2026-76640APT28China-linked threat actorClickFixCosmos EVMIoT botnetNext.jsNorth KoreaPaperCutPowerShellServiceNowValleyRATWordPressactive exploitationbrowser extensionscPanelcredential theftcryptocurrency theftlog evasionmalwarenetwork infrastructureownCloudransomwareremote code executionrouter implantsstate-sponsored espionage
What happened
The feed highlights active and emerging cyber threats, including state-linked espionage, router and infrastructure implants, ransomware operations, malware distribution, social-engineering campaigns, insider-threat job fraud, exploited enterprise vulnerabilities, supply-chain and browser-extension abuse, cryptocurrency theft, and AI-agent security risks. Several critical vulnerabilities are actively exploited or enable unauthenticated remote code execution, root access, account takeover, or data theft.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c70121b81d7d57736062e64b187febda50bab3081483807b54c788444614fa1a
- Enrichment time
- 2026-09-01T07:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.