Reminder connect to your cell phone hotspot as opposed to hotel wifi... if you have one. Connecting to a free hotel wifi hotspot should be a last resort.
Our blog on the Axios NPM supply chain attacks. We are attributing the incident to a suspected North Korean threat actor we track as UNC1069. That actor is financially motivated and DPRK historically leveraged supply chain attacks to target crypto. https://t.co/F4dRfij58R
North Korean actor UNC1069 is targeting the crypto sector with AI-enabled social engineering, deepfakes, and 7 new malware families.
Get the details on their TTPs and tooling, as well as IOCs to detect and hunt for the activity detailed in our post 👇
https://t.co/t2qIB35stt
Google & partners disrupted IPIDEA, one of the world's largest residential proxy networks, reducing its device pool by millions.
This infrastructure was leveraged by over 550 distinct espionage and cybercrime groups.
Full report + IOCs here:
https://t.co/2GAnvawRwl
During our talk at @BSidesPyongyang two weeks ago on Cyber Juche, @crypt0ca1tlyn and I unveiled key feeder pipeline universities that the #RGB, #MSS, #MID, and #MND use to develop skills, experience, and ability to support various roles within their hacking units.
Announcing my rejected talk for @bsidespyongyang:
Is that "web3 enthusiast" follower with the anime PFP acting suspicious?
Find out if you have confirmed North Korean followers at https://t.co/sR2776PBF2.
We are incredibly excited for this years agenda! #BSPY25#BSidesPyongyang
Join us Tuesday 18 November 2025 on Twitch and YouTube
Register at https://t.co/7hHKvW3r2w
Google Threat Intelligence Group details the ways threat actors are misusing AI tools, including how they are generating and executing AI-enabled malware.
🔗 Read this latest report on our blog: https://t.co/VfvwpLFQXn
North Korea threat actor UNC5342 is using EtherHiding, the first time we have observed a nation-state use this technique. 🚨
The TTP is being used in a social engineering campaign that leads to cryptocurrency heists and espionage.
Read the blog post: https://t.co/JGnXcAQfoQ
⚡ North Korean hackers just used the blockchain to hide malware — the first time ever seen.
Google says they used EtherHiding to plant code inside smart contracts, making it nearly impossible to remove and easy to update for just $1.37 in gas fees.
Full story ↓ https://t.co/8fDp4eZscT
A deeper dive into the npm registry phisher's tactics, techniques, and procedures uncovers a history of persistent attempts at attacking cryptocurrency users.
https://t.co/JhvrKUwkse
This is why DPRK IT Workers get hired.
Their resumes are fake but pristine and the perfect length.
They a/b test them 1000x more than you.
If you’ve been hiring for years you can search your archives for names/emails/handles and see 10 versions of one dude with your own eyes.