LIVE · cybersecurity feed
Live wire
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malware
nation-state

Nations take action on North Korean IT workers after UN report

A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.

zeroday.news ·

Multiple countries have initiated legal actions against North Korean nationals or their local facilitators following a report from the United Nations concerning Pyongyang’s illicit IT worker scheme. The Multilateral Sanctions Monitoring Team (MSMT), a U.S.-led international committee tasked with monitoring compliance with UN sanctions on the Democratic People’s Republic of Korea (DPRK), released a report on Wednesday, September 18, 2026, detailing the thousands of North Korean nationals working abroad in various industries.

This latest report expands upon a 140-page study released by the UN in October of the previous year, which specifically focused on the IT worker scheme. In this scheme, North Korean nationals reportedly acquire or forge identification documents to secure high-paying IT positions, often at technology companies. The UN indicated that teams of these IT workers reside illegally in China and approximately 40 other countries.

As of July, Vietnam, Laos, Pakistan, and Argentina have taken significant steps in response to the allegations outlined in the October study. In January, U.S. officials confirmed that Argentina had taken several actions, and Pakistan had detained an individual for facilitating North Korean IT worker activities.

Argentina’s government launched an investigation into Antonia Doroganova, who is accused of laundering funds earned by North Korean IT workers through various payment accounts. The Argentine government also froze some assets and implemented other measures related to Doroganova’s alleged activities.

In Pakistan, a legal case was opened against Syeda Aliya Batool Zaidi, an alleged forger accused of providing fraudulent identification documents to North Korean IT workers. The Pakistani Federal Investigation Agency initiated investigations into Zaidi and two other individuals, Syed Sohail Mehdi and Syed Kazim, who are suspected of assisting North Koreans in conducting IT work within the country.

The MSMT’s report noted that multiple companies and individuals in Vietnam and Laos were sanctioned by the U.S. in March, having been previously identified by UN investigators. These entities and their officials allegedly helped North Koreans open local bank accounts and launder their earnings. In July, the government of Laos confirmed to the MSMT that 19 North Koreans identified in the October report entered the country between 2018 and 2019 and had all departed by 2025. However, Laos denied the existence of several companies listed by the MSMT.

North Koreans working outside the country generated an estimated $800 million last year, with a substantial portion derived from the IT worker scheme. The MSMT reported recent issues with North Korean IT workers in China, including increased surveillance by Chinese authorities and several arrests for alleged espionage. In April 2025, a North Korean IT worker dispatched to China was reportedly arrested and detained by Chinese public security authorities for allegedly stealing Chinese military secrets. This heightened scrutiny has reportedly restricted the DPRK’s ability to deploy new IT workers, making it difficult for them to enter China as of July 2025.

Due to these challenges, a North Korean company reportedly leased a building in Sinuiju, a North Korean border city, to allow IT workers to use Chinese internet and earn foreign currency without physically entering China. An MSMT member also reported that a North Korean IT company attempted to secure residency permits from China’s Foreign Affairs Ministry by misrepresenting IT workers as employees of a trading company, while other firms allegedly tried to smuggle North Koreans into China by portraying them as garment laborers. Similar issues arose in Laos, where North Korean IT workers faced surveillance by Laotian officials, leading to their relocation from the capital, Vientiane, to the provincial city of Vang Vieng. Laos informed the MSMT that it has established a national committee to investigate the IT worker scheme and implement UN regulations.

Multiple UN resolutions mandated that all North Korean nationals be repatriated by 2019 and prohibited them from earning income in UN member states. However, the MSMT stated that at least 17 countries continue to host approximately 100,000 North Koreans, with the majority located in China and Russia. The latest report expands on the October study by tracking the various sectors in which North Koreans are employed. An estimated 20,000 to 70,000 North Korean workers are deployed in China, and up to 30,000 are in Russia, working in manufacturing, farming, and military industrial production. According to the report, up to 90% of their earnings are confiscated by North Korean officials.

Beyond Russia and China, the MSMT identified North Korean laborers in Cambodia, Mongolia, Kyrgyzstan, Cameroon, Equatorial Guinea, Guinea, Mozambique, Niger, Nigeria, Senegal, Tanzania, Uganda, and Zimbabwe. North Korea relies on a network of local facilitators and its own government officials to manage these workers, provide translation services, and remit earned money back to Pyongyang. This extensive network highlights the DPRK’s determination to acquire foreign currency.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed,

ransomwarecritical

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.

ai

Did an AI really try to break free from human control?

An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.

vulnerability

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.

malware

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

breach

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal,