Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. [...]

North Korean IT workers are reportedly exploiting vulnerabilities in remote hiring processes to gain employment with foreign companies, exfiltrate sensitive data, and funnel salaries back to North Korea. These operations leverage sophisticated tactics to bypass standard identity verification and onboarding controls, according to a July alert from the US Department of State and warnings from the FBI.
The scheme involves impersonating nationals of other countries and falsifying credentials to secure remote IT positions. Once embedded within an organization, these fraudulent workers may copy source code repositories, steal proprietary information, and support broader cybercriminal activities. In some instances, after being discovered or dismissed, they have attempted to extort former employers by threatening to publish stolen data.
A key tactic involves creating fake professional profiles and social media accounts, often using artificial intelligence to mimic the tone and language of legitimate IT professionals. They may also forge identification documents or use proxies to register accounts on online platforms. To disguise their true location, these individuals often employ VPNs and remote desktop software.
Further complicating detection, some operations utilize overseas facilitators. Employer-issued computers are shipped to an address in the country where the worker claims to reside. The facilitator then keeps these devices powered on and connected, enabling the overseas worker to control them remotely. Payment methods can also be unorthodox, with a preference for money transfers or cryptocurrency over direct deposits, and some North Korean workers have been observed using third parties for salary deposits.
Standard employment checks, such as background checks, right-to-work verifications, and identity screenings, are often insufficient to counter these sophisticated tactics. While these checks confirm the credibility of supplied details, they fail to verify that the person interviewed is the same individual who receives the equipment and ultimately logs into the system. The operations are designed to satisfy specific controls: a stolen or proxy-supplied document for identity, a fabricated resume for initial review, a proxy or skilled worker for the interview, a facilitator's address for equipment delivery, a "laptop farm" for location and device expectations, and a third-party account for payroll.
Warning signs of a potential fake remote worker include frequent changes to registered information, a mismatch between the account holder's name and the registered payment account, multiple accounts created with the same ID, or a single account accessed from multiple IP addresses in a short period. Unusually high logged hours can also be an indicator.
The FBI has noted that stolen credentials are a significant factor in data breaches, involved in 44.7% of incidents according to one report. This underscores the importance of robust identity verification throughout the employment lifecycle.
To mitigate these risks, organizations are advised to implement more stringent vetting processes for remote and freelance hires. This includes incorporating government-issued identity document scanning and biometric liveness detection into the onboarding process. Document checks confirm the authenticity of the identity document, while biometric checks compare the person completing onboarding with the photograph on that document. Liveness detection further ensures that a real person is physically present, rather than a photograph, recording, or manipulated video.
Even with these measures, a stolen or third-party-supplied identity document remains a possibility, and advanced deepfakes could potentially bypass facial recognition. Therefore, a combination of document validation and biometric liveness detection provides stronger evidence than either control alone. The core lesson is that identity should not be treated as a one-time record but as an ongoing access control, requiring re-verification when access is recovered or changed.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed