For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.

A cybersecurity researcher has revealed that he maintained access to North Korean hacking infrastructure for nearly two years, uncovering evidence of intrusions into 1,640 organizations across 57 countries. Vangelis Stykas, CTO at Kumio, stated that between 700 and 800 of these intrusions were "really damaging," involving root access to servers, AWS environments, and critical cryptocurrency keys.
Stykas gained access to multiple command-and-control servers used by the North Korean hackers, and in some instances, the attackers inadvertently infected their own workstations, granting him access to their internal communications like Slack and Discord. Over 22 months, he collected approximately 5 terabytes of data, which he used to identify potential victims and disclose the incidents.
Among the organizations publicly named by Stykas at the Black Hat security conference are Boston Children’s Hospital, Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, a part of the Flemish Government in Belgium.
Responses from named organizations varied. Japan’s Computer Emergency Response Team confirmed Stykas’s findings and collaborated with AEON Smart Technology on remediation. Digitaal Vlaanderen confirmed a notification on March 3, 2026, leading to the isolation of an affected workstation and revocation of credentials, with the incident deemed contained. Boston Children’s Hospital stated the incident involved a former independent contractor’s personal device, not hospital systems, and that no unauthorized access to their systems was found, with the data at issue already public. Coinbase investigated a contractor and found no evidence of North Korean affiliation, but terminated the contractor due to potential outsourcing risks before Stykas’s tip, confirming no sensitive information or customer data was compromised.
The primary method of attack involved luring software developers with fake job offers and high salaries. Once a target accepted, they were prompted to download a program as a coding test, which secretly installed malware on their machine. This tactic, known as "Contagious Interview," has been documented by Microsoft as early as 2022. Stykas observed that compromised external contractors, who often held developer keys and system access to multiple companies, significantly expanded the potential impact of these attacks, with some contractors having access to up to 30 organizations.
While many compromised firms held highly sensitive data, including health records and criminal records, the North Korean hackers largely focused on acquiring cryptocurrency wallets, often overlooking other systems. However, experts warn that persistent access to corporate networks, even if initially used for crypto theft, could be leveraged by espionage teams for broader intelligence gathering.
North Korea's cyber operations are extensive and adaptable, supporting economic and military development, revenue generation, espionage, and sanctions evasion. The country is believed to employ several hundred skilled cyber operators, alongside thousands of "IT workers" who secure fraudulent remote employment to funnel earnings to the regime. Both groups are reportedly given annual earnings quotas. The scale of these campaigns, with victim lists often numbering in the thousands, is consistent with the broad scope of North Korean hacking activities.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.