North Korea targets macOS users in latest heist
2026-04-16T19:24:06Z•9b385c8937a69143efb2d0ee96059edc636992cccd59ff514162d2995b9c6a21
AI securityAnthropicExcelFortinetGitHub ActionsMicrosoftNorth Koreaactive exploitationauthentication bypasscredential theftdata breachfake updatemacOSpatchingprompt injectionransomwareremote code executionsandbox bypasssocial engineeringsupply chainwebsite hijack
What happened
Multiple high‑impact incidents and vulnerabilities reported across platforms: North Korean actors are using social engineering and fake Zoom updates to push macOS users into running malware; two critical Fortinet sandbox bugs can allow unauthenticated auth bypass and remote command execution; a 17‑year‑old critical Microsoft Excel flaw is being actively exploited; Microsoft’s large Patch Tuesday fixes (including an actively exploited SharePoint issue) address many additional flaws. AI-related risks are prominent: Anthropic’s Mythos/Project Glasswing claims, a git identity‑spoof that fooled anL
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 9b385c8937a69143efb2d0ee96059edc636992cccd59ff514162d2995b9c6a21
- Enrichment time
- 2026-04-16T19:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.