North Korea targets npm, Linux kernel RCE, AI-driven ransomware surge
ID: 5af35e18-7970-5fb4-95bb-a93b706542bf
STIX ID: report--5af35e18-7970-5fb4-95bb-a93b706542bf
Feed Name: defend.network
This briefing reports multiple high-impact threats: a North Korean-linked supply-chain campaign (PolinRider) distributing 108 malicious packages/extensions, a patched critical Linux kernel privilege-escalation (CVE-2026-46242, “Bad Epoll”), the first documented LLM-agent-automated ransomware operation (JadePuffer), disruption of the NetNut residential proxy network built on millions of compromised Android devices, and an extortion incident where a U.S. government entity reportedly paid ~$1M to Kairos; recommended actions include patching, dependency and extension audits, enhanced EDR/behavioral detection, and IoT/Android remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
