Cybersecurity3 min reading time

'Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems': Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks

TechRadar
Read full post
Amazon Threat Intelligence has linked a North Korean hacking group to multiple recent compromises of popular NPM software libraries, including axios, debug, chalk, and typo-crypto. The group used social engineering to manipulate trusted maintainers and distribute malicious updates, exploiting generative AI to create convincing malware and evade detection. These attacks have impacted millions of developers and cloud environments by infiltrating widely used open source packages.

More in Cybersecurity

Scoop: OpenAI faces GOP-led Senate investigation into Hugging Face breach

Covered by 2 sources
Cybersecurity6 min read

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Covered by 2 sources
Cybersecurity5 min read

Every AI Incident Has Two Timelines. We Default To One

Forbes