State Actors, Zero-Days & NFC Relay Fraud

August 13
3 mins

Episode Description

Here is your briefing for Thursday, August 13, 2026. North Korean IT workers are applying for remote developer jobs, passing interviews, and landing inside government agencies and private companies with legitimate credentials. The FBI is investigating at least one case where a suspected DPRK operative worked for a U.S. federal agency. Researchers who deliberately hired suspected Lazarus-linked developers into sandboxed environments documented forged identities, re-used infrastructure, and rapid pivots once inside. The operation flips the usual attacker model: instead of breaking in, the threat gets hired. That's the headline from The Hacker News, and it is the logical endpoint of years of remote-work expansion. The same hiring pipelines companies optimized for speed now route state-sponsored talent straight into production systems. Lazarus Group exploited a freshly patched Windows zero-day in the Ancillary Function Driver for WinSock (AFD.sys, CVE-2026-68820, CVSS 7.0) to escalate privileges and drop a previously unseen backdoor. The campaign targeted defense and aerospace firms in France, Germany, Brazil, and India as part of the long-running Operation Dream Job social-engineering effort. Microsoft shipped the fix in the August 2026 Patch Tuesday bundle. That's the headline from The Hacker News and Krebs on Security, and it is the usual pattern: a high-value zero-day lands in the hands of a sophisticated actor, gets used for targeted espionage, and only surfaces after the patch cycle catches up. Threat actors started exploiting CVE-2026-55040, a critical SharePoint authentication bypass patched in July, within days of Rapid7 publishing proof-of-concept code. The flaw allows impersonation, file disclosure, and data modification. It is already the fifth SharePoint vulnerability observed in active exploitation this year. That's the headline from The Hacker News, and it is another data point on how quickly public PoCs translate into real-world campaigns once the disclosure window opens. A new Android NFC relay malware family called WindRelay works with the SpyNote RAT to capture live card data via contactless payments and forward it to attackers in real time. The malware is sideloaded silently after initial RAT access, requires no screen sharing, and was first spotted in the wild in late 2025. Attacks begin with phishing or smishing to get the initial foothold. That's the headline from The Hacker News, and it shows how the contactless payment surface remains an attractive, under-defended channel for fraud even as mobile security tooling improves. Anthropic rolled out invisible watermarks on Claude-generated text that can flag machine output even when a human only edited the content. Some users are already complaining that the feature will catch them using the model for work or school assignments. Ars Technica notes the mark is designed to survive editing, which raises obvious questions about false positives and detection accuracy in the wild. That's the headline from Ars Technica and TechCrunch, and it is the predictable collision between safety tooling that wants to label everything and users who want the model to stay invisible when it is convenient. Five stories, one recurring theme. State actors are shifting from external intrusion to legitimate employment pipelines. Sophisticated groups like Lazarus continue to weaponize zero-days the moment they appear. Public PoCs accelerate exploitation of enterprise platforms. Mobile payment fraud tooling is getting more specialized. And the safety features companies add to their models are already generating user friction. The through-line is the same one we see every week: the abstractions we rely on for speed and convenience keep leaking at the seams. The organizations that treat every new integration, every new hire, and every new model output as potentially hostile will be the ones that still have options when the next one lands. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Support the show

See all episodes