Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
DPRK Job Fraud Expands to Healthcare and Sales: Insider Threat Detection and Hiring Controls for Defenders
The Insider Threat Is No Longer Confined to Your Engineering Org For the past several years, the security community has tracked the DPRK IT ...
North Korean Supply Chain Attack via Malicious Rust Crates: Detection and Remediation Guide for Defender Teams
Introduction Cybersecurity researchers have attributed a malicious unauthorized access mechanism — in plain terms, a backdoor — embedded in ...
Kimsuky's Offline AI Stack: Defending Against North Korea's AI-Automated Social Engineering and Malware Development
Kimsuky Moves AI In-House — and What That Means for Your SOC North Korean state-sponsored threat actors have spent the past two years experi...
npm Supply Chain Attack: North Korean Campaign Targeting Axios Users — Detection and Mitigation
npm Supply Chain Attack: North Korean Campaign Targeting Axios Users — Detection and Mitigation Introduction AWS has publicly attributed a w...
North Korean NPM Supply Chain Attacks: Amazon Attribution and Defensive Strategies
North Korean NPM Supply Chain Attacks: Amazon Attribution and Defensive Strategies Introduction Amazon's security teams have recently attrib...
North Korea-Linked npm Supply Chain Attack: Rollup Polyfill Mimicry Detection
North Korea-Linked npm Supply Chain Attack: Rollup Polyfill Mimicry Detection Introduction A sophisticated supply chain attack has been iden...
PolinRider Campaign: Defending Against North Korean Supply Chain Attacks in npm, Go, and Chrome
Introduction The threat landscape for software development environments has deteriorated significantly with the emergence of the PolinRider ...
Medusa Ransomware: Lazarus Group Targets US Healthcare — Defense and Hunting Guide
Medusa Ransomware: Lazarus Group Targets US Healthcare — Defense and Hunting Guide Introduction The threat landscape facing the US healthcar...
Defending Against VS Code Auto-Run Attacks: Mitigating StoatWaffle Malware
Defending Against VS Code Auto-Run Attacks: Mitigating StoatWaffle Malware Introduction Software development environments have become a prim...