South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean

South Korean authorities have issued a joint advisory warning citizens and businesses about ongoing state-backed cyberattacks employing both phishing and watering hole techniques. The National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute collaborated on the alert, which details how attackers are silently compromising systems.
The advisory describes two primary phishing methods. In one scenario, attackers pose as job applicants, sending emails with links to attacker-controlled blogs or GitHub pages instead of direct attachments. The second method involves impersonating legitimate recruiters, sometimes by hijacking their email accounts, and sending password-protected ZIP files labeled as job offers. These files contain malware that infects a machine upon opening.
More concerning for general users are the watering hole attacks. Threat actors are compromising legitimate and trusted websites, including news portals, hospital sites, and other platforms with weaker security, to serve as infection points. The danger lies in the fact that merely visiting these compromised sites can trigger an infection without any user interaction. This is achieved by exploiting unpatched vulnerabilities in security software commonly required for accessing Korean banking and government services. The malicious code operates silently in the background, with no visible prompts or warnings to the user.
This aligns with findings from a separate technical report by AhnLab, titled "Operation Double Barrel," which the joint advisory directly references. AhnLab documented 15 compromised Korean websites, including media outlets, hospitals, and manufacturers, between 2025 and mid-2026, all using this watering hole technique. The attackers exploited flaws in two specific pieces of Korean financial security software to inject backdoors into legitimate Microsoft processes. In one instance, the malicious code was observed to activate only when visitors used Naver's Whale browser, indicating a targeted approach.
Once a system is infected, attackers can siphon off saved browser passwords and manually entered credentials, extract documents and photos, and use the compromised computer as a pivot point to infect other devices on the same network. For businesses, the advisory specifically notes that stolen source code and customer data can be used for extortion, with threats of publication or distribution if demands are not met.
The recommended mitigations are straightforward. Individuals are advised to update all security software, particularly older electronic-signature and authentication tools, enable two-factor authentication, avoid saving passwords in browsers, and verify the legitimacy of any attachments or links from unfamiliar senders through official channels before opening them. Organizations are given a more extensive list of recommendations, including network segmentation for critical servers, mandatory multi-factor authentication, regular phishing awareness training, and immediate reporting of suspicious activity to the relevant authorities.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.