North Korean threat actor Jumpy Pisces collaborated with the Play ransomware gang in a cyberattack, according to Palo Alto Networks Unit 42. Jumpy Pisces made initial access through a compromised account, utilising open-source and custom tools for lateral movement and persistence. The access was then used to conduct pre-ransomware activity and deploy the Play ransomware payload. Jumpy Pisces, linked to North Korea’s Reconnaissance General Bureau, is transitioning from cyberespionage to financially motivated attacks.

Sonatype reports rise in open source malware to 17,954
The 1Q 2025 Open Source Malware Index from Sonatype revealed that open source malware packages doubled compared to the same period last year, with 56%