logo

North Korea targets npm, Linux kernel RCE, AI-driven ransomware surge

ID: 5af35e18-7970-5fb4-95bb-a93b706542bf

STIX ID: report--5af35e18-7970-5fb4-95bb-a93b706542bf

Feed Name: defend.network

Threat Score
85/100

Date Published: 2026-07-05

Date Updated: 2026-07-05

Author: defend.network

...
...

This briefing reports multiple high-impact threats: a North Korean-linked supply-chain campaign (PolinRider) distributing 108 malicious packages/extensions, a patched critical Linux kernel privilege-escalation (CVE-2026-46242, “Bad Epoll”), the first documented LLM-agent-automated ransomware operation (JadePuffer), disruption of the NetNut residential proxy network built on millions of compromised Android devices, and an extortion incident where a U.S. government entity reportedly paid ~$1M to Kairos; recommended actions include patching, dependency and extension audits, enhanced EDR/behavioral detection, and IoT/Android remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.