North Korean hackers have used ChatGPT in a phishing campaign, generating a fake South Korean military ID to deceive victims. The Kimsuky group, linked to Pyongyang, was behind this attack, which shows how generative AI in cybercrime is expanding beyond text generation. The incident underlines a worrying trend: AI cyber attacks are becoming more sophisticated, […]
A major npm supply chain attack has compromised more than 40 Node Package Manager (npm) packages, injecting a malicious script called bundle.js to steal sensitive developer credentials. According to security researchers, the campaign, dubbed the Shai-Hulud attack, uses the open-source tool TruffleHog (TruffleHog Secret Scanner) to extract secrets such as GitHub personal access tokens, Node […]