Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The article details how North Korean IT workers, often linked to Lazarus Group, infiltrate organizations by exploiting the hiring process rather than breaking in externally. An investigation using controlled sandboxes exposed their use of forged documents, AI tools, and specific infrastructure, including IP addresses and VPN exit nodes.
Researchers at Group-IB discovered WindRelay, a new NFC relay malware that captures live card data via NFC and forwards it in real time to attackers. This malware, combined with SpyNote RAT, allows criminals to remotely control victims' phones and use their physical payment cards for fraudulent transactions.
Google discusses the evolving role of its Red Teams in the era of agentic security. The piece highlights how autonomous systems and AI-driven threats require red teams to adapt their methodologies and maintain cutting-edge security operations.
Cisco Talos uncovered the JWR phishing framework, which impersonates major payment platforms and steals sensitive data via real-time operator control. The framework shares similarities with 'The Outsider' PhaaS platform and has been deployed in SMS-based campaigns across Southeast Asia and the Middle East.
A hacker group dubbed 'Jewelbug' has been found conducting both state-sponsored espionage and cryptocurrency theft using the same infrastructure. Security researchers uncovered a shared web panel connecting these activities, demonstrating the group's dual objectives.
The Jewelbug APT group, based in China, is executing espionage campaigns against government ministries in the Middle East and Asia while running a cryptocurrency fraud operation from the same infrastructure. This dual-purpose strategy highlights the group's ability to leverage its resources for both intelligence gathering and financial crimes.