North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

2026-09-01T07:24:01Zc70121b81d7d57736062e64b187febda50bab3081483807b54c788444614fa1a
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76581CVE-2026-76639CVE-2026-76640APT28China-linked threat actorClickFixCosmos EVMIoT botnetNext.jsNorth KoreaPaperCutPowerShellServiceNowValleyRATWordPressactive exploitationbrowser extensionscPanelcredential theftcryptocurrency theftlog evasionmalwarenetwork infrastructureownCloudransomwareremote code executionrouter implantsstate-sponsored espionage

What happened

The feed highlights active and emerging cyber threats, including state-linked espionage, router and infrastructure implants, ransomware operations, malware distribution, social-engineering campaigns, insider-threat job fraud, exploited enterprise vulnerabilities, supply-chain and browser-extension abuse, cryptocurrency theft, and AI-agent security risks. Several critical vulnerabilities are actively exploited or enable unauthenticated remote code execution, root access, account takeover, or data theft.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c70121b81d7d57736062e64b187febda50bab3081483807b54c788444614fa1a
Enrichment time
2026-09-01T07:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.