Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Researchers Expose North Korean IT Workers’ Role in Crypto Heist, Highlighting Vulnerabilities in Identity Verification A group of researchers has made a startling discovery, building a fake cryptocurrency startup and successfully hiring three individuals suspected of being part of North Korea’s cyber warfare program. This bold experiment sheds light on the ease with which malicious … Read more

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla’s Surprise Move: Revoking Firefox and Thunderbird Linux Signing Key Raises Questions on Security Practices In a sudden and unexpected move, Mozilla has revoked its Linux signing key, used to verify the authenticity of software updates for its popular Firefox and Thunderbird browsers. The decision comes after it was discovered that the private key had … Read more

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A Security Vulnerability in Cellular IoT Devices Exposes Millions of Users to Malicious Activity A recent discovery has shed light on a previously unknown vulnerability in cellular Internet of Things (IoT) devices, which could allow attackers to inject malicious code into the modems that power these devices. This exploit takes advantage of a weakness in … Read more

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI’s Latest GPT Model Sparks Concerns Over Reduced Safeguards for Exploit Development A new version of OpenAI’s large language model, designed for exploit development and penetration testing, has been launched with significantly reduced safeguards. The move has raised eyebrows among security experts, who warn that the increased accessibility of this powerful tool could embolden malicious … Read more

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla Updates GPG Signing Key After Accidental Exposure, Low Risk of Malicious Activity A recent security incident has prompted Mozilla to update the GPG signing key used for Firefox and Thunderbird releases. The company had inadvertently exposed an unencrypted copy of the previous subkey on a private GitHub repository, sparking concerns about potential supply chain … Read more

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

A fake cryptocurrency startup, dubbed “CryptoLux,” has been used as a front to lure and hire suspected North Korean IT workers, who were then exploited for their skills in malicious activities. This brazen scheme highlights the growing threat of state-sponsored cybercrime and the ease with which attackers can manipulate legitimate-looking ventures to further their nefarious … Read more

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A recently disclosed vulnerability in cellular IoT devices has revealed a shocking truth: malicious SIM cards can secretly run attacker code inside the modems that power these devices. This means that hackers can gain control over the very foundation of IoT networks, exploiting vulnerabilities that could have far-reaching consequences for individuals and organizations alike. The … Read more