Red Flags That Expose Fake North Korean IT Workers
Article Link: https://www.darkreading.com/insider-threats/red-flags-expose-fake-north-korean-it-workers
- North Korean IT worker schemes are maturing into a sophisticated insider threat. DPRK operatives continue using stolen or fabricated identities to secure legitimate remote employment, generating revenue for the regime while creating opportunities for espionage, data theft, or malware deployment. Unlike traditional intrusions, these actors often enter organizations through standard hiring processes.
- Infrastructure-based indicators remain valuable detection opportunities. Huntress investigations identified recurring use of VPNs, residential proxies (such as IPRoyal Proxy), and remote-access technologies like PiKVM devices to conceal true locations and enable remote operation of corporate workstations. Extensive use of these tools, particularly in combination, should trigger additional scrutiny.
- Identity verification controls are increasingly important. Investigators discovered altered passports, manipulated identity documents, stolen profile photos, and inconsistencies in supporting documentation. Security and HR teams should strengthen pre-employment vetting through document validation, metadata analysis, notarization requirements, background checks, and employment-history verification.
- Behavioral monitoring can expose fraudulent workers after onboarding. Huntress recommends monitoring for PiKVM and Guermok devices, unusual use of translation and pronunciation tools, microphone-testing websites, public sharing of meeting links, persistent VPN/proxy usage, and identity-related activity occurring outside expected work patterns. These indicators may reveal attempts to mask location or facilitate remote control by third parties.
What does this mean for me?
- Not every insider threat starts with a hacker breaking in. Some attackers obtain legitimate jobs using fake identities, which is why organizations verify identities, conduct background checks, and monitor for unusual account activity. If something about a coworker’s behavior or access requests seems suspicious, report it through the appropriate channels.
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Article Link: https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/
- SVG files are emerging as a phishing delivery mechanism that can evade traditional email controls. In this campaign, attackers disguised SVG attachments as voicemail messages and embedded obfuscated JavaScript within the SVG content. The campaign impacted 5,527 organizations and involved more than 26,000 phishing emails.
- Attackers exploited file-type and content inspection weaknesses. The malicious attachments were SVG/XML files that declared a MIME type of text/plain instead of image/svg+xml, potentially causing some email security tools to treat them as benign text files rather than active content capable of executing JavaScript.
- The campaign combined multiple trust signals to improve success rates. Messages were disguised as voicemail notifications, personalized with the recipient’s email address, and heavily relied on internal-domain spoofing. Approximately 95% of messages appeared to originate from the victim organization’s own domain despite being sent externally.
- Native email filtering struggled to identify the threat. According to INKY, 75% of the messages received Microsoft Spam Confidence Level (SCL) ratings of 0 or 1, meaning they were largely treated as legitimate email rather than spam. This highlights the importance of layered defenses beyond standard email filtering.
What does this mean for me?
- Treat unexpected voicemail attachments with caution, even if they appear to come from your own organization. If you receive an email prompting you to open an attachment, log in, or verify information unexpectedly, verify its legitimacy through another communication method before taking action.
Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations
- Medical device maker Boston Scientific confirmed in an SEC filing that it began experiencing disruptions and limitations to its IT systems and business applications on Tuesday, August 25, calling it an ongoing “global disruption” to operations.
- The company, which makes implanted devices such as pacemakers and treats around 48 million patients a year, said the attack has affected its ability to ship and process orders, but would not say whether the disruption extends to patients with medical devices and implants.
- Local Irish media reported that thousands of staff at Boston Scientific’s Cork campus were sent home Tuesday after network communications were cut across the company. A timeline for restoring systems is not yet known, and the cause of the attack has not been disclosed.
- Boston Scientific relies largely on Microsoft and Amazon Web Services for its corporate infrastructure, and is the latest health technology company hit this year, following attacks on Abbott Laboratories and Medtronic, and an Iranian-backed attack on Stryker that wiped tens of thousands of employee devices.
- Additional information: Update on recent cybersecurity incident
What does this mean for me?
- Cyberattacks can disrupt business operations on a global scale, affecting everything from communications to product delivery. This highlights the importance of maintaining alternative communication methods, following business continuity procedures, and being prepared for temporary technology outages.
Toy-making giant Hasbro disclose data breach affecting employees
Article Link: https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/
- Hasbro disclosed that attackers accessed personal and financial information belonging to an undisclosed number of employees. Massachusetts records show that 436 Hasbro employees were affected, with exposed information including Social Security numbers, financial account details, credit or debit card numbers, and driver’s license information.
- Hasbro’s notification letters do not state when the breach was detected or explain how attackers gained access. The company also has not disclosed if a ransom demand was made. “The information involved varied by individual but may have included your name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information,” Hasbro said.
- The disclosure follows a separate March 28 attack that forced Hasbro to take some systems offline. Company filings indicate that incident caused about $25 million in lost revenue. Hasbro has not connected the two events.
- Hasbro says it disabled the compromised employee account, terminated unauthorized access, and deployed additional safeguards intended to prevent a similar incident.
What does this mean for me?
- Employee information is a valuable target for cybercriminals. If you are notified that your personal information may have been exposed in a breach, monitor financial accounts, review credit reports, and be cautious of phishing attempts that use your personal details to gain trust.
ATF confirms breach of a standalone system after Qilin ransomware gang posted the agency on its leak site
- The Bureau of Alcohol, Tobacco, Firearms and Explosives says it is responding to a major breach after the Qilin ransomware group listed the agency on its leak site. Investigators say intruders accessed a standalone computer containing information about people targeted in ATF investigations.
- ATF officials say the affected computer was isolated from its enterprise network and other agency systems. Officials have not disclosed what information was taken, how much data may be involved, or whether Qilin’s claims are accurate. The investigation is still ongoing.
- The ATF claims the incident has not disrupted agency operations, its eForms system, or its broader network. Senior Justice Department officials classified the compromise as a major incident under federal guidelines.
- The ATF says it immediately blocked connections to the affected environment after discovering the breach and is coordinating with the Justice Department as the investigation continues.
What does this mean for me?
- Even systems that are separated from larger networks can be targeted by attackers. This serves as a reminder that sensitive information should always be handled carefully, and that no single security measure completely eliminates cyber risk.
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
Article Link: https://www.securityweek.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/
- CISA says more than 100 internet-exposed water and wastewater systems were targeted during July 2026. The affected systems commonly used programmable logic controllers connected directly to cellular modems.
- The attacks, linked to Iranian threat actors, targeted operational technology used to control water infrastructure. At least 12 states have confirmed attacks, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. The incidents reportedly did not cause operational disruption.
- Federal agencies had not previously disclosed a total for this wave of attacks. The activity raised concerns because exposed control systems can provide attackers with direct access to equipment that supports water services.
- CISA recommends identifying internet-accessible systems, removing unnecessary exposure, changing default passwords, applying updates, using secure gateways for remote access, requiring multifactor authentication, monitoring traffic, and regularly reassessing network and third-party connections.
What does this mean for me?
- Critical infrastructure organizations continue to be targeted by nation-state attackers. While most people are not responsible for securing industrial systems, using strong passwords, MFA, and following security policies helps reduce the broader cyber risks facing organizations and essential services.
Carhartt data breach exposes information of 12.9 million accounts
Article Link: https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/
- Clothing retailer Carhartt is facing a data breach affecting more than 12.9 million customer accounts. The ShinyHunters extortion group released an archive of allegedly stolen information after claiming the company rejected a $3.3 million ransom demand. “After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions,” a company negotiator told the extortion gang.
- ShinyHunters claimed it stole more than 50 gigabytes of customer, employee, and corporate data on August 13. Analysis of the released archive by Have I Been Pwned founder Troy Hunt linked the incident to Carhartt’s Databricks analytics platform.
- Exposed information includes email addresses, names, phone numbers, and physical addresses. The database also contained more than 15,000 employees using Carhartt email addresses, although millions of records were synthetic and did not correspond to real people.
What does this mean for me?
- Data breaches can expose contact information that criminals later use in phishing, scam calls, and fraudulent messages. Be skeptical of unsolicited communications that reference purchases, accounts, or personal details, even if the information appears accurate.
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Article Link: https://thehackernews.com/2026/08/critical-gitea-rce-actively-exploited.html
- CISA has warned that attackers are actively exploiting CVE-2026-60004, a Gitea flaw rated 9.8 out of 10. The weakness can let someone with repository write access execute commands as the Gitea service account.
- Gitea’s default open-registration setting can allow an outside visitor to create an account and repository, gain the needed access, and exploit the flaw through its diffpatch endpoint. A reported attack used the weakness to deploy a cryptocurrency-miner-like program.
- The flaw affects Gitea versions beginning with 1.17 and was fixed in version 1.27.1. In the reported case, processor use exceeded 70 percent, prompting the hosting provider to restrict the server’s resources.
- Gitea users need version 1.27.1 or later. Federal agencies have been given an August 28 deadline to apply the fix, while reviewing exposure based on risk.
What does this mean for me?
- Attackers often begin exploiting newly disclosed software vulnerabilities almost immediately. When your organization requires updates, maintenance windows, or system restarts, completing them promptly helps ensure critical security fixes are applied before attackers can take advantage of known weaknesses.
