LIVE · cybersecurity feed
Live wire
CVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEs
security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

zeroday.news ·

A joint advisory from law enforcement agencies in Japan, the United States, Australia, and Germany has revealed that the North Korean hacking group WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026. The group is also reported to have transferred over $10.7 million in stolen cryptocurrency to North Korea.

WaterPlum is associated with a multi-year campaign known as "Contagious Interview," which targets job seekers with malicious npm packages designed to infect their devices. The attackers frequently impersonate legitimate companies in the AI, cryptocurrency, and NFT sectors, or leverage recruiting and freelance platforms to approach potential victims. During fake interviews and coding tests, victims are often instructed to download projects, troubleshoot supposed video-conferencing issues, or execute malicious code.

The advisory states that WaterPlum actors have infected devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets. Specifically, 1.7 billion Japanese yen (JPY), equivalent to $10.71 million USD, in cryptocurrency assets were transferred to the Democratic People's Republic of Korea (DPRK).

Several malware families have been linked to WaterPlum operations. These include BeaverTail, a JavaScript malware hidden in npm packages; InvisibleFerret, a Python-based backdoor; OtterCookie, a JavaScript remote-access trojan and information stealer; and OtterCandy, which combines OtterCookie with remote access trojan (RAT) capabilities. Another notable malware is StoatWaffle, a modular Node.js malware delivered through malicious Visual Studio Code projects, which uses configuration files to execute code once a folder is opened and trusted.

Once a system is compromised, the attackers attempt to steal various types of data, including browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents. They also capture screenshots. The access gained from infected computers can be used to pivot into employers' or clients' networks, potentially expanding the attacks to include intellectual property theft and espionage.

Investigators have also directly connected WaterPlum to North Korea's fraudulent IT worker operations. The advisory indicates that some WaterPlum hackers also work as remote IT professionals performing web development for clients, and that both groups have utilized the same IP addresses. Furthermore, North Korean IT workers are believed to reuse identity documents stolen in WaterPlum attacks to impersonate victims and secure jobs. During online interviews, WaterPlum actors have been observed using AI face-swapping software, then turning off their cameras and citing network problems.

The FBI and Japanese police assess that WaterPlum actors and certain North Korean IT workers operate under the country's 313 General Bureau, which is part of the Munitions Industry Department responsible for North Korea's weapons research and production. Japan's National Police Agency reported that authorities identified, investigated, and dismantled a North Korean IT-worker "laptop farm" within Japan for the first time, uncovering evidence of several hundred million yen being transferred abroad.

The advisory recommends that companies meticulously verify the identities, locations, and qualifications of job applicants. It also advises restricting applicant access to only the systems and data necessary for their roles. Developers are urged to avoid running unknown code outside of a sandbox environment and to thoroughly inspect provided files and code for commands that might fetch additional payloads.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

CVE-2026-58138critical

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

ai

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

nation-state

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

security

Flock Offers Employees Buyouts as Customers Flee

As dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned.