Security researchers exposed Phantom Circuit — the hidden administrative layer Lazarus Group uses to centrally manage its C2 servers from Pyongyang, routed through a freight company’s proxy network in Russia to obscure attribution. The same infrastructure connects to Operation 99, a campaign targeting Web3 and crypto developers with malicious GitHub repositories that backdoor corporate environments. […]
Blog
AI’s Dirty Little Secret: Employees Leaking Data by Accident | HN 53
Harmonic Security researchers analyzed thousands of prompts submitted to ChatGPT, Copilot, Gemini, and Claude and found that 8.5% contained sensitive data — including penetration test results, network configurations, customer insurance claims, and proprietary source code. HN53 also covers threat actors hiding info stealers (LumaStealer, Vidar, MARS Stealer) in YouTube comments and Google Ads disguised as […]
800K Volkswagen EVs Hacked! Massive Data Breach and Mirai Botnet Attack Explained | HN 52
An Amazon Cloud storage misconfiguration at Volkswagen’s software subsidiary Cariad exposed 800,000 EV customer records for months — including precise vehicle location data, home addresses, email addresses, and phone numbers. HN52 also covers a new Mirai botnet variant exploiting a zero-day in 4-Faith industrial routers, maintaining 15,000 daily active bots and generating DDoS traffic peaks […]
Chinese Hackers Breach US Treasury AND 3M Fake GitHub Stars Exposed | HN 51
Chinese state-backed threat actors breached the US Treasury Department by compromising a BeyondTrust API key — gaining remote access to Treasury workstations and unclassified documents through the vendor’s privileged remote access infrastructure. HN51 also covers 3.1 million fake GitHub stars identified across 278,000 bot accounts, used to artificially inflate the apparent popularity of malware distribution […]
IoT Webcams Hacked and 900k+ Health Records Exposed | HN 50
The FBI warned that HiatusRAT malware is actively scanning and infecting internet-exposed webcams and DVRs — targeting Chinese-branded devices with CVEs as old as 2017 that remain unpatched or end-of-life. HN50 also covers a telehealth breach at ConnectOnCall that exposed the protected health information of over 914,000 patients, including names, phone numbers, medical record numbers, […]
Fortnite Refund Update: Millions Refunded + Lazarus Group's Crypto Hacks Revealed | HN 49
The FTC distributed $72 million in Fortnite refunds from a record $245 million settlement with Epic Games, after the agency found the company used dark patterns to trick players into unwanted purchases. HN49 also covers the Lazarus Group’s latest cryptocurrency campaign: a professionally built fake NFT tank game, two Chrome zero-days including an unpatched V8 […]





