North Korea Behind Polyfill.io? Supply Chain Poisoning Just Got a State Sponsor

Forensic research links the Polyfill.io supply chain attack to a North Korean operative. The same week, a CVSS 9.8 RCE hits the simple-git npm library. Your dependency graph is your attack surface.

Read More

APT28's Covenant Trick and North Korea's AirDrop Hack: How Nation-States Borrow Their Tools

Russia's APT28 hijacked an open-source red-team tool to hit Ukraine. North Korea's UNC4899 used Apple AirDrop to break into a crypto firm. Both attacks exploit the trust we put in legit software.

Read More