Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea’s Reach

The coding test was the payload. Officials say the developer-focused campaign accumulated more than $10.7 million in transfers.
BlackTree articles covering cybersecurity, privacy and digital legislation across the Asia-Pacific region.

The coding test was the payload. Officials say the developer-focused campaign accumulated more than $10.7 million in transfers.

Japan's Digital Agency detected mass file access in June, identified a VPN-vulnerability intrusion in July and disclosed in September that about 246,000 records may have leaked.

Gen Digital traced a GRAYRABBIT intrusion to a crafted Sogou Input Method link. The link opened a six-year-old browser engine with its sandbox disabled, allowing an old JavaScript exploit to run.

NSA, CISA and the FBI say six Chinese AI companies distributed millions of requests across providers, accounts and proxies to extract frontier-model capabilities.

Two South Korean organisations kept serving traffic through HAProxy while a hidden plugin stole credentials, hijacked sessions and altered pages for selected visitors.

Australia excluded AI-led recordings from its charts, but enforcement begins with declarations from rights holders. The rule is clear. Its evidence model is not.

A router sold under a reassuring retail brand can still be running firmware built by somebody else. VulnCheck’s investigation into ZBT router backdoors found three remote-control implants, including one that can hand an unauthenticated internet user a root shell with…

China’s new rules for network-data security risk assessments took effect on 20 August 2026. For organisations that process data in China, the important change is not simply another assessment obligation. The result may now have to leave the security team,…

Most security teams are trained to look for attackers entering an organisation. Malware arrives. Credentials are stolen. A vulnerability is exploited. A suspicious login appears. The North Korean remote IT worker programme takes a different route. The attacker applies for…

Google found an agentic attack framework managing more than 23,800 harvested secrets. In a separate operation, another framework built and launched a credential campaign in under six hours.