North Korean cyber attackers have undertaken a sophisticated assault on the tech, finance and cryptocurrency sectors by staging fake job interviews to deploy malware including “InvisibleFerret” and “BeaverTail”. These compromises systems and exfiltrates sensitive data, targeting software developers and using coding challenges, video call apps, or dependencies to embed malicious payloads.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.