North Korean actors connected to nation-state hacking group Kimsuky have targeted machines using spear-phishing attacks, delivering backdoors like AppleSeed, Meterpreter, and TinyNuke. South Korean cybersecurity firm AhnLab reported these actors used similar methods for years without significant changes to their malware. Kimsuky has been active for over a decade, initially focusing on South Korea before widening its scope. It uses espionage campaigns involving spear-phishing attacks with malicious documents, which then deploy varying malware forms.

Mandiant warns of attacks on newly-disclosed Ivanti remote takeover threat
Google’s Mandiant team has issued an alert about a remote code execution flaw in the Ivanti Connect Secure VPN platform. The vulnerability, designated CVE-2025-22457, is