Matt Anderson Photography/Getty Images
By
David DiMolfetta,Cybersecurity Reporter, Nextgov/FCW
By
David DiMolfetta
New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.
Matt Anderson Photography/Getty Images
By
David DiMolfetta,Cybersecurity Reporter, Nextgov/FCW
By
David DiMolfetta

North Korean hackers are targeting open source software developers with a backdoor and an information stealer as part of a broad…

Hackers briefly turned a widely trusted developer tool into a vehicle for malware.

Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts

Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem…

Proofpoint says UNK_DeadDrop sent 250+ phishing emails to nearly 100 firms, using GitHub and VS Code lures to steal credentials…

DPRK Hacking Trends 2026: AI‑Powered Supply Chain and Developer Environment Attacks Date:...